STIGQter STIGQter: STIG Summary: Apple iOS/iPadOS 18 Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 13 May 2026:

Apple iOS/iPadOS 18 must be configured to disable "Auto Unlock" of the iPhone by an Apple Watch.

DISA Rule

SV-268064r1031244_rule

Vulnerability Number

V-268064

Group Title

PP-MDF-993300

Rule Version

AIOS-18-014800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the AO has not approved the use of Apple Watch with DOD-owned iPhones, configure the Apple iOS configuration profile to disable "Allow auto unlock".

The procedure for implementing this control will vary depending on the MDM/EMM used by the mobile service provider.

In the MDM console, set "Allow auto unlock" to "False".

This requirement will become "Supervised only" in a future iOS/iPadOS release.

Check Contents

Determine if the site AO has approved the use of Apple Watch with DOD-owned iPhones. Look for a document showing approval. If not approved, review configuration settings to confirm "Allow Auto Unlock" is disabled. If approved, this requirement is not applicable.

This check procedure is performed on the device management tool.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the iOS management tool, verify "Allow auto unlock" is not checked.

If Allow auto unlock is enabled, this is a finding.

This requirement will become "Supervised only" in a future iOS/iPadOS release.

Vulnerability Number

V-268064

Documentable

False

Rule Version

AIOS-18-014800

Severity Override Guidance

Determine if the site AO has approved the use of Apple Watch with DOD-owned iPhones. Look for a document showing approval. If not approved, review configuration settings to confirm "Allow Auto Unlock" is disabled. If approved, this requirement is not applicable.

This check procedure is performed on the device management tool.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the iOS management tool, verify "Allow auto unlock" is not checked.

If Allow auto unlock is enabled, this is a finding.

This requirement will become "Supervised only" in a future iOS/iPadOS release.

Check Content Reference

M

Target Key

5650