Apple iOS/iPadOS 18 must require a valid password be successfully entered before the mobile device data is unencrypted.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-268024AIOS-18-010400SV-268024r1031204_ruleCCI-001199high
Description
Passwords provide a form of access control that prevents unauthorized individuals from accessing computing resources and sensitive data. Passwords may also be a source of entropy for generation of key encryption or data encryption keys. If a password is not required to access data, this data is accessible to any adversary who obtains physical possession of the device. Requiring that a password be successfully entered before the mobile device data is unencrypted mitigates this risk. Note: MDF PP requires a Password Authentication Factor and requires management of its length and complexity. It leaves open whether the  existence of a password is subject to management. This requirement addresses the configuration to require a password, which is critical to the cybersecurity posture of the device. SFRID: FIA_UAU_EXT.1.1
STIGDate
Apple iOS/iPadOS 18 Security Technical Implementation Guide2025-06-30

Related Frameworks

3 paths across 3 frameworks
NIST 800-531 mapping
SC-28
1.00
  • DISA · 1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
NIST 800-1711 mapping
  • DISA · 1 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
  • NIST · Rev 2 (Feb 2020, errata Jan 2021) · nist_800_171_app_d · equivalent
CCI1 mapping
CCI-001199
1.00
  • DISA · 1 · disa_xccdf · related

Details

Check Text (C-268024r1031204_chk)

Review configuration settings to confirm the device is set to require a passcode before use. This procedure is performed on the iOS and iPadOS device. On the iPhone and iPad: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the iOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Passcode required" is set to "Yes". If "Passcode required" is not set to "Yes", this is a finding.

Fix Text (F-71851r1030824_fix)

Install a configuration profile to require a password to unlock the device.