UCF STIG Viewer Logo

The macOS system must disable iCloud document synchronization.


Overview

Finding ID Version Rule ID IA Controls Severity
V-214873 AOSX-13-000559 SV-214873r609363_rule Medium
Description
Operating systems are capable of providing a wide variety of functions and services. Some of the functions and services provided by default may not be necessary to support essential organizational operations. Additionally, it is sometimes convenient to provide multiple services from a single component (e.g., VPN and IPS); however, doing so increases risk over limiting the services provided by any one component. Satisfies: SRG-OS-000095-GPOS-00049, SRG-OS-000370-GPOS-00155
STIG Date
Apple OS X 10.13 Security Technical Implementation Guide 2021-11-19

Details

Check Text ( C-16073r397191_chk )
To view the setting for the iCloud Document Synchronization configuration, run the following command:

/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep allowCloudDocumentSync

If the output is null or not "allowCloudDocumentSync = 0" this is a finding.
Fix Text (F-16071r397192_fix)
This setting is enforced using the "Restrictions" configuration profile.