| Checked | Name | Title |
|---|
| ☐ | SV-267937r1120908_rule | Apple iOS/iPadOS 18 must allow the administrator (MDM) to perform the following management function: enable/disable VPN protection across the device and [selection: on a per-app basis, on a per-group of applications processes basis]. |
| ☐ | SV-267958r1137819_rule | Apple iOS/iPadOS 18 must not allow backup to remote systems (iCloud). |
| ☐ | SV-267959r1137819_rule | Apple iOS/iPadOS 18 must not allow backup to remote systems (iCloud document and data synchronization). |
| ☐ | SV-267960r1137819_rule | Apple iOS/iPadOS 18 must not allow backup to remote systems (iCloud Keychain). |
| ☐ | SV-267961r1137819_rule | Apple iOS/iPadOS 18 must not allow backup to remote systems (Cloud Photo Library). |
| ☐ | SV-267962r1137819_rule | Apple iOS/iPadOS 18 must not allow backup to remote systems (iCloud Photo Sharing, also known as Shared Stream or Shared Photo Stream). |
| ☐ | SV-267963r1137819_rule | Apple iOS/iPadOS 18 must not allow backup to remote systems (managed applications data stored in iCloud). |
| ☐ | SV-267964r1137819_rule | Apple iOS/iPadOS 18 must not allow backup to remote systems (enterprise books). |
| ☐ | SV-267987r1031167_rule | Apple iOS/iPadOS 18 must be configured to enforce a minimum password length of six characters. |
| ☐ | SV-267988r1031168_rule | Apple iOS/iPadOS 18 must be configured to not allow passwords that include more than four repeating or sequential characters. |
| ☐ | SV-267990r1031170_rule | Apple iOS/iPadOS 18 must be configured to lock the display after 15 minutes (or less) of inactivity. |
| ☐ | SV-267991r1031171_rule | Apple iOS/iPadOS 18 must be configured to not allow more than 10 consecutive failed authentication attempts. |
| ☐ | SV-267992r1031172_rule | Apple iOS/iPadOS 18 must be configured to enforce a passcode reuse prohibition of at least two generations. |
| ☐ | SV-267993r1031173_rule | Apple iOS/iPadOS 18 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store]. |
| ☐ | SV-267995r1032950_rule | Apple iOS/iPadOS 18 must not include applications with the following characteristics: access to Siri when the device is locked. |
| ☐ | SV-267997r1042532_rule | The Apple iOS/iPadOS 18 allow list must be configured to not include applications with the following characteristics:
- Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services);
- Transmits MD diagnostic data to non-DOD servers;
- Allows synchronization of data or applications between devices associated with user;
- Allows unencrypted (or encrypted but not FIPS 140-3 validated) data sharing with other MDs or printers;
- Backs up its own data to a remote system; and
- Uses artificial intelligence (AI), which processes data in the cloud (off device). Exception: Apple Intelligence Private Cloud Compute (PCC). |
| ☐ | SV-267998r1031178_rule | Apple iOS/iPadOS 18 must be configured to not display notifications when the device is locked. |
| ☐ | SV-267999r1031179_rule | Apple iOS/iPadOS 18 must not display notifications (calendar information) when the device is locked. |
| ☐ | SV-268007r1031187_rule | Apple iOS/iPadOS 18 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device. |
| ☐ | SV-268013r1137817_rule | Apple iOS/iPadOS 18 must be configured to not allow backup of [all applications, configuration data] to locally connected systems. |
| ☐ | SV-268017r1137824_rule | Apple iOS/iPadOS 18 must not allow non-DOD applications to access DOD data. |
| ☐ | SV-268018r1031198_rule | Apple iPadOS 18 must be configured to disable multiuser modes. |
| ☐ | SV-268019r1031199_rule | Apple iOS/iPadOS 18 must be configured to [selection: wipe protected data, wipe sensitive data] upon unenrollment from MDM. |
| ☐ | SV-268020r1031200_rule | Apple iOS/iPadOS 18 must be configured to [selection: remove Enterprise applications, remove all noncore applications (any nonfactory-installed application)] upon unenrollment from MDM. |
| ☐ | SV-268022r1115587_rule | Apple iOS/iPadOS 18 must be configured to disable ad hoc wireless client-to-client connection capability. |
| ☐ | SV-268024r1031204_rule | Apple iOS/iPadOS 18 must require a valid password be successfully entered before the mobile device data is unencrypted. |
| ☐ | SV-268026r1031206_rule | Apple iOS/iPadOS 18 must implement the management setting: limit Ad Tracking. |
| ☐ | SV-268027r1031207_rule | Apple iOS/iPadOS 18 must implement the management setting: not allow automatic completion of Safari browser passcodes. |
| ☐ | SV-268028r1031208_rule | Apple iOS/iPadOS 18 must implement the management setting: encrypt backups/Encrypt local backup. |
| ☐ | SV-268029r1031209_rule | Apple iOS/iPadOS 18 must implement the management setting: not allow use of Handoff. |
| ☐ | SV-268030r1031210_rule | Apple iOS/iPadOS 18 must implement the management setting: not allow use of iPhone widgets on Mac. |
| ☐ | SV-268031r1031211_rule | Apple iOS/iPadOS 18 must implement the management setting: require the user to enter a password when connecting to an AirPlay-enabled device. |
| ☐ | SV-268033r1031213_rule | Apple iOS/iPadOS 18 must implement the management setting: disable Allow MailDrop. |
| ☐ | SV-268034r1031214_rule | iPhone and iPad must have the latest available iOS/iPadOS operating system installed. |
| ☐ | SV-268035r1031215_rule | Apple iOS/iPadOS 18 must implement the management setting: use SSL for Exchange ActiveSync. |
| ☐ | SV-268036r1031216_rule | Apple iOS/iPadOS 18 must implement the management setting: not allow messages in an ActiveSync Exchange account to be forwarded or moved to other accounts in the Apple iOS/iPadOS 18 Mail app. |
| ☐ | SV-268037r1031217_rule | Apple iOS/iPadOS 18 must implement the management setting: treat AirDrop as an unmanaged destination. |
| ☐ | SV-268038r1031218_rule | Apple iOS/iPadOS 18 must implement the management setting: not have any Family Members in Family Sharing. |
| ☐ | SV-268039r1031219_rule | Apple iOS/iPadOS 18 must implement the management setting: not share location data through iCloud. |
| ☐ | SV-268040r1031220_rule | Apple iOS/iPadOS 18 must implement the management setting: force Apple Watch wrist detection. |
| ☐ | SV-268041r1031221_rule | Apple iOS/iPadOS 18 users must complete required training. |
| ☐ | SV-268042r1031222_rule | A managed photo app must be used to take and store work-related photos. |
| ☐ | SV-268044r1031224_rule | Apple iOS/iPadOS 18 must implement the management setting: enable USB Restricted Mode. |
| ☐ | SV-268045r1031225_rule | Apple iOS/iPadOS 18 must not allow managed apps to write contacts to unmanaged contacts accounts. |
| ☐ | SV-268046r1031226_rule | Apple iOS/iPadOS 18 must not allow unmanaged apps to read contacts from managed contacts accounts. |
| ☐ | SV-268047r1115590_rule | Apple iOS/iPadOS 18 must implement the management setting: disable AirDrop. |
| ☐ | SV-268048r1116197_rule | Apple iOS/iPadOS 18 must implement the management setting: disable paired Apple Watch. |
| ☐ | SV-268049r1031229_rule | Apple iOS/iPadOS 18 must implement the management setting: approved Apple Watches must be managed by an MDM. |
| ☐ | SV-268050r1031230_rule | Apple iOS/iPadOS 18 must disable "Password AutoFill" in browsers and applications. |
| ☐ | SV-268051r1031231_rule | Apple iOS/iPadOS 18 must disable "Allow setting up new nearby devices". |
| ☐ | SV-268052r1031232_rule | Apple iOS/iPadOS 18 must disable password proximity requests. |
| ☐ | SV-268053r1031233_rule | Apple iOS/iPadOS 18 must disable password sharing. |
| ☐ | SV-268054r1031234_rule | Apple iOS/iPadOS 18 must disable "Find My Friends" in the "Find My" app. |
| ☐ | SV-268055r1031235_rule | The Apple iOS/iPadOS 18 must be supervised by the MDM. |
| ☐ | SV-268056r1137817_rule | Apple iOS/iPadOS 18 must disable "Allow USB drive access in Files app" if the authorizing official (AO) has not approved the use of DOD-approved USB storage drives with iOS/iPadOS devices. |
| ☐ | SV-268057r1031237_rule | The Apple iOS must be configured to disable automatic transfer of diagnostic data to an external device other than an MDM service with which the device has enrolled. |
| ☐ | SV-268058r1031238_rule | Apple iOS must implement the management setting: not allow a user to remove Apple iOS configuration profiles that enforce DOD security requirements. |
| ☐ | SV-268059r1031239_rule | Apple iOS/iPadOS 18 must disable "Allow network drive access in Files access". |
| ☐ | SV-268060r1031240_rule | Apple iOS/iPadOS 18 must disable connections to Siri servers for the purpose of dictation. |
| ☐ | SV-268061r1031241_rule | Apple iOS/iPadOS 18 must disable connections to Siri servers for the purpose of translation. |
| ☐ | SV-268062r1031242_rule | Apple iOS/iPadOS 18 must disable copy/paste of data from managed to unmanaged applications. |
| ☐ | SV-268063r1031243_rule | Apple iOS/iPadOS 18 must have DOD root and intermediate PKI certificates installed. |
| ☐ | SV-268064r1031244_rule | Apple iOS/iPadOS 18 must be configured to disable "Auto Unlock" of the iPhone by an Apple Watch. |
| ☐ | SV-268065r1031245_rule | Apple iOS/iPadOS 18 must disable the installation of alternative marketplace apps. |
| ☐ | SV-268066r1031246_rule | Apple iOS/iPadOS 18 must disable app installation from a website. |
| ☐ | SV-268067r1031247_rule | Apple iOS/iPadOS 18 must delete eSIM content when the device is erased. |
| ☐ | SV-268068r1042535_rule | Apple iOS/iPadOS 18 must disable ChatGPT and other external AI app connections in Apple Intelligence. |
| ☐ | SV-269568r1031249_rule | Apple iOS/iPadOS 18 must disable the download of iOS/iPadOS beta updates. |
| ☐ | SV-272169r1067622_rule | Apple iOS/iPadOS 18 must disable the ability to hide apps. |
| ☐ | SV-272170r1067624_rule | Apple iOS/iPadOS 18 must disable recording cell phone calls on the iPhone. |
| ☐ | SV-272171r1067626_rule | Apple iOS/iPadOS 18 must disable iPhone Mirroring on Mac. |
| ☐ | SV-276196r1115625_rule | DOD Apple iOS/iPadOS 18 devices must disable FaceTime. |
| ☐ | SV-276197r1115628_rule | DOD Apple iOS/iPadOS 18 devices must disable eSIM transfers. |
| ☐ | SV-276198r1115631_rule | DOD Apple iOS/iPadOS 18 devices must disable screenshots and screen recordings. |
| ☐ | SV-276199r1115666_rule | Apple iOS/iPadOS 18 must disable the ability of the user to wipe the device. |
| ☐ | SV-276203r1115678_rule | Apple iOS/iPadOS 18 must disable automatic downloads of apps purchased on other Apple devices. |
| ☐ | SV-276204r1115681_rule | Apple iOS/iPadOS 18 must disable pairing with a host Mac or PC. |
| ☐ | SV-276205r1115684_rule | Apple iOS/iPadOS 18 must disable AirPrint. |
| ☐ | SV-276206r1115687_rule | Apple iOS/iPadOS 18 must disable AirPrint: Allow discovery of AirPrint printers using iBeacons. |
| ☐ | SV-276207r1115690_rule | Apple iOS/iPadOS 18 must disable AirPrint: Allow storage of AirPrint credentials in Keychain. |
| ☐ | SV-276208r1115693_rule | Apple iOS/iPadOS 18 must enable AirPrint feature: Disallow AirPrint to destinations with untrusted certificates. |
| ☐ | SV-276209r1115696_rule | Apple iOS/iPadOS 18 must disable Allowed Content Ratings (Movies). |
| ☐ | SV-276210r1115699_rule | Apple iOS/iPadOS 18 must disable Allowed Content Ratings (TV Shows). |
| ☐ | SV-276211r1115702_rule | Apple iOS/iPadOS 18 must disable the Apple Intelligence feature: Image Wand. |
| ☐ | SV-276212r1115705_rule | Apple iOS/iPadOS 18 must disable the Apple Intelligence feature: Image Generation. |
| ☐ | SV-276213r1115708_rule | Apple iOS/iPadOS 18 must disable the Apple Intelligence feature: generate new Genmoji. |
| ☐ | SV-276214r1115711_rule | DOD Apple iOS/iPadOS 18 devices must have a Mobile Threat Detection (MTD) app installed. |
| ☐ | SV-276224r1116200_rule | Apple iOS/iPadOS 18 must implement the management setting: disable Camera. |