Apple visionOS 26 Security Technical Implementation Guide - V1R1

  • Version/Release: V1R1
  • Published: 2026-03-10
  • Released: 2026-02-26
  • Expand All:
  • Severity:
  • Sort:
Compare

Select any two versions of this STIG to compare the individual requirements

View

Select any old version/release of this STIG to view the previous requirements

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.
a
Apple visionOS 26 must allow the administrator (MDM) to perform the following management function: enable/disable VPN protection across the device and [selection: on a per-app basis, on a per-group of applications processes basis].
AC-17 - Low - CCI-000068 - V-282783 - SV-282783r1195664_rule
RMF Control
AC-17
Severity
Low
CCI
CCI-000068
Version
AVOS-26-001000
Vuln IDs
  • V-282783
Rule IDs
  • SV-282783r1195664_rule
The system administrator must have the capability to configure VPN access to meet organization-specific policies based on mission needs. Otherwise, a user could inadvertently or maliciously set up a VPN and connect to a network that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFR ID: FMT_SMF.1.1 #3
Checks: C-87344r1195662_chk

Review the list of unmanaged apps installed on the Vision Pro and determine if any unmanaged third-party VPN clients are installed. If so, verify the VPN app is not configured with a DOD network (work) VPN profile. This validation procedure is performed on the visionOS device only. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap the "VPN and Device Management" line and determine if any "Personal VPN" exists. 4. If not, the requirement has been met. 5. If there are personal VPNs, open each VPN app. Review the list of VPN profiles configured on the VPN client. 6. Verify no DOD network VPN profiles are configured on the VPN client. If any third-party unmanaged VPN apps are installed (personal VPN) and they have a DOD network VPN profile configured on the client, this is a finding. Note: This setting cannot be managed by the MDM administrator and is a User-Based Enforcement (UBE) requirement.

Fix: F-87249r1195663_fix

If a third-party unmanaged VPN app is installed on the visionOS 26 device, do not configure the VPN app with a DOD network VPN profile.

b
Apple visionOS 26 must not allow backup to remote systems (iCloud).
SC-4 - Medium - CCI-001090 - V-282784 - SV-282784r1195667_rule
RMF Control
SC-4
Severity
Medium
CCI
CCI-001090
Version
AVOS-26-003000
Vuln IDs
  • V-282784
Rule IDs
  • SV-282784r1195667_rule
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFR ID: FMT_MOF_EXT.1.2 #40
Checks: C-87345r1195665_chk

Note: This requirement is not applicable if the authorizing official (AO) has approved users' full access to the Apple App Store for downloading unmanaged (personal) apps and syncing personal data on the device with personal cloud data storage accounts. The site must have an AO-signed document showing the AO has assumed the risk for users' full access to the Apple App Store. Review configuration settings to confirm iCloud Backup is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow iCloud backup" is unchecked. Alternatively, verify the text "<key>allowCloudBackup</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the policy. 5. Tap "Restrictions". 6. Verify "iCloud backup not allowed". If "Allow iCloud backup" is checked in the Apple visionOS management tool, "<key>allowCloudBackup</key><true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "iCloud backup not allowed", this is a finding.

Fix: F-87250r1195666_fix

Install a configuration profile to disable iCloud backup.

b
Apple visionOS 26 must not allow backup to remote systems (iCloud document and data synchronization).
SC-4 - Medium - CCI-001090 - V-282785 - SV-282785r1195670_rule
RMF Control
SC-4
Severity
Medium
CCI
CCI-001090
Version
AVOS-26-003200
Vuln IDs
  • V-282785
Rule IDs
  • SV-282785r1195670_rule
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFR ID: FMT_MOF_EXT.1.2 #40
Checks: C-87346r1195668_chk

Note: This requirement is not applicable if the authorizing official (AO) has approved users' full access to the Apple App Store for downloading unmanaged (personal) apps and syncing personal data on the device with personal cloud data storage accounts. The site must have an AO-signed document showing the AO has assumed the risk for users' full access to the Apple App Store. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Allow iCloud documents & data" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow iCloud documents & data" is unchecked. Alternatively, verify the text "<key>allowCloudDocumentSync</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the policy. 5. Tap "Restrictions". 6. Verify "Documents in the Cloud not allowed" is listed. Note: This also verifies that iCloud Drive and iCloud Photo Library are disabled. If "Allow iCloud documents & data" is checked in the Apple visionOS management tool, "<key>allowCloudDocumentSync</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Documents in the Cloud not allowed", this is a finding.

Fix: F-87251r1195669_fix

Install a configuration profile to disable iCloud documents and data. This is a supervised-only control.

b
Apple visionOS 26 must not allow backup to remote systems (iCloud Keychain).
SC-4 - Medium - CCI-001090 - V-282786 - SV-282786r1195673_rule
RMF Control
SC-4
Severity
Medium
CCI
CCI-001090
Version
AVOS-26-003300
Vuln IDs
  • V-282786
Rule IDs
  • SV-282786r1195673_rule
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFR ID: FMT_MOF_EXT.1.2 #40
Checks: C-87347r1195671_chk

Note: This requirement is not applicable if the authorizing official (AO) has approved users' full access to the Apple App Store for downloading unmanaged (personal) apps and syncing personal data on the device with personal cloud data storage accounts. The site must have an AO-signed document showing the AO has assumed the risk for users' full access to the Apple App Store. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm iCloud keychain is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow iCloud keychain" is unchecked. Alternatively, verify the text "<key>allowCloudKeychainSync</key><false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the management policy. 5. Verify "iCloud Keychain not allowed" is listed. If "Allow iCloud keychain" is checked in the Apple visionOS management tool, "<key>allowCloudKeychainSync</key><true/>" appears in the configuration profile, or "iCloud Keychain not allowed" is not listed on the Vision Pro, this is a finding.

Fix: F-87252r1195672_fix

Install a configuration profile to disable iCloud keychain. This is a supervised-only control.

b
Apple visionOS 26 must not allow backup to remote systems (Cloud Photo Library).
SC-4 - Medium - CCI-001090 - V-282787 - SV-282787r1195676_rule
RMF Control
SC-4
Severity
Medium
CCI
CCI-001090
Version
AVOS-26-003450
Vuln IDs
  • V-282787
Rule IDs
  • SV-282787r1195676_rule
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFR ID: FMT_MOF_EXT.1.2 #40
Checks: C-87348r1195674_chk

Note: This requirement is not applicable if the authorizing official (AO) has approved users' full access to the Apple App Store for downloading unmanaged (personal) apps and syncing personal data on the device with personal cloud data storage accounts. The site must have an AO-signed document showing the AO has assumed the risk for users' full access to the Apple App Store. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Allow Cloud Photo Library" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow Cloud Photo Library" is unchecked. Alternatively, verify the text "<key>allowCloudPhotoLibrary</key><false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "iCloud Photos not allowed" is listed. If "Allow Cloud Photo Library" is checked in the Apple visionOS management tool, "<key>allowCloudPhotoLibrary</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "iCloud Photos not allowed", this is a finding.

Fix: F-87253r1195675_fix

Install a configuration profile to disable Cloud Photo Library. This is a supervised-only control.

b
Apple visionOS 26 must not allow backup to remote systems (managed applications data stored in iCloud).
SC-4 - Medium - CCI-001090 - V-282788 - SV-282788r1195679_rule
RMF Control
SC-4
Severity
Medium
CCI
CCI-001090
Version
AVOS-26-003600
Vuln IDs
  • V-282788
Rule IDs
  • SV-282788r1195679_rule
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFR ID: FMT_MOF_EXT.1.2 #40
Checks: C-87349r1195677_chk

Review configuration settings to confirm "Allow managed apps to store data in iCloud" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow managed apps to store data in iCloud" is unchecked. Alternatively, verify the text "<key>allowManagedAppsCloudSync</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Managed apps cloud sync not allowed" is listed. If "Allow managed apps to store data in iCloud" is checked in the Apple visionOS management tool, "<key>allowManagedAppsCloudSync</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Managed apps cloud sync not allowed", this is a finding.

Fix: F-87254r1195678_fix

Install a configuration profile to prevent DOD applications from storing data in iCloud.

b
Apple visionOS 26 must be configured to enforce a minimum password length of six characters.
- Medium - CCI-004066 - V-282789 - SV-282789r1195682_rule
RMF Control
Severity
Medium
CCI
CCI-004066
Version
AVOS-26-006500
Vuln IDs
  • V-282789
Rule IDs
  • SV-282789r1195682_rule
Password strength is a measure of the effectiveness of a password in resisting guessing and brute-force attacks. The ability to crack a password is a function of how many attempts an adversary is permitted, how quickly an adversary can do each attempt, and the size of the password space. The longer the minimum length of the password is, the larger the password space. Having a too-short minimum password length significantly reduces password strength, increasing the chance of password compromise and resulting device and data compromise. SFR ID: FMT_SMF.1.1 #1
Checks: C-87350r1195680_chk

Review configuration settings to confirm the minimum passcode length is six or more characters. This procedure is performed in the Apple visionOS management tool and on the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Management tool, verify the "Minimum passcode length" value is set to six or greater. Alternatively, verify the text "<key>minLength</key> <integer>6</integer>" appears in the configuration profile (.mobileconfig file). An integer value of greater than six is also acceptable. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Minimum length" is listed as "six or greater". If the "Minimum passcode length" is less than six characters in the visionOS management tool, "<key>minLength</key> " has an integer value of less than six, or the password policy on the Vision Pro from the Apple visionOS management tool does not list "Minimum length" of six or more, this is a finding.

Fix: F-87255r1195681_fix

Install a configuration profile to enforce a minimum passcode length value of six or greater.

b
Apple visionOS 26 must be configured to not allow passwords that include more than four repeating or sequential characters.
- Medium - CCI-004066 - V-282790 - SV-282790r1195685_rule
RMF Control
Severity
Medium
CCI
CCI-004066
Version
AVOS-26-006600
Vuln IDs
  • V-282790
Rule IDs
  • SV-282790r1195685_rule
Password strength is a measure of the effectiveness of a password in resisting guessing and brute-force attacks. Passwords that contain repeating or sequential characters are significantly easier to guess than those that do not contain repeating or sequential characters. Therefore, disallowing repeating or sequential characters increases password strength and decreases risk. SFR ID: FMT_SMF.1.1 #1
Checks: C-87351r1195683_chk

Review configuration settings to confirm simple passcodes are not allowed. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow simple value" is unchecked. Alternatively, verify the text "<key>allowSimple</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Simple passcodes allowed" is set to "No". If "Allow simple value" is checked in the Apple visionOS management tool, "<key>allowSimple</key> <true/>" appears in the Configuration Profile, or the password policy on the Vision Pro does not have "Simple passcodes allowed" set to "No", this is a finding.

Fix: F-87256r1195684_fix

Install a configuration profile to disallow more than four sequential or repeating numbers or letters in the device unlock password.

b
Apple visionOS 26 must be configured to lock the display after 15 minutes (or less) of inactivity.
AC-11 - Medium - CCI-000057 - V-282791 - SV-282791r1195688_rule
RMF Control
AC-11
Severity
Medium
CCI
CCI-000057
Version
AVOS-26-006800
Vuln IDs
  • V-282791
Rule IDs
  • SV-282791r1195688_rule
The screen lock timeout must be set to a value that helps protect the device from unauthorized access. Having a too-long timeout would increase the window of opportunity for adversaries who gain physical access to the mobile device through loss, theft, etc. Such devices are much more likely to be in an unlocked state when acquired by an adversary, thus granting immediate access to the data on the mobile device. The maximum timeout period of 15 minutes has been selected to balance functionality and security; shorter timeout periods may be appropriate depending on the risks posed to the mobile device. SFR ID: FMT_SMF.1.1 #2
Checks: C-87352r1195686_chk

Review configuration settings to confirm the screen lock timeout is set to 15 minutes or less. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the management tool, verify the sum of the values assigned to "Maximum Auto-Lock time" and "Grace period for device lock" is between 1 and 15 minutes. Alternatively, locate the text "<key>maxGracePeriod</key>" and "<key>maxInactivity</key>" and ensure the sum of their integer value is between 1 and 15 in the configuration profile (.mobileconfig file). For example: "<key>maxGracePeriod</key> <integer>5</integer> <key>maxInactivity</key> <integer>5</integer>" Here, 5 + 5 = 10; this meets the requirement. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify the sum of the "Max grace period" and "Max inactivity" values is less than 15 minutes. Note: On some visionOS devices, it is not possible to have a sum of exactly 15. In these cases, the sum must be less than 15. A sum of 16 does not meet the requirement. On the management server, if the sum of the "Max grace period" and "Max inactivity" values is not between 1 and 15 minutes in the visionOS management tool, or the sum of the values assigned to "<key>maxGracePeriod</key>" and "<key>maxInactivity</key>" is not between 1 and 15 minutes in the configuration profile, or if on the Vision Pro, the sum of the values assigned to "Max grace period" and "Max inactivity" is not between 1 and 15 minutes, this is a finding.

Fix: F-87257r1195687_fix

Install a configuration profile to lock the device display after 15 minutes (or less) of inactivity. This is done by setting "Maximum Auto-Lock time" and "Grace Period for device lock" so the sum of their values is between 1 and 15 minutes.

b
Apple visionOS 26 must be configured to not allow more than 10 consecutive failed authentication attempts.
AC-7 - Medium - CCI-000044 - V-282792 - SV-282792r1195691_rule
RMF Control
AC-7
Severity
Medium
CCI
CCI-000044
Version
AVOS-26-006900
Vuln IDs
  • V-282792
Rule IDs
  • SV-282792r1195691_rule
The more attempts an adversary has to guess a password, the more likely the adversary will enter the correct password and gain access to resources on the device. Setting a limit on the number of attempts mitigates this risk. Setting the limit at 10 or fewer gives authorized users the ability to make a few mistakes when entering the password but still provides adequate protection against dictionary or brute-force attacks on the password. SFR ID: FMT_SMF.1.1 #2, FIA_AFL_EXT.1.5
Checks: C-87353r1195689_chk

Review configuration settings to confirm that consecutive failed authentication attempts is set to 10 or fewer. This procedure is performed in the Apple visionOS management tool and on the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Management tool, verify the "Maximum number of failed attempts" value is set to 10 or fewer. Alternatively, verify the text "<key>maxFailedAttempts</key> <integer>10</integer>" appears in the configuration profile (.mobileconfig file). An integer value of less than 10 is also acceptable. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Max failed attempts" is listed as "10" or fewer. If the "Maximum number of failed attempts" is more than 10 in the visionOS management tool, "<key>maxFailedAttempts</key> " has an integer value of more than 10, or the password policy on the Vision Pro does not list "Max failed attempts" of 10 or fewer, this is a finding.

Fix: F-87258r1195690_fix

Install a configuration profile to allow only 10 or fewer consecutive failed authentication attempts.

c
Apple visionOS 26 must be configured to enforce a passcode reuse prohibition of at least two generations.
- High - CCI-004061 - V-282793 - SV-282793r1195694_rule
RMF Control
Severity
High
CCI
CCI-004061
Version
AVOS-26-006950
Vuln IDs
  • V-282793
Rule IDs
  • SV-282793r1195694_rule
visionOS-iPadOS 17 and later versions include a feature that allows the previous passcode to be valid for 72 hours after a passcode change. If the previous passcode has been compromised and the attacker has access to it and the Apple device, enterprise data and the enterprise network can be compromised. Currently there is no MDM control to force the old passcode to expire immediately after passcode change. The previous passcode will expire immediately after a passcode change if the MDM password history control is implemented. SFR ID: FMT_SMF.1.1 #47
Checks: C-87354r1195692_chk

Review configuration settings to confirm the Apple visionOS device has a passcode reuse prohibition of at least two generations. This procedure is performed in the Apple visionOS management tool and on the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Management tool, verify the "Passcode History" value is set to two or greater. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Number of unique recent passcodes required" is listed as "two" or greater. If the Apple visionOS device does not enforce a passcode reuse prohibition of at least two generations, this is a finding.

Fix: F-87259r1195693_fix

Install a configuration profile to enforce a passcode reuse prohibition of at least two generations (passcode history).

b
Apple visionOS 26 must be configured to enforce an application installation policy by specifying one or more authorized application repositories, including [selection: DOD-approved commercial app repository, MDM server, mobile application store].
CM-6 - Medium - CCI-000366 - V-282794 - SV-282794r1195697_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-007000
Vuln IDs
  • V-282794
Rule IDs
  • SV-282794r1195697_rule
Forcing all applications to be installed from authorized application repositories can prevent unauthorized and malicious applications from being installed and executed on mobile devices. Allowing such installations and executions could cause a compromise of DOD data accessible by these unauthorized/malicious applications. SFR ID: FMT_SMF.1.1 #8
Checks: C-87355r1195695_chk

Review configuration settings to confirm "Allow Trusting New Enterprise App Authors" is disabled. This procedure is performed in the Apple visionOS management tool and on the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Management tool, verify "Allow Trusting New Enterprise App Authors" is disabled. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Trusting enterprise apps not allowed" is listed. If "Allow Trusting New Enterprise App Authors" is not disabled in the visionOS management tool or on the Vision Pro, this is a finding.

Fix: F-87260r1195696_fix

Install a configuration profile to disable "Allow Trusting New Enterprise App Authors".

b
Apple visionOS 26 must be configured to not display notifications when the device is locked.
AC-11 - Medium - CCI-000060 - V-282795 - SV-282795r1195700_rule
RMF Control
AC-11
Severity
Medium
CCI
CCI-000060
Version
AVOS-26-007500
Vuln IDs
  • V-282795
Rule IDs
  • SV-282795r1195700_rule
Many mobile devices display notifications on the lock screen so users can obtain relevant information in a timely manner without having to frequently unlock the phone to determine if there are new notifications. However, in many cases, these notifications can contain sensitive information. When they are available on the lock screen, an adversary can see them merely by being in close physical proximity to the device. Configuring the mobile operating system to not send notifications to the lock screen mitigates this risk. SFR ID: FMT_SMF.1.1 #18
Checks: C-87356r1195698_chk

Review configuration settings to confirm the display of notifications when the device is locked has been disabled. This check procedure is performed on the Apple visionOS management tool and mobile device. In the Apple visionOS management tool, for each managed app, verify the app is configured to disable Notifications preview. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the management policy. 5. Tap "Apps". 6. Tap an app and verify "Disallow notification view in locked screen" is listed. Repeat steps 5 and 6 for each managed app in the list. If one or more managed apps are not set to disable showing notification view on locked screen, this is a finding.

Fix: F-87261r1195699_fix

Install a configuration profile to disable the display of notifications when the device is locked. Install a configuration profile to disable Notification Center from the device Lock screen.

a
Apple visionOS 26 must be configured to display the DOD advisory warning message at startup or each time the user unlocks the device.
AC-8 - Low - CCI-000048 - V-282796 - SV-282796r1196143_rule
RMF Control
AC-8
Severity
Low
CCI
CCI-000048
Version
AVOS-26-008400
Vuln IDs
  • V-282796
Rule IDs
  • SV-282796r1196143_rule
Before granting access to the system, the mobile operating system is required to display the DOD-approved system use notification message or banner that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. Required banners help ensure that DOD can audit and monitor the activities of mobile device users without legal restriction. System use notification messages can be displayed when individuals first access or unlock the mobile device. The banner must be implemented as a "click-through" banner at device unlock (to the extent permitted by the operating system). A "click-through" banner prevents further activity on the information system unless and until the user executes a positive action to manifest agreement by clicking on a box indicating "OK". The approved DOD text must be used exactly as required in the Knowledge Service referenced in DODI 8500.01. For devices accommodating banners of 1300 characters, the banner text is: You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details. For devices with severe character limitations, the banner text is: I've read & consent to terms in IS user agreem't. The administrator must configure the banner text exactly as written without any changes. SFR ID: FMT_SMF.1.1 #36
Checks: C-87357r1195701_chk

The DOD warning banner can be displayed by placing the DOD warning banner text in the user agreement signed by each Vision Pro user. (The required text is found in the Discussion.) Review the signed user agreements for several visionOS device users and verify the agreement includes the required DOD warning banner text. If the required warning banner text is not on all signed user agreements reviewed, this is a finding.

Fix: F-87262r1196142_fix

Configure the DOD warning banner by placing the DOD warning banner text in the user agreement signed by each visionOS device user. (The required text is found in the Discussion.) Note: Vision Pro does not support the LockScreenFootnote key.

b
Apple visionOS 26 must not allow non-DOD applications to access DOD data.
SC-39 - Medium - CCI-002530 - V-282797 - SV-282797r1195706_rule
RMF Control
SC-39
Severity
Medium
CCI
CCI-002530
Version
AVOS-26-009700
Vuln IDs
  • V-282797
Rule IDs
  • SV-282797r1195706_rule
App data sharing gives apps the ability to access the data of other apps for enhanced user functionality. However, sharing also poses a significant risk that unauthorized users or apps will obtain access to sensitive DOD information. Data sharing restrictions mitigate this risk. If a user is allowed to make exceptions to the data sharing restriction policy, the user could enable unauthorized sharing of data, leaving it vulnerable to breach. Limiting the granting of exceptions to either the administrator or common application developer mitigates this risk. Copy/paste of data between applications in different application processes or groups of application processes is considered an exception to the access control policy; therefore, the administrator must be able to enable/disable the feature. Other exceptions include allowing any data or application sharing between process groups. SFR ID: FMT_SMF.1.1 #42, FDP_ACF_EXT.1.2
Checks: C-87358r1195704_chk

Review configuration settings to confirm "Allow documents from managed apps in unmanaged apps" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow documents from managed apps in unmanaged apps" is unchecked. Alternatively, verify the text "<key>allowOpenFromManagedToUnmanaged</key><false/>" appears in the configuration profile (.mobileconfig file). On the visionOS device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Opening documents from managed to unmanaged apps not allowed" is listed. If "Allow documents from managed apps in unmanaged apps" is checked in the visionOS management tool, "<key>allowOpenFromManagedToUnmanaged</key><true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Opening documents from managed to unmanaged apps not allowed", this is a finding.

Fix: F-87263r1195705_fix

Install a configuration profile to prevent non-DOD applications from accessing DOD data.

b
Apple visionOS 26 must be configured to [selection: wipe protected data, wipe sensitive data] upon unenrollment from MDM.
MP-6 - Medium - CCI-001033 - V-282798 - SV-282798r1195709_rule
RMF Control
MP-6
Severity
Medium
CCI
CCI-001033
Version
AVOS-26-009900
Vuln IDs
  • V-282798
Rule IDs
  • SV-282798r1195709_rule
When a mobile device is no longer going to be managed by MDM technologies, its protected/sensitive data must be sanitized because it will no longer be protected by the MDM software, putting it at much greater risk of unauthorized access and disclosure. At least one of the two options must be selected. SFR ID: FMT_SMF_EXT.2.1
Checks: C-87359r1195707_chk

Note: Not all Apple visionOS deployments involve MDM. If the site uses an authorized alternative to MDM for distribution of configuration profiles (Apple Configurator), this check procedure is not applicable. This check procedure is performed on the Apple visionOS management tool or on the visionOS device. In the Apple visionOS management tool, for each managed app, verify the app is configured to be removed when the MDM profile is removed. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the management policy. 5. Tap "Apps". 6. Tap an app and verify "App and data will be removed when device is no longer managed" is listed. Repeat steps 5 and 6 for each managed app in the list. If one or more managed apps are not set to be removed upon device MDM unenrollment, this is a finding.

Fix: F-87264r1195708_fix

Install a configuration profile to delete all managed apps upon device unenrollment.

b
Apple visionOS 26 must be configured to [selection: remove Enterprise applications, remove all noncore applications (any nonfactory-installed application)] upon unenrollment from MDM.
MP-6 - Medium - CCI-001033 - V-282799 - SV-282799r1195712_rule
RMF Control
MP-6
Severity
Medium
CCI
CCI-001033
Version
AVOS-26-010000
Vuln IDs
  • V-282799
Rule IDs
  • SV-282799r1195712_rule
When a mobile device is no longer going to be managed by MDM technologies, its protected/sensitive data must be sanitized because it will no longer be protected by the MDM software, putting it at much greater risk of unauthorized access and disclosure. At least one of the two options must be selected. SFR ID: FMT_SMF_EXT.2.1
Checks: C-87360r1195710_chk

Note: Not all Apple visionOS deployments involve MDM. If the site uses an authorized alternative to MDM for distribution of configuration profiles (Apple Configurator), this check procedure is not applicable. This check procedure is performed on the Apple visionOS management tool or on the visionOS device. In the Apple visionOS management tool, for each managed app, verify the app is configured to be removed when the MDM profile is removed. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the management policy. 5. Tap "Apps". 6. Tap an app and verify "App and data will be removed when device is no longer managed" is listed. Repeat steps 5 and 6 for each managed app in the list. If one or more managed apps are not set to be removed upon device MDM unenrollment, this is a finding.

Fix: F-87265r1195711_fix

Install a configuration profile to delete all managed apps upon device unenrollment.

b
Apple visionOS 26 must be configured to disable ad hoc wireless client-to-client connection capability.
SC-40 - Medium - CCI-002536 - V-282800 - SV-282800r1195715_rule
RMF Control
SC-40
Severity
Medium
CCI
CCI-002536
Version
AVOS-26-010200
Vuln IDs
  • V-282800
Rule IDs
  • SV-282800r1195715_rule
Ad hoc wireless client-to-client connections allow mobile devices to communicate with each other directly, circumventing network security policies and making the traffic invisible. This could allow the exposure of sensitive DOD data and increase the risk of downloading and installing malware on the DOD mobile device. SFR ID: FMT_SMF_EXT.1.1/WLAN
Checks: C-87361r1195713_chk

Review configuration settings to confirm AirDrop is disabled. If AirDrop is approved, this requirement is not applicable. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow AirDrop" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "AirDrop not allowed" is listed. If "AirDrop not allowed" is not listed in the management tool and on the Apple device, this is a finding.

Fix: F-87266r1195714_fix

Install a configuration profile to disable the AllowAirDrop control in the management tool. This is a supervised-only control.

c
Apple visionOS 26 must require a valid password be successfully entered before the mobile device data is unencrypted.
SC-28 - High - CCI-001199 - V-282801 - SV-282801r1196148_rule
RMF Control
SC-28
Severity
High
CCI
CCI-001199
Version
AVOS-26-010400
Vuln IDs
  • V-282801
Rule IDs
  • SV-282801r1196148_rule
Passwords provide a form of access control that prevents unauthorized individuals from accessing computing resources and sensitive data. Passwords may also be a source of entropy for generation of key encryption or data encryption keys. If a password is not required to access data, this data is accessible to any adversary who obtains physical possession of the device. Requiring that a password be successfully entered before the mobile device data is unencrypted mitigates this risk. Note: MDF PP requires a Password Authentication Factor and requires management of its length and complexity. It leaves open whether the existence of a password is subject to management. This requirement addresses the configuration to require a password, which is critical to the cybersecurity posture of the device. SFR ID: FIA_UAU_EXT.1.1
Checks: C-87362r1195716_chk

Review configuration settings to confirm the device is set to require a passcode before use. This procedure is performed on the visionOS device. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the password policy. 5. Tap "Restrictions". 6. Tap "Passcode". 7. Verify "Passcode required" is set to "Yes". If "Passcode required" is not set to "Yes", this is a finding.

Fix: F-87267r1195717_fix

Install a configuration profile to require a password to unlock the device.

a
Apple visionOS 26 must implement the management setting: not allow automatic completion of Safari browser passcodes.
CM-7 - Low - CCI-000381 - V-282802 - SV-282802r1195721_rule
RMF Control
CM-7
Severity
Low
CCI
CCI-000381
Version
AVOS-26-010600
Vuln IDs
  • V-282802
Rule IDs
  • SV-282802r1195721_rule
The AutoFill functionality in the Safari web browser allows the user to complete a form that contains sensitive information, such as Personally Identifiable Information, without previous knowledge of the information. By allowing the use of the AutoFill functionality, an adversary who learns a user's Vision Pro passcode, or who otherwise is able to unlock the device, may be able to further breach other systems by relying on the AutoFill feature to provide information unknown to the adversary. Disabling the AutoFill functionality significantly mitigates the risk of an adversary gaining additional information about the device's user or compromising other systems. SFR ID: FMT_SMF.1.1 #47
Checks: C-87363r1195719_chk

Review configuration settings to confirm "Enable autofill" is unchecked. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Enable autofill" is unchecked. Alternatively, verify the text "<key>safariAllowAutoFill</key><false>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the management policy. 5. Tap "Restrictions". 6. Verify "Auto-fill in Safari not allowed" is present. If "Enable autofill" is checked in the Apple visionOS management tool, "<key>safariAllowAutoFill</key><true>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Auto-fill in Safari not allowed", this is a finding.

Fix: F-87268r1195720_fix

Install a configuration profile to disable the AutoFill capability in the Safari app.

a
Apple visionOS 26 must implement the management setting: not allow use of Handoff.
CM-7 - Low - CCI-000381 - V-282803 - SV-282803r1195724_rule
RMF Control
CM-7
Severity
Low
CCI
CCI-000381
Version
AVOS-26-010800
Vuln IDs
  • V-282803
Rule IDs
  • SV-282803r1195724_rule
Handoff permits a Vision Pro user to transition user activities from one device to another. Handoff passes sufficient information between the devices to describe the activity, but app data synchronization associated with the activity is handled though iCloud, which should be disabled on a compliant Vision Pro. If a user associates both DOD and personal devices to the same Apple ID, the user may improperly reveal information about the nature of the user's activities on an unprotected device. Disabling Handoff mitigates this risk. SFR ID: FMT_SMF.1.1 #47
Checks: C-87364r1195722_chk

This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Allow Handoff" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow Handoff" is unchecked. Alternatively, verify the text "<key>allowActivityContinuation</key> <false/>" appears in the configuration profile (.mobileconfig file). On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Handoff not allowed" is listed. If "Allow Handoff" is checked in the Apple visionOS management tool, "<key>allowActivityContinuation</key> <true/>" appears in the configuration profile, or the restrictions policy on the Vision Pro does not list "Handoff not allowed", this is a finding.

Fix: F-87269r1195723_fix

Install a configuration profile to disable continuation of activities among devices and workstations. This is a supervised-only control.

b
Apple visionOS 26 must implement the management setting: disable Allow MailDrop.
AC-17 - Medium - CCI-002314 - V-282804 - SV-282804r1195727_rule
RMF Control
AC-17
Severity
Medium
CCI
CCI-002314
Version
AVOS-26-011000
Vuln IDs
  • V-282804
Rule IDs
  • SV-282804r1195727_rule
MailDrop allows users to send large attachments (up to 5 GB) via iCloud. Storing data with a non-DOD cloud provider may leave the data vulnerable to breach. Disabling non-DOD cloud services mitigates this risk. SFR ID: FMT_SMF.1.1 #47
Checks: C-87365r1195725_chk

Review configuration settings to confirm "Allow MailDrop" is disabled. This validation procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow MailDrop" is not checked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the restrictions policy. 5. Tap "Mail". 6. Tap the mail account. 7. Verify "Mail Drop Enabled" is set to "No". If "Allow MailDrop" is not disabled in the Apple visionOS management tool, or the restrictions policy on the Vision Pro lists "Mail Drop Enabled" as "Yes", this is a finding.

Fix: F-87270r1195726_fix

Configure the Apple visionOS configuration profile to disable "Allow MailDrop".

c
Vision Pro must have the latest available visionOS operating system installed.
CM-7 - High - CCI-000381 - V-282805 - SV-282805r1195730_rule
RMF Control
CM-7
Severity
High
CCI
CCI-000381
Version
AVOS-26-011200
Vuln IDs
  • V-282805
Rule IDs
  • SV-282805r1195730_rule
Required security features are not available in earlier OS versions. In addition, earlier versions may have known vulnerabilities. SFR ID: FMT_SMF.1.1 #47
Checks: C-87366r1195728_chk

Review configuration settings to confirm the most recently released version of visionOS is installed. This validation procedure is performed on both the Apple visionOS management tool and the Vision Pro. Go to https://www.apple.com and determine the most current version of visionOS released by Apple. In the MDM management console, review the version of visionOS installed on a sample of managed devices. This procedure will vary depending on the MDM product. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "About" and view the installed version of visionOS. 4. Go back to the "General" screen. Tap "Software Update" and verify the following message is shown on the screen: "Your software is up to date." If the installed version of visionOS on any reviewed visionOS devices is not the latest released by Apple, this is a finding.

Fix: F-87271r1195729_fix

Install the latest release version of Apple visionOS on all managed visionOS devices.

b
Apple visionOS 26 must implement the management setting: use SSL for Exchange ActiveSync.
IA-2 - Medium - CCI-000764 - V-282806 - SV-282806r1195733_rule
RMF Control
IA-2
Severity
Medium
CCI
CCI-000764
Version
AVOS-26-011300
Vuln IDs
  • V-282806
Rule IDs
  • SV-282806r1195733_rule
Exchange email messages are a form of data in transit and thus are vulnerable to eavesdropping and man-in-the-middle attacks. Secure Sockets Layer (SSL), also referred to as Transport Layer Security (TLS), provides encryption and authentication services that mitigate the risk of breach. SFR ID: FMT_SMF.1.1 #47
Checks: C-87367r1195731_chk

Review configuration settings to confirm "Use SSL" for the Exchange account is enabled for incoming mail. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Use SSL for incoming mail" is checked under the Exchange payload. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the Exchange policy. 5. Tap "Mail". 6. Tap the name of the Exchange account. 7. Verify "SSL for incoming mail" is set to "Yes". If "Use SSL for incoming mail" is unchecked in the Apple visionOS management tool, or the Exchange policy on the Vision Pro has "SSL for incoming mail" set to "No", this is a finding.

Fix: F-87272r1195732_fix

Install a configuration profile to use SSL for Exchange ActiveSync incoming mail.

b
Apple visionOS 26 must implement the management setting: not allow messages in an ActiveSync Exchange account to be forwarded or moved to other accounts in the Apple visionOS 26 Mail app.
IA-2 - Medium - CCI-000764 - V-282807 - SV-282807r1195736_rule
RMF Control
IA-2
Severity
Medium
CCI
CCI-000764
Version
AVOS-26-011400
Vuln IDs
  • V-282807
Rule IDs
  • SV-282807r1195736_rule
The Apple visionOS Mail app can be configured to support multiple email accounts concurrently. These email accounts are likely to involve content of varying degrees of sensitivity (e.g., both personal and enterprise messages). To prevent the unauthorized and undetected forwarding or moving of messages from one account to another, Mail ActiveSync Exchange accounts can be configured to block such behavior. While users may still send a message from the Exchange account to another account, these transactions must involve an Exchange server, enabling audit records of the transaction, filtering of mail content, and subsequent forensic analysis. SFR ID: FMT_SMF.1.1 #47
Checks: C-87368r1195734_chk

Review configuration settings to confirm "Allow messages to be moved" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Allow messages to be moved" is unchecked under the Exchange payload. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Apple visionOS management tool containing the Exchange policy. 5. Tap "Mail". 6. Tap the name of the Exchange account. 7. Verify "Prevent Move" is set to "Yes". If "Allow messages to be moved" is checked in the Apple visionOS management tool, or the Exchange policy on the Vision Pro has "Prevent Move" set to "No", this is a finding.

Fix: F-87273r1195735_fix

Install a configuration profile to prevent Exchange messages from being moved or forwarded between email accounts.

b
Apple visionOS 26 must implement the management setting: treat AirDrop as an unmanaged destination.
IA-5 - Medium - CCI-002007 - V-282808 - SV-282808r1195739_rule
RMF Control
IA-5
Severity
Medium
CCI
CCI-002007
Version
AVOS-26-011500
Vuln IDs
  • V-282808
Rule IDs
  • SV-282808r1195739_rule
AirDrop is a way to send contact information or photos to other users with AirDrop enabled. This feature enables a possible attack vector for adversaries to exploit. Once the attacker has gained access to the information broadcast by this feature, the attacker may distribute this sensitive information very quickly and without DOD's control or awareness. By disabling this feature, the risk of mass data exfiltration will be mitigated. Note: If the site uses Apple's optional Automatic Device Enrollment, this control is available as a supervised MDM control. SFR ID: FMT_SMF.1.1 #47
Checks: C-87369r1195737_chk

Review configuration settings to confirm "Treat AirDrop as an unmanaged destination" is enabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Treat AirDrop as unmanaged destination" is checked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Sharing managed documents using AirDrop not allowed" is listed. If "Treat AirDrop as unmanaged destination" is disabled in the Apple visionOS management tool, or the restrictions policy on the Vision Pro does not list "Sharing managed documents using AirDrop not allowed", this is a finding.

Fix: F-87274r1195738_fix

Install a configuration profile to treat AirDrop as an unmanaged destination.

b
Apple visionOS 26 must implement the management setting: not share location data through iCloud.
AC-8 - Medium - CCI-000048 - V-282809 - SV-282809r1196253_rule
RMF Control
AC-8
Severity
Medium
CCI
CCI-000048
Version
AVOS-26-011700
Vuln IDs
  • V-282809
Rule IDs
  • SV-282809r1196253_rule
Sharing of location data is an operational security risk because it potentially allows an adversary to determine a DOD user's location, movements, and patterns in those movements over time. An adversary could use this information to target the user or gather intelligence on the user's likely activities. Using commercial cloud services to store and handle location data could leave the data vulnerable to breach, particularly by sophisticated adversaries. Disabling the use of such services mitigates this risk. SFR ID: FMT_SMF.1.1 #47
Checks: C-87370r1195740_chk

Review configuration settings to confirm "Location Services" is disabled. Note that this is a User-Based Enforcement (UBE) control, which cannot be managed by an MDM server. This check procedure is performed on the iPhone and iPad only. On the iPhone and iPad: 1. Open the Settings app. 2. Tap "Privacy & Security". 3. Tap "Location Services". 4. If the authorizing official (AO) has not approved use of personal iCloud accounts on the device, verify "Location Services" is disabled. 5. If the AO has approved the use of personal iCloud accounts on the device, enable tap "Location Services". If "Location Services" is not disabled when the AO has not approved use of personal iCloud accounts on the device, this is a finding. If "Share My Location" is toggled to the right and appears green on the iPhone and iPad when the AO has approved the use of personal iCloud accounts, this is a finding.

Fix: F-87275r1196159_fix

The user must configure Apple Vision Pro to disable location sharing through iCloud.

b
Apple visionOS 26 users must complete required training.
CM-7 - Medium - CCI-000381 - V-282810 - SV-282810r1195745_rule
RMF Control
CM-7
Severity
Medium
CCI
CCI-000381
Version
AVOS-26-011900
Vuln IDs
  • V-282810
Rule IDs
  • SV-282810r1195745_rule
The security posture on visionOS devices requires the device user to configure several required policy rules on their device. User-Based Enforcement (UBE) is required for these controls. In addition, if the authorizing official (AO) has approved users' full access to the Apple App Store, users must receive training on risks. If a user is not aware of their responsibilities and does not comply with UBE requirements, the security posture of the visionOS mobile device and DOD sensitive data may become compromised. SFR ID: NA
Checks: C-87371r1195743_chk

Review a sample of site User Agreements for visionOS device users or similar training records and training course content. Verify Vision Pro users have completed required training. If any Vision Pro user has not completed required training, this is a finding.

Fix: F-87276r1195744_fix

Have all Vision Pro users complete training on the following topics. Users must acknowledge receipt of training via a signed User Agreement or similar written record. Training topics: - Operational security concerns introduced by unmanaged applications, including applications using global positioning system (GPS) tracking. - Must ensure no DOD data is saved in an unmanaged app or transmitted from a personal app (for example, from personal email). - If the Purebred key management app is used, users are responsible for maintaining positive control of their credentialed device at all times. The DOD PKI certificate policy requires subscribers to maintain positive control of the devices that contain private keys and report any loss of control so the credentials can be revoked. Upon device retirement, turn-in, or reassignment, ensure a factory data reset is performed prior to device handoff. Follow mobility service provider decommissioning procedures as applicable. - How to configure the following UBE controls (users must configure the control) and other controls on the Vision Pro: **Never enable Guest User Mode. Use is prohibited. **Never enable Developer Mode. Use is prohibited. - AO guidance on acceptable use and restrictions, if any, on downloading and installing personal apps and data (music, photos, etc.). -The Developer Strap must not be used with a DOD Vision Pro device without the explicit approval of the AO.

b
A managed photo app must be used to take and store work-related photos.
CM-6 - Medium - CCI-000366 - V-282811 - SV-282811r1195748_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-012000
Vuln IDs
  • V-282811
Rule IDs
  • SV-282811r1195748_rule
The visionOS Photos app is unmanaged and may sync photos with a device or user's personal iCloud account. Therefore, work-related photos must not be taken via the visionOS camera app or stored in the Photos app. A managed photo app must be used to take and manage work-related photos. SFR ID: NA
Checks: C-87372r1195746_chk

Review configuration settings to confirm a managed photos app is installed on the visionOS device. This check procedure is performed on the Vision Pro. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the DOD Configuration Profile from the Apple visionOS management tool. 5. Tap "Apps". 6. Verify a photo capture and management app is listed. If a managed photo capture and management app is not installed on the Vision Pro, this is a finding.

Fix: F-87277r1195747_fix

Install a managed photos app to take and manage work-related photos.

a
Apple visionOS 26 must not allow managed apps to write contacts to unmanaged contacts accounts.
CM-6 - Low - CCI-000366 - V-282812 - SV-282812r1195751_rule
RMF Control
CM-6
Severity
Low
CCI
CCI-000366
Version
AVOS-26-012300
Vuln IDs
  • V-282812
Rule IDs
  • SV-282812r1195751_rule
Managed apps have been approved for the handling of DOD sensitive information. Unmanaged apps are provided for productivity and morale purposes but are not approved to handle DOD sensitive information. Examples of unmanaged apps include those for news services, travel guides, maps, and social networking. If a document were to be viewed in a managed app and the user had the ability to open this same document in an unmanaged app, this could lead to the compromise of sensitive DOD data. In some cases, the unmanaged apps are connected to cloud backup or social networks that would permit dissemination of DOD sensitive information to unauthorized individuals. Not allowing data to be opened within unmanaged apps mitigates the risk of compromising sensitive data. SFR ID: FMT_SMF.1.1 #42, FDP_ACF_EXT.1.2
Checks: C-87373r1195749_chk

Review configuration settings to confirm "Allow managed apps to write contacts to unmanaged contacts accounts" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Apple visionOS device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow managed apps to write contacts to unmanaged contacts accounts" is unchecked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Allow managed apps to write contacts to unmanaged contacts accounts" is not listed. If "Allow managed apps to write contacts to unmanaged contacts accounts" is checked in the visionOS management tool, or the restrictions policy on the Vision Pro lists "Allow managed apps to write contacts to unmanaged contacts accounts", this is a finding.

Fix: F-87278r1195750_fix

Install a configuration profile to prevent managed apps from writing contacts to unmanaged contacts accounts.

a
Apple visionOS 26 must not allow unmanaged apps to read contacts from managed contacts accounts.
CM-6 - Low - CCI-000366 - V-282813 - SV-282813r1195754_rule
RMF Control
CM-6
Severity
Low
CCI
CCI-000366
Version
AVOS-26-012400
Vuln IDs
  • V-282813
Rule IDs
  • SV-282813r1195754_rule
Managed apps have been approved for the handling of DOD sensitive information. Unmanaged apps are provided for productivity and morale purposes but are not approved to handle DOD sensitive information. Examples of unmanaged apps include those for news services, travel guides, maps, and social networking. If a document were to be viewed in a managed app and the user had the ability to open this same document in an unmanaged app, this could lead to the compromise of sensitive DOD data. In some cases, the unmanaged apps are connected to cloud backup or social networks that would permit dissemination of DOD sensitive information to unauthorized individuals. Not allowing data to be opened within unmanaged apps mitigates the risk of compromising sensitive data. SFR ID: FMT_SMF.1.1 #42, FDP_ACF_EXT.1.2
Checks: C-87374r1195752_chk

Review configuration settings to confirm "Allow unmanaged apps to read contacts from managed contacts accounts" is disabled. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow unmanaged apps to read contacts from managed contacts accounts" is unchecked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Allow unmanaged apps to read contacts from managed contacts accounts" is not listed. If "Allow unmanaged apps to read contacts from managed contacts accounts" is checked in the visionOS management tool, or the restrictions policy on the Vision Pro lists "Allow unmanaged apps to read contacts from managed contacts accounts", this is a finding.

Fix: F-87279r1195753_fix

Install a configuration profile to prevent unmanaged apps from reading contacts from managed contacts accounts.

b
Apple visionOS 26 must implement the management setting: disable AirDrop.
CM-6 - Medium - CCI-000366 - V-282814 - SV-282814r1195757_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-012500
Vuln IDs
  • V-282814
Rule IDs
  • SV-282814r1195757_rule
AirDrop is a way to send contact information or photos to other users with this same feature enabled. This feature enables a possible attack vector for adversaries to exploit. Once the attacker has gained access to the information broadcast by this feature, the attacker may distribute this sensitive information very quickly and without DOD's control or awareness. By disabling this feature, the risk of mass data exfiltration will be mitigated. Note: If the site uses Apple's optional Automatic Device Enrollment, this control is available as a supervised MDM control. SFR ID: FMT_SMF.1.1 #47
Checks: C-87375r1195755_chk

Review configuration settings to confirm it is disabled. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify "Allow AirDrop" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "AirDrop not allowed" is listed. If "AirDrop not allowed" is not listed in the management tool and on the Apple device, this is a finding.

Fix: F-87280r1195756_fix

Install a configuration profile to disable the AllowAirDrop control in the management tool. This is a supervised-only control.

b
Apple visionOS 26 must disable "Password AutoFill" in browsers and applications.
CM-6 - Medium - CCI-000366 - V-282815 - SV-282815r1195760_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-012700
Vuln IDs
  • V-282815
Rule IDs
  • SV-282815r1195760_rule
The AutoFill functionality in browsers and applications allows the user to complete a form that contains sensitive information, such as Personally Identifiable Information, without previous knowledge of the information. By allowing the use of the AutoFill functionality, an adversary who learns a user's Vision Pro passcode, or who otherwise is able to unlock the device, may be able to further breach other systems by relying on the AutoFill feature to provide information unknown to the adversary. Disabling the AutoFill functionality significantly mitigates the risk of an adversary gaining further information about the device's user or compromising other systems. SFR ID: FMT_SMF.1.1 #47
Checks: C-87376r1195758_chk

This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Password AutoFill is not allowed" is disabled. This check procedure is performed on both the visionOS device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Password AutoFill is not allowed" is unchecked. On the Vision Pro: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Password AutoFill is not allowed" is listed. If "Password AutoFill is not allowed" is not enabled in the visionOS management tool and on the Apple device, this is a finding.

Fix: F-87281r1195759_fix

Install a configuration profile to disable allow Password AutoFill in the management tool. This is a supervised-only control.

b
Apple visionOS 26 must disable password sharing.
CM-6 - Medium - CCI-000366 - V-282816 - SV-282816r1195763_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-013000
Vuln IDs
  • V-282816
Rule IDs
  • SV-282816r1195763_rule
This control allows sharing passwords between Apple devices using AirDrop. This could lead to a compromise of the device password with an unauthorized person or device. DOD Apple device passwords must not be shared. SFR ID: FMT_SMF.1.1 #47
Checks: C-87377r1195761_chk

This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Password Sharing is not allowed" is enabled. This check procedure is performed on both the device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Password Sharing is not allowed" is checked. On the visionOS: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Password Sharing is not allowed" is listed. If "Password Sharing is not allowed" is not enabled in the management tool and on the Apple device, this is a finding.

Fix: F-87282r1195762_fix

Install a configuration profile to disable allow password proximity sharing in the management tool. This is a supervised-only control.

b
The Apple visionOS 26 must be supervised by the MDM.
CM-6 - Medium - CCI-000366 - V-282817 - SV-282817r1195766_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-013200
Vuln IDs
  • V-282817
Rule IDs
  • SV-282817r1195766_rule
When visionOS is not supervised, the DOD mobile service provider cannot control when new visionOS updates are installed on site-managed devices. Most updates should be installed immediately to mitigate new security vulnerabilities, while some sites need to test each update prior to installation to ensure critical missions are not adversely impacted by the update. Several password and data protection controls can be implemented only when an Apple device is supervised. SFR ID: FMT_SMF.1.1 #47
Checks: C-87378r1195764_chk

Review configuration settings to confirm site-managed visionOS devices are supervised. This check procedure is performed on both the Apple visionOS management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify all managed Apple devices are supervised (verification procedure will vary by MDM product). Note: If the Apple device is not managed by an MDM and supervision is set up via Apple Configurator, this procedure is not applicable. On the Vision Pro: 1. Open the Settings app. 2. Verify a message similar to the following appears on the screen: "This AVP is supervised by (name of site DOD mobile service provider)." If site-managed visionOS devices are not supervised, this is a finding.

Fix: F-87283r1195765_fix

Use one of the following methods to supervise visionOS devices managed by the DOD mobile service provider. Method 1: - Register all current and new visionOS devices in the DOD mobile service provider's Automated Device Management/Apple Business Manager (ABM) account. - Enable supervision of managed visionOS devices in the MDM. Method 2: - Configure each visionOS device using the Apple Configurator tool for Supervision. - This method is usually only appropriate when MDM management of the DOD Apple device is not appropriate or an older device cannot be registered in ABM.

a
The Apple visionOS must be configured to disable automatic transfer of diagnostic data to an external device other than an MDM service with which the device has enrolled.
SC-28 - Low - CCI-001199 - V-282818 - SV-282818r1195769_rule
RMF Control
SC-28
Severity
Low
CCI
CCI-001199
Version
AVOS-26-013400
Vuln IDs
  • V-282818
Rule IDs
  • SV-282818r1195769_rule
Many software systems automatically send diagnostic data to the manufacturer or a third-party. This data enables the developers to understand real-world field behavior and improve the product based on that information. It can also reveal information about what DOD users are doing with the systems and what causes them to fail. An adversary embedded within the software development team or elsewhere could use the information acquired to breach mobile operating system security. Disabling automatic transfer of such information mitigates this risk. SFR ID: FMT_SMF.1.1 #47a
Checks: C-87379r1195767_chk

Review configuration settings to confirm "Allow sending diagnostic and usage data to Apple" is disabled. This check procedure is performed on both the visionOS management tool and the visionOS device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow sending diagnostic and usage data to Apple" is unchecked. Alternatively, verify the text "<key>allowDiagnosticSubmission</key><false/>" appears in the configuration profile (.mobileconfig file). On the Apple visionOS device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the management policy. 5. Tap "Restrictions". 6. Verify "Diagnostic submission not allowed". Note: This setting also disables "Share With App Developers". If "Allow sending diagnostic and usage data to Apple" is checked in the visionOS management tool, "<key>allowDiagnosticSubmission</key><true/>" appears in the configuration profile, or the restrictions policy on the Apple visionOS device from the Apple visionOS management tool does not list "Diagnostic submission not allowed", this is a finding.

Fix: F-87284r1195768_fix

Install a configuration profile to disable sending diagnostic data to an organization other than DOD.

b
Apple visionOS must implement the management setting: not allow a user to remove Apple visionOS configuration profiles that enforce DOD security requirements.
CM-6 - Medium - CCI-000366 - V-282819 - SV-282819r1195772_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-013500
Vuln IDs
  • V-282819
Rule IDs
  • SV-282819r1195772_rule
Configuration profiles define security policies on Apple visionOS devices. If a user is able to remove a configuration profile, the user can then change the configuration that had been enforced by that policy. Relaxing security policies may introduce vulnerabilities the profiles had mitigated. Configuring a profile to never be removed mitigates this risk. SFR ID: FMT_SMF.1.1 #47
Checks: C-87380r1195770_chk

Review configuration settings to confirm configuration profiles are not removable. This check procedure is performed on both the Apple visionOS management tool and the Apple visionOS device. The procedures below assume the site is not enrolled in Apple's Automatic Device Enrollment and are not applicable to devices under MDM management. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Apple visionOS management tool, verify "Security" is set to "Never" and "Automatically Remove Profile" is set to "Never". On the Apple visionOS device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap each Configuration Profile from the Apple visionOS management tool that contains the restrictions for the device. 5. Verify the "Remove Profile" button is not present. If on the Apple visionOS management tool or the visionOS device the "Remove Profile" button is available on the configuration profile, this is a finding.

Fix: F-87285r1195771_fix

Configure the Apple visionOS configuration profile so that it can never be removed. The procedure for implementing this control will vary depending on the MDM/EMM used by the mobile service provider. When using Apple Configurator, under "General Security", configure "Security" to "Never" and "Automatically Remove Profile" to "Never".

b
Apple visionOS 26 must disable "Allow network drive access in Files access".
CM-6 - Medium - CCI-000366 - V-282820 - SV-282820r1195775_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-014300
Vuln IDs
  • V-282820
Rule IDs
  • SV-282820r1195775_rule
Allowing network drive access by the Files app could lead to the introduction of malware or unauthorized software into the DOD IT infrastructure and compromise of sensitive DOD information and systems. SFR ID: FMT_SMF.1.1 #47
Checks: C-87381r1195773_chk

This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. This check procedure is performed on both the device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow network drive access in Files access" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Network drives not accessible in Files app" is listed. If "Allow network drive access in Files access" is not disabled in the management tool, and "Network drives not accessible in Files app" is not listed in Profile Restrictions on the Apple device, this is a finding.

Fix: F-87286r1195774_fix

Install a configuration profile to disable "Allow network drive access in Files access".

b
Apple visionOS 26 must disable connections to Siri servers for the purpose of dictation.
CM-6 - Medium - CCI-000366 - V-282821 - SV-282821r1195778_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-014400
Vuln IDs
  • V-282821
Rule IDs
  • SV-282821r1195778_rule
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. Dictation information could contain sensitive DOD information and therefore should not leave DOD control. SFR ID: FMT_SMF.1.1 #47
Checks: C-87382r1195776_chk

If the Vision Pro being reviewed is supervised by the MDM, review configuration settings to confirm "Disable connections to Siri servers for the purpose of dictation" is disabled. This check procedure is performed on both the device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Disable connections to Siri servers for the purpose of dictation" is checked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Dictation processes voice inputs on Apple Vision Pro" is not listed. If connections to Siri servers are not disabled for dictation in the management tool, and "Dictation processes voice inputs on Apple Vision Pro" is listed in Profile Restrictions on the Apple device, this is a finding.

Fix: F-87287r1195777_fix

Configure the Apple visionOS configuration profile to disable connections to Siri servers for the purpose of dictation. This is a supervised-only control. The procedure for implementing this control will vary depending on the MDM/EMM used by the mobile service provider. In the MDM console, select "disable connections to Siri servers for the purpose of dictation".

b
Apple visionOS 26 must disable copy/paste of data from managed to unmanaged applications.
CM-6 - Medium - CCI-000366 - V-282822 - SV-282822r1195781_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-014600
Vuln IDs
  • V-282822
Rule IDs
  • SV-282822r1195781_rule
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DOD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DOD sensitive information. SFR ID: FMT_SMF.1.1 #47
Checks: C-87383r1195779_chk

Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. This check procedure is performed on both the device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Require managed pasteboard" is set to "True". On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Copy and paste are managed" is listed. If "Require managed pasteboard" is not disabled in the management tool, and "Copy and paste are managed" is not listed in Profile Restrictions on the Apple device, this is a finding.

Fix: F-87288r1195780_fix

Configure the Apple visionOS configuration profile to disable copy/paste of data from managed to unmanaged applications. The procedure for implementing this control will vary depending on the MDM/EMM used by the mobile service provider. In the MDM console, set "Require managed pasteboard" to "True".

b
Apple visionOS 26 must have DOD root and intermediate PKI certificates installed.
CM-6 - Medium - CCI-000370 - V-282823 - SV-282823r1195784_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000370
Version
AVOS-26-014700
Vuln IDs
  • V-282823
Rule IDs
  • SV-282823r1195784_rule
DOD root and intermediate PKI certificates are used to verify the authenticity of PKI certificates of users and web services. If the user is allowed to remove root and intermediate certificates, the user could allow an adversary to falsely sign a certificate in such a way that it could not be detected. Restricting the ability to remove DOD root and intermediate PKI certificates to the administrator mitigates this risk. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87384r1195782_chk

Verify DOD intermediate and root certificates have been installed on Apple devices. In the visionOS management tool, verify the DOD intermediate and root certificates are installed on the Apple device. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Tap "More Details". 7. Verify the DOD intermediate and root certificates are listed. If DOD intermediate and root certificates are not installed on the Apple device, this is a finding.

Fix: F-87289r1195783_fix

Install DOD intermediate and root certificates on managed mobile devices using the MDM.

b
Apple visionOS 26 must disable ChatGPT connection for Apple Intelligence.
CM-6 - Medium - CCI-000366 - V-282824 - SV-282824r1196145_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-015400
Vuln IDs
  • V-282824
Rule IDs
  • SV-282824r1196145_rule
The ChatGPT feature of Apple Intelligence allows DOD information to be downloaded from the DOD Vision Pro and processed by the ChatGPT application in the cloud. The ChatGPT feature of Apple Intelligence increases the risk of compromise of sensitive DOD information. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87385r1196144_chk

This check procedure is performed on the device management tool and the device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify the following controls are set to Disable (the text may vary, depending on the UEM/MDM product): - Allow External Intelligence Integrations. - Allow External Intelligence Integrations Sign-In. On the Vision Pro (Apple Intelligence-capable device only), use one of the following methods: Method #1 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "External intelligence integrations not allowed" and "Sign-ins with external intelligence integrations not allowed" are listed. Method #2 1. Go to Settings >> Apple Intelligence & Siri >> ChatGPT. 2. Verify "ChatGPT" is grayed out and disabled. If external AI apps are not disabled (for example, ChatGPT), this is a finding.

Fix: F-87290r1195786_fix

Install a configuration profile to disable ChatGPT and other external AI app connections for Apple Intelligence. 1. Set allowExternalIntelligenceIntegrations to "False". 2. Set allowExternalIntelligenceIntegrationsSignIn to "False".

b
Apple visionOS 26 must disable the download of visionOS beta updates.
CM-6 - Medium - CCI-000366 - V-282825 - SV-282825r1195790_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-015500
Vuln IDs
  • V-282825
Rule IDs
  • SV-282825r1195790_rule
Beta operating system updates may contain features that could lead to the compromise of sensitive DOD information or provide a vector for the attack on the DOD network. The current STIG will not normally provide controls to disable these unsecure features. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87386r1195788_chk

This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. This check procedure is performed on both the device management tool and the Vision Pro. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the visionOS management tool, verify "Allow installing configuration profiles (supervised only)" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Installing configuration profiles not allowed" is listed. If "Allow installing configuration profiles" is not disabled in the management tool, this is a finding.

Fix: F-87291r1195789_fix

Install a configuration profile to disable the installation of new configuration profiles. This will block the download and installation of beta visionOS updates. This is a supervised-only control.

a
Apple Vision Pro (AVP) hardware must not be modified to use the Developer Strap unless the authorizing official (AO) approves use on a case-by-case basis.
CM-6 - Low - CCI-000366 - V-282826 - SV-282826r1197167_rule
RMF Control
CM-6
Severity
Low
CCI
CCI-000366
Version
AVOS-26-015900
Vuln IDs
  • V-282826
Rule IDs
  • SV-282826r1197167_rule
The Apple Developer Strap provides a USB connector on the AVP and is used to download content on the AVP from a Mac. The use of the Developer Strap without authorization is considered an unauthorized modification to the DOD-owned AVP. The Developer Strap is sold by Apple only to registered Apple developers but can also be bought online. Data cannot be downloaded from the AVP to a connected Mac and does not currently provide access to an AVP enterprise network to the connected Mac. Only unmanaged apps can be uploaded to an AVP via the Developer Strap. Unauthorized unmanaged apps can be downloaded to the AVP from the connected Mac. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87387r1197166_chk

Interview the site information system security officer and AVP users. 1. Determine if the AVP Developer Strap is used at the site. If it is, verify the AO has approved its use by reviewing approval documentation. 2. Verify AVP users are trained to not use the AVP developer Strap without AO approval (AVOS-26-011900). If the AVP Developer Strap is used at the site without AO approval, this is a finding.

Fix: F-87292r1195792_fix

Train AVP users to not connect and use the Developer Strap unless the AO has approved its use for a specific use case (refer to AVOS-26-011900). AO use approval must be documented and detail specific use cases for which use is approved.

b
Apple visionOS 26 must disable the user's ability to wipe the device.
CM-6 - Medium - CCI-000366 - V-282827 - SV-282827r1195796_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-016000
Vuln IDs
  • V-282827
Rule IDs
  • SV-282827r1195796_rule
This feature must be disabled to comply with DOD electronic records retention requirements for mobile devices. Otherwise, mobile device users could wipe the device, which would violate DOD policy. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87388r1195794_chk

Review configuration settings to confirm device wipe is disabled. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify "Allow erase all content and settings" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Vision Pro management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Erase content and settings not allowed" is listed. If "Allow erase all content and settings" is not disabled in the management tool and on the Apple device, this is a finding.

Fix: F-87293r1195795_fix

Install a configuration profile to disable "Allow Erase All Content and Settings". This is a supervised-only control.

a
Apple visionOS 26 must disable the use of voice assistant (Siri) unless required to meet Section 508 compliance requirements.
CM-6 - Low - CCI-000366 - V-282828 - SV-282828r1195799_rule
RMF Control
CM-6
Severity
Low
CCI
CCI-000366
Version
AVOS-26-016100
Vuln IDs
  • V-282828
Rule IDs
  • SV-282828r1195799_rule
The use of voice assistants could expose sensitive DOD data to cloud-based servers during the processing of assistant requests. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87389r1195797_chk

Review configuration settings to confirm the use of voice assistant is disabled. Exception: Siri is allowed to meet Section 508 compliance requirements. This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify "Allow Siri" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Vision Pro management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Siri not allowed" is listed. If "Allow Siri" is not disabled in the management tool and on the Apple device, this is a finding.

Fix: F-87294r1195798_fix

Install a configuration profile to disable "Allow Siri" unless required to meet Section 508 compliance requirements.

a
Apple visionOS 26 must disable the Apple Intelligence feature: Image Wand.
CM-6 - Low - CCI-000366 - V-282829 - SV-282829r1195802_rule
RMF Control
CM-6
Severity
Low
CCI
CCI-000366
Version
AVOS-26-017200
Vuln IDs
  • V-282829
Rule IDs
  • SV-282829r1195802_rule
The security of the Apple Intelligence system has not been vetted by the DOD, and the risk to DOD sensitive information is not known at this time. Therefore, Apple intelligence features must be disabled until more information is available. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87390r1195800_chk

Note: This control is only applicable to Apple Intelligence-capable Vision Pro devices. Review configuration settings to confirm the Apple Intelligence feature Image Wand is disabled. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify the Apple Intelligence feature Image Wand is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Image Wand not allowed" is listed. If Image Wand is not disabled in the management tool and on the Apple device, this is a finding.

Fix: F-87295r1195801_fix

Install a configuration profile to disable the Apple Intelligence feature Image Wand. This is a supervised-only control. Note: This control is only applicable to Apple Intelligence-capable Vision Pro devices. Configuration Profile Key: allowImagewand

a
Apple visionOS 26 must disable the Apple Intelligence feature: Image Generation.
CM-6 - Low - CCI-000366 - V-282830 - SV-282830r1195805_rule
RMF Control
CM-6
Severity
Low
CCI
CCI-000366
Version
AVOS-26-017300
Vuln IDs
  • V-282830
Rule IDs
  • SV-282830r1195805_rule
The security of the Apple Intelligence system has not been vetted by the DOD, and the risk to DOD sensitive information is not known at this time. Therefore, Apple intelligence features must be disabled until more information is available. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87391r1195803_chk

Note: This control is only applicable to Apple Intelligence-capable Vision Pros. Review configuration settings to confirm the Apple Intelligence feature Image Generation is disabled. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify the Apple Intelligence feature Image Generation is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Vision Pro management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Image Playground not allowed" is listed. If Image Generation is not disabled in the management tool and on the Apple device, this is a finding.

Fix: F-87296r1195804_fix

Install a configuration profile to disable the Apple Intelligence feature Image Generation. This is a supervised-only control.

a
Apple visionOS 26 must disable the Apple Intelligence feature: generate new Genmoji.
CM-6 - Low - CCI-000366 - V-282831 - SV-282831r1196146_rule
RMF Control
CM-6
Severity
Low
CCI
CCI-000366
Version
AVOS-26-017400
Vuln IDs
  • V-282831
Rule IDs
  • SV-282831r1196146_rule
The security of the Apple Intelligence system has not been vetted by the DOD, and the risk to DOD sensitive information is not known at this time. Therefore, Apple intelligence features must be disabled until more information is available. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87392r1195806_chk

Note: This control is only applicable to Apple Intelligence-capable Vision Pro. Review configuration settings to confirm the Apple Intelligence feature generate new Genmoji is disabled. This is a supervised-only control. If the Vision Pro being reviewed is not supervised by the MDM, this control is automatically a finding. If the Vision Pro being reviewed is supervised by the MDM, follow these procedures: This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify the Apple Intelligence feature generate new Genmoji is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the visionOS management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Genmoji not allowed" is listed. If generate new Genmoji is not disabled in the management tool and on the Apple device, this is a finding.

Fix: F-87297r1195807_fix

Install a configuration profile to disable the Apple Intelligence feature generate new Genmoji. This is a supervised-only control.

b
DOD Apple visionOS 26 devices must have a Mobile Threat Detection (MTD) app installed.
CM-6 - Medium - CCI-000366 - V-282832 - SV-282832r1195811_rule
RMF Control
CM-6
Severity
Medium
CCI
CCI-000366
Version
AVOS-26-017700
Vuln IDs
  • V-282832
Rule IDs
  • SV-282832r1195811_rule
DOD mobile devices are in constant risk of cyber threats. MTD apps mitigate these risks by providing real-time threat detection, malware prevention, and vulnerability analysis. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87393r1195809_chk

Confirm an MTD app is installed on the managed Vision Pro. This check procedure is performed on both the device management tool and the Vision Pro device. In the Vision Pro management tool, verify an MTD app is listed as a managed app being deployed to site-managed devices. On the Vision Pro device: 1. Open the Settings app. 2. Tap "Apps". 3. Verify an MTD app is listed. If an MTD app is not installed on the device, this is a finding.

Fix: F-87298r1195810_fix

Deploy a site-approved MTD app via the MDM server to the managed Vision Pro.

a
DOD Apple visionOS 26 devices must disable screenshots and screen recordings.
CM-6 - Low - CCI-000366 - V-282833 - SV-282833r1195814_rule
RMF Control
CM-6
Severity
Low
CCI
CCI-000366
Version
AVOS-26-018000
Vuln IDs
  • V-282833
Rule IDs
  • SV-282833r1195814_rule
A screenshot or screen recording of sensitive DOD information could lead to the inadvertent exposure of that information. SFR ID: FMT_MOF_EXT.1.2 #47
Checks: C-87394r1195812_chk

Review configuration settings to confirm screenshot and screen recording is disabled. This check procedure is performed on both the device management tool and the Vision Pro device. Note: If an organization has multiple configuration profiles, the check procedure must be performed on the relevant configuration profiles applicable to the scope of the review. In the Vision Pro management tool, verify "Allow screenshot and screen recording" is unchecked. On the Vision Pro device: 1. Open the Settings app. 2. Tap "General". 3. Tap "VPN & Device Management". 4. Tap the Configuration Profile from the Vision Pro management tool containing the restrictions policy. 5. Tap "Restrictions". 6. Verify "Screen capture not allowed" is listed. If "Allow screenshot and screen recording" is listed in the management tool or "Screen capture not allowed" is not listed on the Apple device, this is a finding.

Fix: F-87299r1195813_fix

Install a configuration profile to disable screenshot and screen recording.