SV-278757r1151156_rule
V-278757
PP-MDF-333070
AIOS-26-007400
CAT II
10
Install a configuration profile with an allow list of approved apps (allowlistedAppBundleIDs). Ensure the allow list does not include apps with the following characteristics:
- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3-validated) data sharing with other MDs or printers; and
- Backs up own data to a remote system.
Configuration Profile Key: allowListedAppBundleIDs
Verify no apps with the following prohibited characteristics are included in the configuration profile:
- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3-validated) data sharing with other MDs or printers; and
- Backs up own data to a remote system.
This check procedure is performed on the Apple iOS/iPadOS management tool.
Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.
In the Apple iOS/iPadOS management tool, verify "Allow Listed App" (allowlistedAppBundleIDs) is configured and there are no apps with prohibited characteristics.
If "Allow listed apps" is not configured and contains apps with prohibited characteristics, this is a finding.
V-278757
False
AIOS-26-007400
Verify no apps with the following prohibited characteristics are included in the configuration profile:
- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3-validated) data sharing with other MDs or printers; and
- Backs up own data to a remote system.
This check procedure is performed on the Apple iOS/iPadOS management tool.
Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.
In the Apple iOS/iPadOS management tool, verify "Allow Listed App" (allowlistedAppBundleIDs) is configured and there are no apps with prohibited characteristics.
If "Allow listed apps" is not configured and contains apps with prohibited characteristics, this is a finding.
M
5723