STIGQter STIGQter: STIG Summary: Apple iOS/iPadOS 26 Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 13 May 2026:

Apple iOS/iPadOS 26 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DOD servers; - Allows synchronization of data or applications between devices associated with user; - Allows unencrypted (or encrypted but not FIPS 140-3-validated) data sharing with other MDs or printers; and - Backs up own data to a remote system.

DISA Rule

SV-278757r1151156_rule

Vulnerability Number

V-278757

Group Title

PP-MDF-333070

Rule Version

AIOS-26-007400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install a configuration profile with an allow list of approved apps (allowlistedAppBundleIDs). Ensure the allow list does not include apps with the following characteristics:

- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3-validated) data sharing with other MDs or printers; and
- Backs up own data to a remote system.

Configuration Profile Key: allowListedAppBundleIDs

Check Contents

Verify no apps with the following prohibited characteristics are included in the configuration profile:

- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3-validated) data sharing with other MDs or printers; and
- Backs up own data to a remote system.

This check procedure is performed on the Apple iOS/iPadOS management tool.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple iOS/iPadOS management tool, verify "Allow Listed App" (allowlistedAppBundleIDs) is configured and there are no apps with prohibited characteristics.

If "Allow listed apps" is not configured and contains apps with prohibited characteristics, this is a finding.

Vulnerability Number

V-278757

Documentable

False

Rule Version

AIOS-26-007400

Severity Override Guidance

Verify no apps with the following prohibited characteristics are included in the configuration profile:

- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3-validated) data sharing with other MDs or printers; and
- Backs up own data to a remote system.

This check procedure is performed on the Apple iOS/iPadOS management tool.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple iOS/iPadOS management tool, verify "Allow Listed App" (allowlistedAppBundleIDs) is configured and there are no apps with prohibited characteristics.

If "Allow listed apps" is not configured and contains apps with prohibited characteristics, this is a finding.

Check Content Reference

M

Target Key

5723