STIGQter STIGQter: STIG Summary: Apple iOS/iPadOS 26 Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 13 May 2026:

Apple iOS/iPadOS 26 must implement the management setting: encrypt backups/Encrypt local backup.

DISA Rule

SV-278788r1150611_rule

Vulnerability Number

V-278788

Group Title

PP-MDF-993300

Rule Version

AIOS-26-010700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Install a configuration profile to force encrypted backups to iCloud.

Configuration Profile Key: forceEncryptedBackup

Check Contents

Review configuration settings to confirm "Force encrypted backups" is enabled.

This check procedure is performed on both the Apple iOS/iPadOS management tool and the iPhone and iPad.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple iOS/iPadOS management tool, verify "Encrypt local backup" is checked.

Alternatively, verify the text "<key>forceEncryptedBackup</key><true/>" appears in the configuration profile (.mobileconfig file).

On the iPhone and iPad:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the Configuration Profile from the Apple iOS/iPadOS management tool containing the restrictions policy.
5. Tap "Restrictions".
6. Verify "Encrypt backups enforced" is listed.

If "Encrypt local backup" is unchecked in the Apple iOS/iPadOS management tool, "<key>forceEncryptedBackup</key><false/>" appears in the configuration profile, or the restrictions policy on the iPhone and iPad does not list "Encrypt backups enforced", this is a finding.

Vulnerability Number

V-278788

Documentable

False

Rule Version

AIOS-26-010700

Severity Override Guidance

Review configuration settings to confirm "Force encrypted backups" is enabled.

This check procedure is performed on both the Apple iOS/iPadOS management tool and the iPhone and iPad.

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review.

In the Apple iOS/iPadOS management tool, verify "Encrypt local backup" is checked.

Alternatively, verify the text "<key>forceEncryptedBackup</key><true/>" appears in the configuration profile (.mobileconfig file).

On the iPhone and iPad:
1. Open the Settings app.
2. Tap "General".
3. Tap "VPN & Device Management".
4. Tap the Configuration Profile from the Apple iOS/iPadOS management tool containing the restrictions policy.
5. Tap "Restrictions".
6. Verify "Encrypt backups enforced" is listed.

If "Encrypt local backup" is unchecked in the Apple iOS/iPadOS management tool, "<key>forceEncryptedBackup</key><false/>" appears in the configuration profile, or the restrictions policy on the iPhone and iPad does not list "Encrypt backups enforced", this is a finding.

Check Content Reference

M

Target Key

5723