iOS 26 STIG V1R2

View as one page
STIG IDTitle
AIOS-26-001000Apple iOS/iPadOS 26 must allow the administrator (MDM) to perform the following management function: enable/disable VPN protection across the device and [selection: on a per-app basis, on a per-group of applications processes basis].
AIOS-26-003000Apple iOS/iPadOS 26 must not allow backup to remote systems (iCloud).
AIOS-26-003200Apple iOS/iPadOS 26 must not allow backup to remote systems (iCloud document and data synchronization).
AIOS-26-003300Apple iOS/iPadOS 26 must not allow backup to remote systems (iCloud Keychain).
AIOS-26-003450Apple iOS/iPadOS 26 must not allow backup to remote systems (Cloud Photo Library).
AIOS-26-003500Apple iOS/iPadOS 26 must not allow backup to remote systems (iCloud Photo Sharing, also known as Shared Stream or Shared Photo Stream).
AIOS-26-003600Apple iOS/iPadOS 26 must not allow backup to remote systems (managed applications data stored in iCloud).
AIOS-26-003700Apple iOS/iPadOS 26 must not allow backup to remote systems (enterprise books).
AIOS-26-006500Apple iOS/iPadOS 26 must be configured to enforce a minimum password length of six characters.
AIOS-26-006600Apple iOS/iPadOS 26 must be configured to not allow passwords that include more than four repeating or sequential characters.
AIOS-26-006800Apple iOS/iPadOS 26 must be configured to lock the display after 15 minutes (or less) of inactivity.
AIOS-26-006900Apple iOS/iPadOS 26 must be configured to not allow more than 10 consecutive failed authentication attempts.
AIOS-26-006950Apple iOS/iPadOS 26 must be configured to enforce a passcode reuse prohibition of at least two generations.
AIOS-26-007000Apple iOS/iPadOS 26 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store].
AIOS-26-007200Apple iOS/iPadOS 26 must not include applications with the following characteristics: access to Siri when the device is locked.
AIOS-26-007400Apple iOS/iPadOS 26 allow list must be configured to not include applications with the following characteristics: - Backs up MD data to non-DOD cloud servers (including user and application access to cloud backup services); - Transmits MD diagnostic data to non-DOD servers; - Allows synchronization of data or applications between devices associated with user; - Allows unencrypted (or encrypted but not FIPS 140-3-validated) data sharing with other MDs or printers; and - Backs up own data to a remote system.
AIOS-26-007500Apple iOS/iPadOS 26 must be configured to not display notifications when the device is locked.
AIOS-26-007600Apple iOS/iPadOS 26 must not display notifications (calendar information) when the device is locked.
AIOS-26-008400Apple iOS/iPadOS 26 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device.
AIOS-26-009200Apple iOS/iPadOS 26 must be configured to not allow backup of [all applications, configuration data] to locally connected systems.
AIOS-26-009700Apple iOS/iPadOS 26 must not allow non-DOD applications to access DOD data.
AIOS-26-009800Apple iPadOS 26 must be configured to disable multiuser modes.
AIOS-26-009900Apple iOS/iPadOS 26 must be configured to [selection: wipe protected data, wipe sensitive data] upon unenrollment from MDM.
AIOS-26-010000Apple iOS/iPadOS 26 must be configured to [selection: remove Enterprise applications, remove all noncore applications (any nonfactory-installed application)] upon unenrollment from MDM.
AIOS-26-010200Apple iOS/iPadOS 26 must be configured to disable ad hoc wireless client-to-client connection capability.
AIOS-26-010400Apple iOS/iPadOS 26 must require a valid password be successfully entered before the mobile device data is unencrypted.
AIOS-26-010500Apple iOS/iPadOS 26 must implement the management setting: limit Ad Tracking.
AIOS-26-010600Apple iOS/iPadOS 26 must implement the management setting: not allow automatic completion of Safari browser passcodes.
AIOS-26-010700Apple iOS/iPadOS 26 must implement the management setting: encrypt backups/Encrypt local backup.
AIOS-26-010800Apple iOS/iPadOS 26 must implement the management setting: not allow use of Handoff.
AIOS-26-010850Apple iOS/iPadOS 26 must implement the management setting: not allow use of iPhone widgets on Mac.
AIOS-26-010900Apple iOS/iPadOS 26 must implement the management setting: require the user to enter a password when connecting to an AirPlay-enabled device.
AIOS-26-011000Apple iOS/iPadOS 26 must implement the management setting: disable Allow MailDrop.
AIOS-26-011200iPhone and iPad must have the latest available iOS/iPadOS operating system installed.
AIOS-26-011300Apple iOS/iPadOS 26 must implement the management setting: use SSL for Exchange ActiveSync.
AIOS-26-011400Apple iOS/iPadOS 26 must implement the management setting: not allow messages in an ActiveSync Exchange account to be forwarded or moved to other accounts in the Apple iOS/iPadOS 26 Mail app.
AIOS-26-011500Apple iOS/iPadOS 26 must implement the management setting: treat AirDrop as an unmanaged destination.
AIOS-26-011600Apple iOS/iPadOS 26 must implement the management setting: not have any Family Members in Family Sharing.
AIOS-26-011700Apple iOS/iPadOS 26 must implement the management setting: not share location data through iCloud.
AIOS-26-011800Apple iOS/iPadOS 26 must implement the management setting: force Apple Watch wrist detection.
AIOS-26-011900Apple iOS/iPadOS 26 users must complete required training.
AIOS-26-012000A managed photo app must be used to take and store work-related photos.
AIOS-26-012200Apple iOS/iPadOS 26 must implement the management setting: enable USB Restricted Mode.
AIOS-26-012300Apple iOS/iPadOS 26 must not allow managed apps to write contacts to unmanaged contacts accounts.
AIOS-26-012400Apple iOS/iPadOS 26 must not allow unmanaged apps to read contacts from managed contacts accounts.
AIOS-26-012500Apple iOS/iPadOS 26 must implement the management setting: disable AirDrop.
AIOS-26-012600Apple iOS/iPadOS 26 must implement the management setting: disable paired Apple Watch.
AIOS-26-012700Apple iOS/iPadOS 26 must disable "Password AutoFill" in browsers and applications.
AIOS-26-012800Apple iOS/iPadOS 26 must disable "Allow setting up new nearby devices".
AIOS-26-012900Apple iOS/iPadOS 26 must disable password proximity requests.
AIOS-26-013000Apple iOS/iPadOS 26 must disable password sharing.
AIOS-26-013100Apple iOS/iPadOS 26 must disable "Find My Friends" in the "Find My" app.
AIOS-26-013200The Apple iOS/iPadOS 26 must be supervised by the MDM.
AIOS-26-013300Apple iOS/iPadOS 26 must disable "Allow USB drive access in Files app" if the authorizing official (AO) has not approved the use of DOD-approved USB storage drives with iOS/iPadOS devices.
AIOS-26-013400The Apple iOS must be configured to disable automatic transfer of diagnostic data to an external device other than an MDM service with which the device has enrolled.
AIOS-26-013500Apple iOS must implement the management setting: not allow a user to remove Apple iOS configuration profiles that enforce DOD security requirements.
AIOS-26-014300Apple iOS/iPadOS 26 must disable "Allow network drive access in Files access".
AIOS-26-014400Apple iOS/iPadOS 26 must disable connections to Siri servers for the purpose of dictation.
AIOS-26-014500Apple iOS/iPadOS 26 must disable connections to Siri servers for the purpose of translation.
AIOS-26-014600Apple iOS/iPadOS 26 must disable copy/paste of data from managed to unmanaged applications.
AIOS-26-014700Apple iOS/iPadOS 26 must have DOD root and intermediate PKI certificates installed.
AIOS-26-014800Apple iOS/iPadOS 26 must be configured to disable "Auto Unlock" of the iPhone by an Apple Watch.
AIOS-26-014900Apple iOS/iPadOS 26 must disable the installation of alternative marketplace apps.
AIOS-26-015000Apple iOS/iPadOS 26 must disable app installation from a website.
AIOS-26-015100Apple iOS/iPadOS 26 must delete eSIM content when the device is erased.
AIOS-26-015400Apple iOS/iPadOS 26 must disable ChatGPT connection for Apple Intelligence.
AIOS-26-015500Apple iOS/iPadOS 26 must disable the download of iOS/iPadOS beta updates.
AIOS-26-015600Apple iOS/iPadOS 26 must disable the ability to hide apps.
AIOS-26-015700Apple iOS/iPadOS 26 must disable recording cell phone calls on the iPhone.
AIOS-26-015800Apple iOS/iPadOS 26 must disable iPhone Mirroring on Mac.
AIOS-26-016000Apple iOS/iPadOS 26 must disable the ability of the user to wipe the device.
AIOS-26-016100Apple iOS/iPadOS 26 must disable the use voice assistant (Siri) unless required to meet Section 508 compliance requirements.
AIOS-26-016200Apple iOS/iPadOS 26 must disable the use voice assistant (Show user-generated content in Siri) unless required to meet Section 508 compliance requirements.
AIOS-26-016300Apple iOS/iPadOS 26 must disable the use voice assistant (Siri suggestions) unless required to meet Section 508 compliance requirements.
AIOS-26-016400Apple iOS/iPadOS 26 must disable automatic downloads of apps purchased on other Apple devices.
AIOS-26-016500Apple iOS/iPadOS 26 must disable pairing with a host Mac or PC.
AIOS-26-016600Apple iOS/iPadOS 26 must disable AirPrint.
AIOS-26-016700Apple iOS/iPadOS 26 must disable AirPrint: Allow discovery of AirPrint printers using iBeacons.
AIOS-26-016800Apple iOS/iPadOS 26 must disable AirPrint: Allow storage of AirPrint credentials in Keychain.
AIOS-26-016900Apple iOS/iPadOS 26 must allow AirPrint feature: Disallow AirPrint to destinations with untrusted certificates.
AIOS-26-017000Apple iOS/iPadOS 26 must disable Allowed Content Ratings (Movies).
AIOS-26-017100Apple iOS/iPadOS 26 must disable Allowed Content Ratings (TV Shows).
AIOS-26-017200Apple iOS/iPadOS 26 must disable Apple Intelligence feature: Image Wand.
AIOS-26-017300Apple iOS/iPadOS 26 must disable Apple Intelligence feature: Image Generation.
AIOS-26-017400Apple iOS/iPadOS 26 must disable Apple Intelligence feature: generate new Genmoji.
AIOS-26-017700DOD Apple iOS/iPadOS 26 devices must have a Mobile Threat Detection (MTD) app installed.
AIOS-26-017800DOD Apple iOS/iPadOS 26 devices must disable FaceTime.
AIOS-26-017900DOD Apple iOS/iPadOS 26 devices must disable eSIM transfers.
AIOS-26-018000DOD Apple iOS/iPadOS 26 devices must disable screenshots and screen recordings.
AIOS-26-018100Apple iOS/iPadOS 26 must implement the management setting: disable Camera.
AIOS-26-018200Apple iOS/iPadOS 26 must implement the management setting: disable the Bluetooth radio.
AIOS-26-018300Apple iOS/iPadOS 26 must be configured to disable Wi-Fi Aware.