Apple visionOS 2 Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Supporting documents 4 PDFs
Bundled by DISA alongside this STIG release: overview, revision history, and readme files. Download the full archive or open an individual PDF.
Digest of Updates −2
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Removed rules 2
- V-276418 Low Apple visionOS 2 must disable the use voice assistant (Siri) unless required to meet Section 508 compliance requirements.
- V-279327 Medium Apple visionOS 2 must implement the management setting: disable the Bluetooth radio.
- RMF Control
- AC-17
- Severity
- L
- CCI
- CCI-000068
- Version
- AVOS-02-001000
- Vuln IDs
-
- V-276374
- Rule IDs
-
- SV-276374r1146618_rule
Checks: C-80529r1146616_chk
Review the list of unmanaged apps installed on the Vision Pro and determine if any unmanaged third-party VPN clients are installed. If so, verify the VPN app is not configured with a DOD network (work) VPN profile. This validation procedure is performed on the visionOS device only. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap the "VPN and Device Management" line and determine if any "Personal VPN" exists. 4. If not, the requirement has been met. 5. If there are personal VPNs, open each VPN app. Review the list of VPN profiles configured on the VPN client. 6. Verify no DOD network VPN profiles are configured on the VPN client. If any third-party unmanaged VPN apps are installed (personal VPN) and they have a DOD network VPN profile configured on the client, this is a finding. Note: This setting cannot be managed by the MDM administrator and is a User-Based Enforcement (UBE) requirement.
Fix: F-80434r1146617_fix
If a third-party unmanaged VPN app is installed on the visionOS 2 device, do not configure the VPN app with a DOD network VPN profile.
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- AVOS-02-003000
- Vuln IDs
-
- V-276375
- Rule IDs
-
- SV-276375r1146621_rule
Checks: C-80530r1146619_chk
Note: This requirement is not applicable if the authorizing official (AO) has approved users' full access to the Apple App Store for downloading unmanaged (personal) apps and syncing personal data on the device with personal cloud data storage accounts. The site must have an AO-signed document showing the AO has assumed the risk for users' full access to the Apple App Store. Review configuration settings to confirm iCloud Backup is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow iCloud backup" is unchecked. Alternatively, verify the text "<key>allowCloudBackup</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the policy. 5. Tap "Restrictions". 6. Verify "iCloud backup not allowed". If "Allow iCloud backup" is checked in the Apple visionOS management tool, "<key>allowCloudBackup</key><true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "iCloud backup not allowed", this is a finding.
Fix: F-80435r1146620_fix
Install a configuration profile to disable iCloud backup.
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- AVOS-02-003200
- Vuln IDs
-
- V-276376
- Rule IDs
-
- SV-276376r1146624_rule
Checks: C-80531r1146622_chk
Note: This requirement is not applicable if the authorizing official (AO) has approved users' full access to the Apple App Store for downloading unmanaged (personal) apps and syncing personal data on the device with personal cloud data storage accounts. The site must have an AO-signed document showing the AO has assumed the risk for users' full access to the Apple App Store. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Allow iCloud documents & data" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow iCloud documents & data" is unchecked. Alternatively, verify the text "<key>allowCloudDocumentSync</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the policy. 5. Tap "Restrictions". 6. Verify "Documents in the Cloud not allowed" is listed. Note: This also verifies that iCloud Drive and iCloud Photo Library are disabled. If "Allow iCloud documents & data" is checked in the Apple visionOS management tool, "<key>allowCloudDocumentSync</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Documents in the Cloud not allowed", this is a finding.
Fix: F-80436r1146623_fix
Install a configuration profile to disable iCloud documents and data. This is a supervised-only control.
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- AVOS-02-003300
- Vuln IDs
-
- V-276377
- Rule IDs
-
- SV-276377r1146627_rule
Checks: C-80532r1146625_chk
Note: This requirement is not applicable if the authorizing official (AO) has approved users' full access to the Apple App Store for downloading unmanaged (personal) apps and syncing personal data on the device with personal cloud data storage accounts. The site must have an AO-signed document showing the AO has assumed the risk for users' full access to the Apple App Store. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm iCloud keychain is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow iCloud keychain" is unchecked. Alternatively, verify the text "<key>allowCloudKeychainSync</key><false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the management policy. 5. Verify "iCloud Keychain not allowed" is listed. If "Allow iCloud keychain" is checked in the Apple visionOS management tool, "<key>allowCloudKeychainSync</key><true/>" appears in the configuration profile, or "iCloud Keychain not allowed" is not listed on the Vision Pro, this is a finding.
Fix: F-80437r1146626_fix
Install a configuration profile to disable iCloud keychain. This is a supervised-only control.
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- AVOS-02-003450
- Vuln IDs
-
- V-276378
- Rule IDs
-
- SV-276378r1146630_rule
Checks: C-80533r1146628_chk
Note: This requirement is not applicable if the authorizing official (AO) has approved users' full access to the Apple App Store for downloading unmanaged (personal) apps and syncing personal data on the device with personal cloud data storage accounts. The site must have an AO-signed document showing the AO has assumed the risk for users' full access to the Apple App Store. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Allow Cloud Photo Library" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow Cloud Photo Library" is unchecked. Alternatively, verify the text "<key>allowCloudPhotoLibrary</key><false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "iCloud Photos not allowed" is listed. If "Allow Cloud Photo Library" is checked in the Apple visionOS management tool, "<key>allowCloudPhotoLibrary</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "iCloud Photos not allowed", this is a finding.
Fix: F-80438r1146629_fix
Install a configuration profile to disable Cloud Photo Library. This is a supervised-only control.
- RMF Control
- SC-4
- Severity
- M
- CCI
- CCI-001090
- Version
- AVOS-02-003600
- Vuln IDs
-
- V-276379
- Rule IDs
-
- SV-276379r1146633_rule
Checks: C-80534r1146631_chk
Review configuration settings to confirm "Allow managed apps to store data in iCloud" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow managed apps to store data in iCloud" is unchecked. Alternatively, verify the text "<key>allowManagedAppsCloudSync</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Managed apps cloud sync not allowed" is listed. If "Allow managed apps to store data in iCloud" is checked in the Apple visionOS management tool, "<key>allowManagedAppsCloudSync</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Managed apps cloud sync not allowed", this is a finding.
Fix: F-80439r1146632_fix
Install a configuration profile to prevent DOD applications from storing data in iCloud.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- AVOS-02-006500
- Vuln IDs
-
- V-276380
- Rule IDs
-
- SV-276380r1146636_rule
Checks: C-80535r1146634_chk
Review configuration settings to confirm the minimum passcode length is six or more characters. This procedure is performed in the Apple visionOS management tool and on the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Management tool, verify the "Minimum passcode length" value is set to six or greater. Alternatively, verify the text "<key>minLength</key> <integer>6</integer>" appears in the configuration profile (.mobileconfig file). It also is acceptable for the integer value to be greater than six. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Minimum length" is listed as "six or greater". If the "Minimum passcode length" is fewer than six characters in the visionOS management tool, "<key>minLength</key> " has an integer value of fewer than six, or the password policy on the Vision Pro from the Apple visionOS management tool does not list "Minimum length" of six or more, this is a finding.
Fix: F-80440r1146635_fix
Install a configuration profile to enforce a minimum passcode length value of six or greater.
- RMF Control
- Severity
- M
- CCI
- CCI-004066
- Version
- AVOS-02-006600
- Vuln IDs
-
- V-276381
- Rule IDs
-
- SV-276381r1146639_rule
Checks: C-80536r1146637_chk
Review configuration settings to confirm simple passcodes are not allowed. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow simple value" is unchecked. Alternatively, verify the text "<key>allowSimple</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Simple passcodes allowed" is set to "No". If "Allow simple value" is checked in the Apple visionOS management tool, "<key>allowSimple</key> <true/>" appears in the Configuration Profile, or the password policy on the Vision Pro does not have "Simple passcodes allowed" set to "No", this is a finding.
Fix: F-80441r1146638_fix
Install a configuration profile to disallow more than four sequential or repeating numbers or letters in the device unlock password.
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000057
- Version
- AVOS-02-006800
- Vuln IDs
-
- V-276382
- Rule IDs
-
- SV-276382r1146642_rule
Checks: C-80537r1146640_chk
Review configuration settings to confirm the screen lock timeout is set to 15 minutes or fewer. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the management tool, verify the sum of the values assigned to "Maximum Auto-Lock time" and "Grace period for device lock" is between 1 and 15 minutes. Alternatively, locate the text "<key>maxGracePeriod</key>" and "<key>maxInactivity</key>" and ensure the sum of their integer value is between 1 and 15 in the configuration profile (.mobileconfig file). For example: "<key>maxGracePeriod</key> <integer>5</integer> <key>maxInactivity</key> <integer>5</integer>" Here, 5 + 5 = 10; this meets the requirement. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify the sum of the "Max grace period" and "Max inactivity" values is fewer than 15 minutes. Note: On some visionOS devices, it is not possible to have a sum of exactly 15. In these cases, the sum must be fewer than 15. A sum of 16 does not meet the requirement. On the management server, if the sum of the "Max grace period" and "Max inactivity" values is not between 1 and 15 minutes in the visionOS management tool or the sum of the values assigned to "<key>maxGracePeriod</key>" and "<key>maxInactivity</key>" is not between 1 and 15 minutes in the configuration profile, or if on the Vision Pro, the sum of the values assigned to "Max grace period" and "Max inactivity" is not between 1 and 15 minutes, this is a finding.
Fix: F-80442r1146641_fix
Install a configuration profile to lock the device display after 15 minutes (or fewer) of inactivity. This is done by setting "Maximum Auto-Lock time" and "Grace Period for device lock" so the sum of their values is between 1 and 15 minutes.
- RMF Control
- AC-7
- Severity
- M
- CCI
- CCI-000044
- Version
- AVOS-02-006900
- Vuln IDs
-
- V-276383
- Rule IDs
-
- SV-276383r1146645_rule
Checks: C-80538r1146643_chk
Review configuration settings to confirm that consecutive failed authentication attempts is set to 10 or fewer. This procedure is performed in the Apple visionOS management tool and on the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Management tool, verify the "Maximum number of failed attempts" value is set to 10 or fewer. Alternatively, verify the text "<key>maxFailedAttempts</key> <integer>10</integer>" appears in the configuration profile (.mobileconfig file). It also is acceptable for the integer value to be fewer than 10. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Max failed attempts" is listed as "10" or fewer. If the "Maximum number of failed attempts" is more than 10 in the visionOS management tool, "<key>maxFailedAttempts</key> " has an integer value of more than 10, or the password policy on the Vision Pro does not list "Max failed attempts" of 10 or fewer, this is a finding.
Fix: F-80443r1146644_fix
Install a configuration profile to allow only 10 or fewer consecutive failed authentication attempts.
- RMF Control
- Severity
- H
- CCI
- CCI-004061
- Version
- AVOS-02-006950
- Vuln IDs
-
- V-276384
- Rule IDs
-
- SV-276384r1146648_rule
Checks: C-80539r1146646_chk
Review configuration settings to confirm the Apple visionOS device has a passcode reuse prohibition of at least two generations. This procedure is performed in the Apple visionOS management tool and on the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Management tool, verify the "Passcode History" value is set to two or greater. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Number of unique recent passcodes required" is listed as "two" or greater. If the Apple visionOS device does not enforce a passcode reuse prohibition of at least two generations, this is a finding.
Fix: F-80444r1146647_fix
Install a configuration profile to enforce a passcode reuse prohibition of at least two generations (passcode history).
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-007000
- Vuln IDs
-
- V-276385
- Rule IDs
-
- SV-276385r1146651_rule
Checks: C-80540r1146649_chk
Review configuration settings to confirm "Allow Trusting New Enterprise App Authors" is disabled. This procedure is performed in the Apple visionOS management tool and on the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Management tool, verify "Allow Trusting New Enterprise App Authors" is disabled. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Trusting enterprise apps not allowed" is listed. If "Allow Trusting New Enterprise App Authors" is not disabled in the visionOS management tool or on the Vision Pro, this is a finding.
Fix: F-80445r1146650_fix
Install a configuration profile to disable "Allow Trusting New Enterprise App Authors".
- RMF Control
- AC-11
- Severity
- M
- CCI
- CCI-000060
- Version
- AVOS-02-007500
- Vuln IDs
-
- V-276386
- Rule IDs
-
- SV-276386r1146654_rule
Checks: C-80541r1146652_chk
Review configuration settings to confirm the display of notifications when the device is locked has been disabled. This check procedure is performed on the Apple visionOS management tool and mobile device. In the Apple visionOS management tool, for each managed app, verify the app is configured to disable Notifications preview. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the management policy. 5. Tap "Apps". 6. Tap an app and verify "Disallow notification view in locked screen" is listed. Repeat steps 5 and 6 for each managed app in the list. If one or more managed apps are not set to disable showing notification view on locked screen, this is a finding.
Fix: F-80446r1146653_fix
Install a configuration profile to disable the display of notifications when the device is locked. Install a configuration profile to disable Notification Center from the device Lock screen.
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000048
- Version
- AVOS-02-008400
- Vuln IDs
-
- V-276387
- Rule IDs
-
- SV-276387r1146657_rule
Checks: C-80542r1146655_chk
The DOD warning banner can be displayed by the following method (required text is found in the Vulnerability Discussion): 1. By placing the DOD warning banner text in the user agreement signed by each Vision Pro user. Validation Procedure for Method #1: Review the signed user agreements for several visionOS device users and verify the agreement includes the required DOD warning banner text. If, the required warning banner text is not on all signed user agreements reviewed, this is a finding.
Fix: F-80447r1146656_fix
Configure the DOD warning banner by the following method (required text is found in the Vulnerability Discussion): 1. By placing the DOD warning banner text in the user agreement signed by each visionOS device user. Note, Vision Pro does not support the LockScreenFootnote key.
- RMF Control
- SC-39
- Severity
- M
- CCI
- CCI-002530
- Version
- AVOS-02-009700
- Vuln IDs
-
- V-276388
- Rule IDs
-
- SV-276388r1146660_rule
Checks: C-80543r1146658_chk
Review configuration settings to confirm "Allow documents from managed apps in unmanaged apps" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow documents from managed apps in unmanaged apps" is unchecked. Alternatively, verify the text "<key>allowOpenFromManagedToUnmanaged</key><false/>" appears in the configuration profile (.mobileconfig file). On the visionOS device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Opening documents from managed to unmanaged apps not allowed" is listed. If "Allow documents from managed apps in unmanaged apps" is checked in the visionOS management tool, "<key>allowOpenFromManagedToUnmanaged</key><true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Opening documents from managed to unmanaged apps not allowed", this is a finding.
Fix: F-80448r1146659_fix
Install a configuration profile to prevent non-DOD applications from accessing DOD data.
- RMF Control
- MP-6
- Severity
- M
- CCI
- CCI-001033
- Version
- AVOS-02-009900
- Vuln IDs
-
- V-276389
- Rule IDs
-
- SV-276389r1146663_rule
Checks: C-80544r1146661_chk
Note: Not all Apple visionOS deployments involve MDM. If the site uses an authorized alternative to MDM for distribution of configuration profiles (Apple Configurator), this check procedure is not applicable. This check procedure is performed on the Apple visionOS management tool or on the visionOS device. In the Apple visionOS management tool, for each managed app, verify the app is configured to be removed when the MDM profile is removed. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the management policy. 5. Tap "Apps". 6. Tap an app and verify "App and data will be removed when device is no longer managed" is listed. Repeat steps 5 and 6 for each managed app in the list. If one or more managed apps are not set to be removed upon device MDM unenrollment, this is a finding.
Fix: F-80449r1146662_fix
Install a configuration profile to delete all managed apps upon device unenrollment.
- RMF Control
- MP-6
- Severity
- M
- CCI
- CCI-001033
- Version
- AVOS-02-010000
- Vuln IDs
-
- V-276390
- Rule IDs
-
- SV-276390r1146666_rule
Checks: C-80545r1146664_chk
Note: Not all Apple visionOS deployments involve MDM. If the site uses an authorized alternative to MDM for distribution of configuration profiles (Apple Configurator), this check procedure is not applicable. This check procedure is performed on the Apple visionOS management tool or on the visionOS device. In the Apple visionOS management tool, for each managed app, verify the app is configured to be removed when the MDM profile is removed. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the management policy. 5. Tap "Apps". 6. Tap an app and verify "App and data will be removed when device is no longer managed" is listed. Repeat steps 5 and 6 for each managed app in the list. If one or more managed apps are not set to be removed upon device MDM unenrollment, this is a finding.
Fix: F-80450r1146665_fix
Install a configuration profile to delete all managed apps upon device unenrollment.
- RMF Control
- SC-40
- Severity
- M
- CCI
- CCI-002536
- Version
- AVOS-02-010200
- Vuln IDs
-
- V-276391
- Rule IDs
-
- SV-276391r1146669_rule
Checks: C-80546r1146667_chk
Review configuration settings to confirm it is disabled. If AirDrop is approved, this requirement is not applicable. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow AirDrop" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "AirDrop not allowed" is listed. If "AirDrop not allowed" is not listed in the management tool and on the Apple device, this is a finding.
Fix: F-80451r1146668_fix
Install a configuration profile to disable the AllowAirDrop control in the management tool. This is a supervised-only control.
- RMF Control
- SC-28
- Severity
- H
- CCI
- CCI-001199
- Version
- AVOS-02-010400
- Vuln IDs
-
- V-276392
- Rule IDs
-
- SV-276392r1146672_rule
Checks: C-80547r1146670_chk
Review configuration settings to confirm the device is set to require a passcode before use. This procedure is performed on the visionOS device. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Passcode required" is set to "Yes". If "Passcode required" is not set to "Yes", this is a finding.
Fix: F-80452r1146671_fix
Install a configuration profile to require a password to unlock the device.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AVOS-02-010600
- Vuln IDs
-
- V-276393
- Rule IDs
-
- SV-276393r1146675_rule
Checks: C-80548r1146673_chk
Review configuration settings to confirm "Enable autofill" is unchecked. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Enable autofill" is unchecked. Alternatively, verify the text "<key>safariAllowAutoFill</key><false>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the management policy. 5. Tap "Restrictions". 6. Verify "Auto-fill in Safari not allowed" is present. If "Enable autofill" is checked in the Apple visionOS management tool, "<key>safariAllowAutoFill</key><true>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Auto-fill in Safari not allowed", this is a finding.
Fix: F-80453r1146674_fix
Install a configuration profile to disable the AutoFill capability in the Safari app.
- RMF Control
- CM-7
- Severity
- L
- CCI
- CCI-000381
- Version
- AVOS-02-010800
- Vuln IDs
-
- V-276394
- Rule IDs
-
- SV-276394r1146678_rule
Checks: C-80549r1146676_chk
This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Allow Handoff" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow Handoff" is unchecked. Alternatively, verify the text "<key>allowActivityContinuation</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Handoff not allowed" is listed. If "Allow Handoff" is checked in the Apple visionOS management tool, "<key>allowActivityContinuation</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Handoff not allowed", this is a finding.
Fix: F-80454r1146677_fix
Install a configuration profile to disable continuation of activities among devices and workstations. This is a supervised-only control.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- AVOS-02-011000
- Vuln IDs
-
- V-276395
- Rule IDs
-
- SV-276395r1146681_rule
Checks: C-80550r1146679_chk
Review configuration settings to confirm "Allow MailDrop" is disabled. This validation procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow MailDrop" is not checked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Mail". 6. Tap the mail account. 7. Verify "Mail Drop Enabled" is set to "No". If "Allow MailDrop" is not disabled in the Apple visionOS management tool or the restrictions policy on the Vision Pro lists "Mail Drop Enabled" as "Yes", this is a finding.
Fix: F-80455r1146680_fix
Configure the Apple visionOS configuration profile to disable "Allow MailDrop".
- RMF Control
- CM-7
- Severity
- H
- CCI
- CCI-000381
- Version
- AVOS-02-011200
- Vuln IDs
-
- V-276396
- Rule IDs
-
- SV-276396r1146684_rule
Checks: C-80551r1146682_chk
Review configuration settings to confirm the most recently released version of visionOS is installed. This validation procedure is performed on both the Apple visionOS management tool and the Vision Pro. Go to https://www.apple.com and determine the most current version of visionOS released by Apple. In the MDM management console, review the version of visionOS installed on a sample of managed devices. This procedure will vary depending on the MDM product. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "About" and view the installed version of visionOS. 4. Go back to the "General" screen. Tap "Software Update" and verify the following message is shown on the screen: "Your software is up to date." If the installed version of visionOS on any reviewed visionOS devices is not the latest released by Apple, this is a finding.
Fix: F-80456r1146683_fix
Install the latest release version of Apple visionOS on all managed visionOS devices.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- AVOS-02-011300
- Vuln IDs
-
- V-276397
- Rule IDs
-
- SV-276397r1146687_rule
Checks: C-80552r1146685_chk
Review configuration settings to confirm "Use SSL" for the Exchange account is enabled for incoming mail. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Use SSL for incoming mail" is checked under the Exchange payload. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the Exchange policy. 5. Tap "Mail". 6. Tap the name of the Exchange account. 7. Verify "SSL for incoming mail" is set to "Yes". If "Use SSL for incoming mail" is unchecked in the Apple visionOS management tool or the Exchange policy on the Vision Pro has "SSL for incoming mail" set to "No", this is a finding.
Fix: F-80457r1146686_fix
Install a configuration profile to use SSL for Exchange ActiveSync incoming mail.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- AVOS-02-011400
- Vuln IDs
-
- V-276398
- Rule IDs
-
- SV-276398r1146690_rule
Checks: C-80553r1146688_chk
Review configuration settings to confirm "Allow messages to be moved" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow messages to be moved" is unchecked under the Exchange payload. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Apple visionOS management tool containing the Exchange policy. 5. Tap "Mail". 6. Tap the name of the Exchange account. 7. Verify "Prevent Move" is set to "Yes". If "Allow messages to be moved" is checked in the Apple visionOS management tool or the Exchange policy on the Vision Pro has "Prevent Move" set to "No", this is a finding.
Fix: F-80458r1146689_fix
Install a configuration profile to prevent Exchange messages from being moved or forwarded between email accounts.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-002007
- Version
- AVOS-02-011500
- Vuln IDs
-
- V-276399
- Rule IDs
-
- SV-276399r1146693_rule
Checks: C-80554r1146691_chk
Review configuration settings to confirm "Treat AirDrop as an unmanaged destination" is enabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Treat AirDrop as unmanaged destination" is checked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the c0onfiguration management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Sharing managed documents using AirDrop not allowed" is listed. If "Treat AirDrop as unmanaged destination" is disabled in the Apple visionOS management tool or the restrictions policy on the Vision Pro does not list "Sharing managed documents using AirDrop not allowed", this is a finding.
Fix: F-80459r1146692_fix
Install a configuration profile to treat AirDrop as an unmanaged destination.
- RMF Control
- CM-7
- Severity
- M
- CCI
- CCI-000381
- Version
- AVOS-02-011900
- Vuln IDs
-
- V-276400
- Rule IDs
-
- SV-276400r1148316_rule
Checks: C-80555r1146694_chk
Review a sample of site User Agreements for visionOS device users or similar training records and training course content. Verify Vision Pro users have completed required training. If any Vision Pro user has not completed required training, this is a finding.
Fix: F-80460r1148315_fix
Have all Vision Pro users complete training on the following topics. Users must acknowledge receipt of training via a signed User Agreement or similar written record. Training topics: - Operational security concerns introduced by unmanaged applications, including applications using global positioning system (GPS) tracking. - Must ensure no DOD data is saved in an unmanaged app or transmitted from a personal app (for example, from personal email). - If the Purebred key management app is used, users are responsible for always maintaining positive control of their credentialed device. The DOD PKI certificate policy requires subscribers to maintain positive control of the devices that contain private keys and report any loss of control so the credentials can be revoked. Upon device retirement, turn in, or reassignment, ensure a factory data reset is performed prior to device handoff. Follow mobility service provider decommissioning procedures as applicable. - How to configure the following UBE controls (users must configure the control) and other controls on the Vision Pro: ** Never enable Guest User Mode. Use is prohibited. ** Never enable Developer Mode. Use is prohibited. - AO guidance on acceptable use and restrictions, if any, on downloading and installing personal apps and data (music, photos, etc.). - The Developer Strap must not be used with a DOD Vision Pro device without the explicit approval of the AO. - How to disable Bluetooth when Bluetooth use is not approved by the AO.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-012000
- Vuln IDs
-
- V-276401
- Rule IDs
-
- SV-276401r1146699_rule
Checks: C-80556r1146697_chk
Review configuration settings to confirm a managed photos app is installed on the visionOS device. This check procedure is performed on the Vision Pro. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the DOD Configuration Profile from the Apple visionOS management tool. 5. Tap "Apps". 6. Verify a photo capture and management app is listed. If a managed photo capture and management app is not installed on the Vision Pro, this is a finding.
Fix: F-80461r1146698_fix
Install a managed photos app to take and manage work-related photos.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- AVOS-02-012300
- Vuln IDs
-
- V-276402
- Rule IDs
-
- SV-276402r1146702_rule
Checks: C-80557r1146700_chk
Review configuration settings to confirm "Allow managed apps to write contacts to unmanaged contacts accounts" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Apple visionOS device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow managed apps to write contacts to unmanaged contacts accounts" is unchecked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Allow managed apps to write contacts to unmanaged contacts accounts" is not listed. If "Allow managed apps to write contacts to unmanaged contacts accounts" is checked in the visionOS management tool or the restrictions policy on the Vision Pro lists "Allow managed apps to write contacts to unmanaged contacts accounts", this is a finding.
Fix: F-80462r1146701_fix
Install a configuration profile to prevent managed apps from writing contacts to unmanaged contacts accounts.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- AVOS-02-012400
- Vuln IDs
-
- V-276403
- Rule IDs
-
- SV-276403r1146705_rule
Checks: C-80558r1146703_chk
Review configuration settings to confirm "Allow unmanaged apps to read contacts from managed contacts accounts" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow unmanaged apps to read contacts from managed contacts accounts" is unchecked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Allow unmanaged apps to read contacts from managed contacts accounts" is not listed. If "Allow unmanaged apps to read contacts from managed contacts accounts" is checked in the visionOS management tool or the restrictions policy on the Vision Pro lists "Allow unmanaged apps to read contacts from managed contacts accounts", this is a finding.
Fix: F-80463r1146704_fix
Install a configuration profile to prevent unmanaged apps from reading contacts from managed contacts accounts.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-012500
- Vuln IDs
-
- V-276404
- Rule IDs
-
- SV-276404r1146708_rule
Checks: C-80559r1146706_chk
Review configuration settings to confirm it is disabled. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify "Allow AirDrop" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the iOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "AirDrop not allowed" is listed. If "AirDrop not allowed" is not listed in the management tool and on the Apple device, this is a finding.
Fix: F-80464r1146707_fix
Install a configuration profile to disable the AllowAirDrop control in the management tool. This is a supervised-only control.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-012700
- Vuln IDs
-
- V-276405
- Rule IDs
-
- SV-276405r1146711_rule
Checks: C-80560r1146709_chk
This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Password AutoFill is not allowed" is disabled. This check procedure is performed on both the visionOS device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Password AutoFill is not allowed" is unchecked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Password AutoFill is not allowed" is listed. If "Password AutoFill is not allowed" is not enabled in the visionOS management tool and on the Apple device, this is a finding.
Fix: F-80465r1146710_fix
Install a configuration profile to disable allow Password AutoFill in the management tool. This is a supervised-only control.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-013000
- Vuln IDs
-
- V-276406
- Rule IDs
-
- SV-276406r1146714_rule
Checks: C-80561r1146712_chk
This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Password Sharing is not allowed" is enabled. This check procedure is performed on both the device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Password Sharing is not allowed" is checked. On the visionOS: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Password Sharing is not allowed" is listed. If "Password Sharing is not allowed" is not enabled in the management tool and on the Apple device, this is a finding.
Fix: F-80466r1146713_fix
Install a configuration profile to disable allow password proximity sharing in the management tool. This is a supervised-only control.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-013200
- Vuln IDs
-
- V-276407
- Rule IDs
-
- SV-276407r1146717_rule
Checks: C-80562r1146715_chk
Review configuration settings to confirm site-managed visionOS devices are supervised. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify all managed Apple devices are supervised (verification procedure will vary by MDM product). Note: If the Apple device is not managed by an MDM and supervision is set up via Apple Configurator, this procedure is not applicable. On the Vision Pro: 1. Open the Settings app. 2. Verify a message similar to the following appears on the screen: "This AVP is supervised by (name of site DOD mobile service provider)." If site-managed visionOS devices are not supervised, this is a finding.
Fix: F-80467r1146716_fix
Use one of the following methods to supervise visionOS devices managed by the DOD mobile service provider. Method 1: - Register all current and new visionOS devices in the DOD mobile service provider's Automated Device Management/Apple Business Manager (ABM) account. - Enable supervision of managed visionOS devices in the MDM. Method 2: - Configure each visionOS device using the Apple Configurator tool for Supervision. - This method is usually only appropriate when MDM management of the DOD Apple device is not appropriate or an older device cannot be registered in ABM.
- RMF Control
- SC-28
- Severity
- L
- CCI
- CCI-001199
- Version
- AVOS-02-013400
- Vuln IDs
-
- V-276408
- Rule IDs
-
- SV-276408r1146720_rule
Checks: C-80563r1146718_chk
Review configuration settings to confirm "Allow sending diagnostic and usage data to Apple" is disabled. This check procedure is performed on both the visionOS management tool and the visionOS device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow sending diagnostic and usage data to Apple" is unchecked. Alternatively, verify the text "<key>allowDiagnosticSubmission</key><false/>" appears in the configuration profile (.mobileconfig file). On the Apple visionOS device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the management policy. 5. Tap "Restrictions". 6. Verify "Diagnostic submission not allowed". Note: This setting also disables "Share With App Developers". If "Allow sending diagnostic and usage data to Apple" is checked in the visionOS management tool, "<key>allowDiagnosticSubmission</key><true/>" appears in the configuration profile, or the restrictions policy on the Apple visionOS device from the Apple visionOS management tool does not list "Diagnostic submission not allowed", this is a finding.
Fix: F-80468r1146719_fix
Install a configuration profile to disable sending diagnostic data to an organization other than DOD.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-013500
- Vuln IDs
-
- V-276409
- Rule IDs
-
- SV-276409r1146723_rule
Checks: C-80564r1146721_chk
Review configuration settings to confirm configuration profiles are not removable. This check procedure is performed on both the Apple visionOS management tool and the Apple visionOS device. The procedures below assume the site is not enrolled in Apple's Automatic Device Enrollment and are not applicable to devices under MDM management. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Security" is set to "Never" and "Automatically Remove Profile" is set to "Never". On the Apple visionOS device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap each Configuration Profile from the Apple visionOS management tool that contains the restrictions for the device. 5. Verify the "Remove Profile" button is not present. If on the Apple visionOS management tool or the visionOS device the "Remove Profile" button is available on the configuration profile, this is a finding.
Fix: F-80469r1146722_fix
Configure the Apple visionOS configuration profile so that it can never be removed. The procedure for implementing this control will vary depending on the MDM/EMM used by the mobile service provider. When using Apple Configurator, under "General Security", configure "Security" to "Never" and "Automatically Remove Profile" to "Never".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-014300
- Vuln IDs
-
- V-276410
- Rule IDs
-
- SV-276410r1146726_rule
Checks: C-80565r1146724_chk
This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. This check procedure is performed on both the device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow network drive access in Files access" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Network drives not accessible in Files app" is listed. If "Allow network drive access in Files access" is not disabled in the management tool and "Network drives not accessible in Files app" is not listed in Profile Restrictions on the Apple device, this is a finding.
Fix: F-80470r1146725_fix
Install a configuration profile to disable "Allow network drive access in Files access".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-014400
- Vuln IDs
-
- V-276411
- Rule IDs
-
- SV-276411r1146729_rule
Checks: C-80566r1146727_chk
If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Disable connections to Siri servers for the purpose of dictation" is disabled. This check procedure is performed on the device management tool. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Disable connections to Siri servers for the purpose of dictation" is checked. If connections to Siri servers are not disabled for dictation, this is a finding.
Fix: F-80471r1146728_fix
Configure the Apple visionOS configuration profile to disable connections to Siri servers for the purpose of dictation. This is a supervised-only control. The procedure for implementing this control will vary depending on the MDM/EMM used by the mobile service provider. In the MDM console, select "disable connections to Siri servers for the purpose of dictation".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-014600
- Vuln IDs
-
- V-276412
- Rule IDs
-
- SV-276412r1146732_rule
Checks: C-80567r1146730_chk
Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Require managed pasteboard" is set to "True". If "Require managed pasteboard" is not set to "True", this is a finding.
Fix: F-80472r1146731_fix
Configure the Apple visionOS configuration profile to disable copy/paste of data from managed to unmanaged applications. The procedure for implementing this control will vary depending on the MDM/EMM used by the mobile service provider. In the MDM console, set "Require managed pasteboard" to "True".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000370
- Version
- AVOS-02-014700
- Vuln IDs
-
- V-276413
- Rule IDs
-
- SV-276413r1146735_rule
Checks: C-80568r1146733_chk
Verify DOD intermediate and root certificates have been installed on Apple devices. In the visionOS management tool, verify the DOD intermediate and root certificates are installed on the Apple device. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Tap "More Details". 7. Verify the DOD intermediate and root certificates are listed. If DOD intermediate and root certificates are not installed on the Apple device, this is a finding.
Fix: F-80473r1146734_fix
Install DOD intermediate and root certificates on managed mobile devices using the MDM.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-015400
- Vuln IDs
-
- V-276414
- Rule IDs
-
- SV-276414r1147116_rule
Checks: C-80569r1147115_chk
This check procedure is performed on the device management tool and the device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify the following controls are set to Disable (the text may vary, depending on the UEM/MDM product): -Allow External Intelligence Integrations. -Allow External Intelligence Integrations Sign In. On the Vision Pro (Apple Intelligence capable device only): 1. Settings >> Apple Intelligence & Siri >> ChatGPT. 2. Verify "ChatGPT" is grayed out and disabled. If ChatGPT and other external AI app connections are not disabled in the management tool or are not grayed out and disabled on the Vision Pro, this is a finding.
Fix: F-80474r1146737_fix
Install a configuration profile to disable ChatGPT and other external AI app connections for Apple Intelligence. -Set "allowExternalIntelligenceIntegrations" to "False". -Set "allowExternalIntelligenceIntegrationsSignIn" to "False".
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-015500
- Vuln IDs
-
- V-276415
- Rule IDs
-
- SV-276415r1146741_rule
Checks: C-80570r1146739_chk
This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. This check procedure is performed on both the device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow installing configuration profiles (supervised only)" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Installing configuration profiles not allowed" is listed. If "Allow installing configuration profiles" is not disabled in the management tool, this is a finding.
Fix: F-80475r1146740_fix
Install a configuration profile to disable the installation of new configuration profiles. This will block the download and installation of beta visionOS updates. This is a supervised-only control.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- AVOS-02-015900
- Vuln IDs
-
- V-276416
- Rule IDs
-
- SV-276416r1146744_rule
Checks: C-80571r1146742_chk
Interview the site information system security officer (ISSO) and AVP users. Determine if the AVP Developer Strap is used at the site. If yes, verify the AO has approved its use by reviewing approval documentation. Verify AVP users are trained to not use the AVP developer Strap without AO approval (AVOS-02-011900). If the AVP Developer Strap is used at the site without AO approval, this is a finding.
Fix: F-80476r1146743_fix
Train AVP users to not connect and use the Developer Strap unless the AO has approved its use for a specific use case (refer to AVOS-02-011900). AO use approval must be documented and must detail specific use cases for which its use is approved.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-016000
- Vuln IDs
-
- V-276417
- Rule IDs
-
- SV-276417r1146747_rule
Checks: C-80572r1146745_chk
Review configuration settings to confirm it is disabled. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify "Allow erase all content and settings" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Vision Pro management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Erase content and settings not allowed" is listed. If "Allow erase all content and settings" is not disabled in the management tool and on the Apple device, this is a finding.
Fix: F-80477r1146746_fix
Install a configuration profile to disable "Allow Erase All Content and Settings". This is a supervised-only control.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- AVOS-02-017300
- Vuln IDs
-
- V-276419
- Rule IDs
-
- SV-276419r1146753_rule
Checks: C-80574r1146751_chk
Review configuration settings to confirm it is disabled. Note: this control is only applicable to Apple Intelligence capable Vision Pros. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify the Apple Intelligence feature: Image Generation is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Vision Pro management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Image Playground not allowed" is listed. If Image Generation is not disabled in the management tool and on the Apple device, this is a finding.
Fix: F-80479r1146752_fix
Install a configuration profile to disable Apple Intelligence feature: Image Generation. This is a supervised-only control.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- AVOS-02-017400
- Vuln IDs
-
- V-276420
- Rule IDs
-
- SV-276420r1146756_rule
Checks: C-80575r1146754_chk
Review configuration settings to confirm it is disabled. Note: this control is only applicable to Apple Intelligence capable Vision Pro. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify the Apple Intelligence feature: generate new Genmoji is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Genmoji not allowed" is listed. If generate new Genmoji is not disabled in the management tool and on the Apple device, this is a finding.
Fix: F-80480r1146755_fix
Install a configuration profile to disable Apple Intelligence feature: generate new Genmoji. This is a supervised-only control.
- RMF Control
- CM-6
- Severity
- M
- CCI
- CCI-000366
- Version
- AVOS-02-017700
- Vuln IDs
-
- V-276421
- Rule IDs
-
- SV-276421r1147110_rule
Checks: C-80576r1147108_chk
Confirm an MTD app is installed on managed Vision Pro. This check procedure is performed on both the device management tool and the Vision Pro device. In the Vision Pro management tool, verify an MTD app is listed as a managed app being deployed to site managed devices. On the Vision Pro device: 1. Open the Settings app. 2. Tap "Apps". 3. Verify an MTD app is listed. If an MTD app is not installed on the device, this is a finding.
Fix: F-80481r1146758_fix
Deploy a site approved MTD app via the MDM server to manage Vision Pro.
- RMF Control
- CM-6
- Severity
- L
- CCI
- CCI-000366
- Version
- AVOS-02-018000
- Vuln IDs
-
- V-276422
- Rule IDs
-
- SV-276422r1148317_rule
Checks: C-80577r1146760_chk
Review configuration settings to confirm screenshot and screen recording is disabled. This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify "Allow screenshot and screen recording" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the configuration profile from the Vision Pro management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Screen capture not allowed" is listed. If "Allow screenshot and screen recording" is listed in the management tool or "Screen capture not allowed" is not listed on the Apple device, this is a finding.
Fix: F-80482r1146761_fix
Install a configuration profile to disable the screenshot and screen recording.