Apple iOS/iPadOS 26 STIG Compliance Checklist
20 items · Security · Medium difficulty · 4 hours
Actionable steps to implement iOS/iPadOS 26 STIG for DOD Apple devices.
-
Confirm STIG scope and applicability
Verify devices are COPE/COBO and running iOS/iPadOS 26 before applying controls.
-
Obtain ABM customer number
Request and record the Apple Business/Automated Enrollment customer number at deploy.apple.com.
-
Supervise devices
Enable supervised mode for institutionally owned devices to gain required management controls.
-
Enroll devices in Automated Device Enrollment (ABM)
Register devices with ABM so supervision occurs during activation.
-
Place devices in supervised mode using Apple Configurator
Use Apple Configurator (AC2) to manually supervise devices when ABM enrollment is not used.
-
Install and configure Mobile Device Management (MDM) profile
Deploy MDM to enforce profiles, restrictions, and reporting on supervised devices.
-
Restrict users from removing MDM profile
Prevent profile removal to maintain device management and compliance.
-
Enable device encryption and data protection
Ensure iOS data protection is active to encrypt device storage contents.
-
Set and enforce a strong passcode policy
Require complex, minimum-length passcodes and short auto-lock intervals via MDM.
-
Require passcode fallback for biometric authentication
Allow biometrics but enforce a secure passcode as a fallback method.
-
Configure MDM-controlled OS updates
Schedule and enforce managed iOS/iPadOS updates; block unsanctioned OS installs.
-
Restrict App Store access per AO policy
Disable or limit App Store access and app installations according to AO decisions.
-
Restrict unmanaged apps from accessing DOD data and document AO approvals
Use managed/unmanaged app controls and record any AO exceptions in writing.
-
Install approved Wi‑Fi profiles and restrict to authorized SSIDs
Deploy enterprise Wi‑Fi settings and ensure networks meet Network Infrastructure STIG.
-
Configure and enforce VPN profiles for DOD access
Require approved VPNs (per-app where applicable) for access to DOD resources.
-
Disable AirDrop and restrict Bluetooth file exchange
Turn off AirDrop and limit Bluetooth sharing to reduce data leakage risks.
-
Enable remote wipe and device locate in MDM
Configure remote wipe, lock, and locate capabilities for lost or compromised devices.
-
Disable iCloud backups for work data or enforce managed backups
Prevent uncontrolled cloud backups of DOD data or use approved managed backup solutions.
-
Record configurations, approvals, and maintain audit logs
Document profiles, AO approvals, change history, and retain logs for audits.
-
Run STIG checks with XCCDF/SCAP and remediate findings
Validate device compliance using the XCCDF 1.1.4/STIG tools and fix reported issues.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.