STIGQter STIGQter: STIG Summary: Apple iOS 12 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 25 Jan 2019:

Apple iOS must be configured to display the DoD advisory warning message at start-up or each time the user unlocks the device.

DISA Rule

SV-96489r1_rule

Vulnerability Number

V-81775

Group Title

PP-MDF-301200

Rule Version

AIOS-12-003600

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure the DoD warning banner by either of the following methods (required text is found in the Vulnerability Description):

1. By placing the DoD warning banner text in the user agreement signed by each iOS device user (preferred method)
2. By creating a background picture with the relevant information and configuring that picture as the background for the lock screen via the Apple iOS management tool

Check Contents

The DoD warning banner can be displayed by either of the following methods (required text is found in the Vulnerability Description):

1. By placing the DoD warning banner text in the user agreement signed by each iOS device user (preferred method)
2. By creating a background picture with the relevant information and configuring that picture as the background for the lock screen via the Apple iOS management tool (only available for supervised devices)

Determine which method is used at the iOS device site and follow the appropriate validation procedure below.

Validation Procedure for Method #1:
Review the signed user agreements for several iOS device users and verify the agreement includes the required DoD warning banner text.

Validation Procedure for Method #2:
- In the Apple iOS management tool, verify a picture of the DoD warning banner text has been configured as the background for the lock screen.
- On the iOS device, verify a picture of the DoD warning banner text is shown as the background for the locked screen.

If, for Method #1, the required warning banner text is not on all signed user agreements reviewed, or for Method #2, the DoD warning banner text is not set as the locked screen background, this is a finding.

Vulnerability Number

V-81775

Documentable

False

Rule Version

AIOS-12-003600

Severity Override Guidance

The DoD warning banner can be displayed by either of the following methods (required text is found in the Vulnerability Description):

1. By placing the DoD warning banner text in the user agreement signed by each iOS device user (preferred method)
2. By creating a background picture with the relevant information and configuring that picture as the background for the lock screen via the Apple iOS management tool (only available for supervised devices)

Determine which method is used at the iOS device site and follow the appropriate validation procedure below.

Validation Procedure for Method #1:
Review the signed user agreements for several iOS device users and verify the agreement includes the required DoD warning banner text.

Validation Procedure for Method #2:
- In the Apple iOS management tool, verify a picture of the DoD warning banner text has been configured as the background for the lock screen.
- On the iOS device, verify a picture of the DoD warning banner text is shown as the background for the locked screen.

If, for Method #1, the required warning banner text is not on all signed user agreements reviewed, or for Method #2, the DoD warning banner text is not set as the locked screen background, this is a finding.

Check Content Reference

M

Target Key

3401

Comments