0% found this document useful (0 votes)
15 views32 pages

Apple Device Security Basics for Admins

This document serves as a beginner's guide to Apple device security, emphasizing the importance of proactive measures to protect organizational data and resources from cyber threats. It outlines key security features built into Apple operating systems, the significance of device enrollment and management through Mobile Device Management (MDM), and various ownership models for devices. The guide aims to equip administrators and managers with essential knowledge to enhance the security of Apple devices in their organizations.

Uploaded by

admin
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
15 views32 pages

Apple Device Security Basics for Admins

This document serves as a beginner's guide to Apple device security, emphasizing the importance of proactive measures to protect organizational data and resources from cyber threats. It outlines key security features built into Apple operating systems, the significance of device enrollment and management through Mobile Device Management (MDM), and various ownership models for devices. The guide aims to equip administrators and managers with essential knowledge to enhance the security of Apple devices in their organizations.

Uploaded by

admin
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Apple Device

Security
FOR BEGINNERS
A well-planned cyberattack or an accidental malware download can
mean the difference between a productive day and all work grinding
to a halt. As hackers get more sophisticated, organizations concerned
about their bottom line and the security of their users’ data, like
customers, employees or students, must stay on top of security.

Apple security concerns, like all IT security concerns, are quite real and pose a critical
threat to organizational resources and stakeholder safety.

Apple makes incredibly secure operating systems; there’s no doubt that its focus
on the security and privacy protections baked into its hardware and software has
played a significant role in its rise in popularity and mass adoption within enterprises,
education institutions and other industry organizations. And as Apple continues to
be the platform of choice for personal and professional hardware, it has become a
more attractive target for attackers. This means that administrators must respond
quickly to security incidents as they arise and not wait until an issue occurs. Instead,
MacAdmins and security teams (and the stakeholders they support) are better served
proactively guarding against them before threats can evolve into something far worse
by leveraging solutions tailored or purpose-built for Apple to protect against Apple-
centric threats effectively.

This guide is for administrators and managers who want to get serious about the
organizational security of their Apple devices and offers basic information for
newcomers or even a simple refresher for Apple management veterans.

TABLE OF C ON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 2


Introduction to
Apple Security

Several factors work together to ensure the security of your


organization’s hardware and data:

Apple native security: Data encryption:

1 4
Security systems already Securing data at rest and in
built in to macOS, iOS, transit, on device and
iPadOS and tvOS in network at all times

Enrolled devices:
Enrolling and deploying Compliance monitoring:

2 5
devices with secure, Monitoring devices to
centralized management determine health status

and visibility and enforce baselines

Securing devices: Application security

3 6
Protecting your physical
and patching:
Staying up to date with
devices and safeguarding
operating system, app and
your users from threats
software patches

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 3


1 Security features already built in to macOS (the operating system for Mac), iOS (the operating
system for iPad and iPhone) and tvOS (the operating system for Apple TV) are extensive and
come with several benefits:

BUILDING BLOCK ONE:  pple operating systems are based on UNIX underpinnings which creates a rich
A
computing foundation from a mature, well-researched platform with deep development

Apple Native roots for rock-solid stability.


Strong OS security framework:

Security
Notarization
Gatekeeper
XProtect
Apple devices are the most-secure out-of-
Malware Removal Tool (MRT)
the-box hardware options on the market,
Transparency, Consent and Control (TCC)
and purpose-built management and security
Rapid Security Responses
solutions extend the power of Apple.
Lockdown mode


Physical device security in the form of locking and lost device tracking
with the Find My service

Ability to implement and configure security controls through configuration options via
mobile device management (MDM)
Secure enrollment modes are built in to Apple devices, such as Automated Device Enrollment
and User-initiated enrollment for company- and/or personally-owned devices to meet all
ownership model needs (like BYOD, CYOD and COPE) without risky enrollment URLs or
suspicious email invitations
Seamless integration with Apple Business Manager or Apple School Manager to aid in
centrally managing all institutional hardware, including enabling Supervision of devices over-
the-air and secure hand-off to your MDM solution for device management functions, like
managed app deployment, secure device provisioning and zero-touch onboarding workflows

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 4


APPLE NATIVE SECURITY

A purpose-built MDM solution can take these existing security


configurations, align them to your unique organizational needs,
including industry benchmarks, and deploy (as well as enforce)
them to your entire Apple fleet, regardless of size. So, you can
securely and efficiently set up one Mac just as easily as you would
thousands. You also gain more expansive security controls with
an MDM tool that makes performing administrative tasks easy on
any devices you select. For example, you can make short work
of repetitive tasks by remotely locking and wiping devices that
are lost or should be removed from your facility’s inventory, to
name a few. Learn more with our Apple Device Management for
beginner’s e-book.

TABLE OF C ON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 5


APPLE NATIVE SECURITY

Security feature details


Native security features for macOS, iOS, iPadOS and tvOS

macOS iOS and iPadOS tvOS

Software Updates Software Updates Software Updates

System Integrity Protection (SIP) Secure System App Store

Gatekeeper App Store Airplay settings and passwords

App Store Biometric Identiffcation App restrictions

FileVault Encryption Hardware Encryption Screen saver

Supervision Supervision Supervision

XProtect and Malware Removal Tool (MRT) App Sandboxing

Find My Find My

Privacy Settings Privacy Settings

Notarization and ffle quarantine Secure Enclave and Biometric Identiffcation

Endpoint Security API Notarization

App Sandboxing

Secure Enclave and Biometric Identiffcation

TABLE OF C ON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 6


2
The first step to correctly provisioning devices and securely deploying them across your
entire fleet in a standardized, efficient manner is to use Automated Device Enrollment, which
BUILDING BLOCK TWO: is included as part of the free services offered by Apple through Apple Business Manager and
Apple School Manager.

Securely Enrolled With Automated Device Enrollment, you can inform Apple of all devices your organization
owns, as well as other ownership models discussed below, and assign them to be managed

Devices and
by your organization’s MDM. Then, when an enrolled device in this program powers on, it will:

Automatic enrollment to your MDM instance

Deployments 
Enable Supervision, which is integral for allowing tighter
security controls
Allow administrators to apply configuration profiles and harden settings

As with all building blocks, the key 


Ensure critical security settings and payloads are deployed before the user can begin
using a device
to success is a solid foundation. This

Streamline management and deployment of OS updates
informs each subsequent building
and security patches
block that follows and sets the

Cut down on the quantity of device provisioning workflows by centralizing app
overarching tone for the management procurement, configuration and deployment, which also ensures security of apps from
and security as it pertains to the vetted, trusted sources
hardware and application lifecycles. 
Reduce device setup by empowering users to maintain their devices without needing
support from IT

Permit remote management regardless of which supported device is used, from where
and over any network connection

TABLE OF C ON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 7


SECURELY ENROLLED
DEVICES AND DEPLOYMENTS

Device ownership models


Automating the management and security of your device fleet is a critical feature,
especially as device counts grow and as the workforce becomes decentralized.
The rise in the adoption and reliance on the Apple platform and mobile devices
in the workspace has become as diverse as the industries and users that rely on
these devices to remain productive.

Some organizations have embraced Apple products by implementing employee


choice programs that assign company-owned devices running macOS and iOS
and iPadOS, while other organizations have embraced Apple at work by allowing
employees to use personally owned devices to access business resources. By
empowering them to work more comfortably using the hardware and software
they are most familiar with, organizations offset the expense of providing
equipment for each stakeholder—especially when users already have a functional
device they know and love.

This shifts the question from “How do we provide user’s devices?”


to “How do we ensure company resources remain secured?”

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 8


SECURELY ENROLLED
DEVICES AND DEPLOYMENTS

This is where your organization’s MDM and flexible device ownership models meet to form the solution of multiple device ownership models, such as:

Bring Your Own Device (BYOD) Choose Your Own Device (CYOD) Company-Owned Personally
Enabled (COPE)
Arguably the most common model, This a variation on BYOD above, except
allowing users to use their personally that often, the organization or institution The COPE model is a growing trend
owned devices to access business owns the devices used in this model and among larger organizations, especially
resources. By requiring that users are to be used in carrying out job-related those that have gone fully remote or
manually enroll their devices in the functions or in the pursuit of learning (in with hybrid work environments. Here,
organization’s MDM before gaining the case of education.) By instituting a organizations purchase and own the
access to work resources, the dual-fold program of employee choice, stakeholders equipment, while enrolling and managing
benefit is that users can rest assured that can choose which Apple device meets it fully within the organization’s MDM.
they will obtain the tools necessary to their needs best. Each device is enrolled, Like CYOD, the tools necessary for
access the data and services required assigned to a stakeholder and managed stakeholders to perform their job tasks
for them to perform their job functions; by the organization’s MDM. The apps, are installed and managed according to
organizations rest easier knowing that configuration profiles, device settings and the device and the company’s security
enrolled devices are provided the security software are provisioned according posture. But similar to BYOD, the
necessary security software and settings to a baseline of the organization’s security organization allows and even encourages
to keep business data secured while in posture and taking into account the users to utilize the devices for personal
use, at rest and in transit. assignee’s job requirements. use alongside professional usage. This
ensures that company data stays secure
within managed apps and configuration
profiles. While this can open up the issue
of personal, private data being accessible
to companies via COPE devices, it’s
important to consider the privacy of the
data and provide the right amount of
management and privacy to these devices
through means of Acceptable Use Policies
(AUPs) and data managment.

TABLE OF C ON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 9


SECURELY ENROLLED
DEVICES AND DEPLOYMENTS

Flexible enrollment methods


To simplify the management of multiple device ownership models within the same MDM environment, Apple
has developed two different enrollment methods used in conjunction with one another to manage and enforce
organizational security without compromising user privacy and vice-versa.

Automated Device Enrollment


This is the most common method that most organizations with company-owned equipment prefer to choose.
This method certifies that each step in the enrollment chain is verified: from procurement from Apple (or an
authorized third party) through pre-staging in the MDM to the enrollment phase that starts when the device is
powered on — each step follows in an automated procedure from Apple to MDM to administrator for on-going
management. Because this chain is verified, Supervision is enabled on devices enrolled through Automated
Device Enrollment, which acts as a trusted foundation that allows IT to obtain full control over the device
throughout its lifecycle. Supervision is the root of trust, required when performing certain management tasks on
managed devices.

User-initiated device enrollment


This enrollment method is newer and more common when the enrolled devices are personally owned as part
of a BYOD model. With Automated Device Enrollment, the enrollment relies on the user or owner of the device
to manually enroll their device within the Settings app and authenticate using their company credentials. After
completing the user enrollment process, the organization’s MDM is two-way secure communication between
the user’s device and organization’s management solution.

Once enrolled, personally owned devices are manageable through the MDM, with administrators permitted to
install managed apps, deploy configuration profiles and modify certain settings using a set of configurations
allowing organizations to set device-specific requirements as well as associate management actions or
requirements with the user, not the entire device. Apple designs the limitation to allow organizations to take the
steps necessary to secure how their data is accessed, interacts with apps, is stored on device and transmitted
over networks without impacting the personal apps, data and private information on the device. Organizations
can customize the visibility of managed devices by associating a personal Apple ID with personal data and a
Managed Apple ID with company data.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 10


3

BUILDING BLOCK THREE:

Securing Devices If we look back at some of the largest, most complex and even deadliest data
breaches in recent history, we’ll find a common thread. Attacks such as Stuxnet
disabled Iran’s nuclear enrichment program by infecting a contractor’s laptop
Keeping devices, data and users safe performing updates to the SCADA equipment. LinkedIn was targeted by a
developer that exploited its API to effectively scrape PII from 700 million users
from threats
before selling the data dump online. Aadhaar—home to the largest ID database,
including PII and financial data, for more than 1.1 billion Indian citizens—was
“Hackers only need to get it right once; stolen and sold by threat actors after gaining entry through an unprotected
website linked to the database. In these and similar cases, attacks were made
we need to get it right every time.”
possible by targeting and compromising just one device.
— Chris Triolo, HP

One of the most common ways to bypass an organization’s security framework


and gain access to sensitive data while also putting end-user safety at risk is by
compromising a single device. Regardless of which industry your organization
represents or whether it provides data and/or resources to knowledge workers,
students, teachers, healthcare providers, remote staff, retail staff or frequent
travelers — at any given moment, your devices could be anywhere in the
world and connecting via any number of untrusted networks — exponentially
increasing the exposure to risk of threats for both the device and the
company’s network.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 11


SECURING DEVICES

Lost or stolen devices


A lost or stolen iPhone, iPad or Mac isn’t just a financial loss: it also represents
a massive security risk where the potential for fallout may be incalculable.
Consider the following examples as underscoring the criticality of mitigating risk
for lost and stolen devices:

REAL-WORLD SCENARIOS Simply put: Devices get lost and stolen. Accidents
and moments of inattention happen. Yet, planning —
with the assumption that it is only a matter of when,
A remote employee is prepping legal documents for an ongoing liability not if, someone will lose track of a device — is a
case being argued in court and is working from a nearby coffee shop. They vital key toward ensuring that the proper mitigation
leave the company-owned Mac laptop unattended briefly while refilling their strategies are in place to minimize risk before
coffee at the precise moment a thief swoops in and steals the laptop. With the devices become lost or stolen.
device unlocked, the attacker has unfettered access to sensitive and possibly
confidential company information that could negatively impact current legal Additional consideration points for user and data
proceedings and the company’s reputation. security are that many devices — especially those
serving students and patients or shared device
In a second example, a student using their personally owned iPhone to access environments serving multiple users — require
school-related resources via the educational portal misplaces their device while safeguards against misuse, the accidental discovery
changing classes. Another user finds the phone and proceeds to access the of another’s data or the access and viewing of risky
student’s account details, gaining access to sensitive PII, like their address, and inappropriate content.
phone number or student ID. An unauthorized user can utilize PII information Depending on your organization’s unique needs,
like this for identity theft or to commit crimes while impersonating the victim. hardening settings for security while configuring
The device may even be further compromised with malware and returned to devices so that they’re aligned with organizational
the victim, placing their safety and well-being at risk from remote tracking and and compliance requirements could be a
stalking by threat actors. considerable undertaking that is time and labor-
intensive, especially as device counts grow.

TABLE OF CO N T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 12


SECURING DEVICES

When securing or restricting devices manually, you need to:

Mac Phone and iPad Apple TV

Require passwords on all devices Require passwords on all devices Require passwords on all Apple TVs


Enable Find My Mac through System Enable Find My Mac through System 
Configure restrictions:
Preferences>iCloud Preferences>iCloud From the main menu, go to


Depend on individual users to be able to 
Depend on individual users to be able to sign Settings>General>Restrictions
sign into iCloud or remember their password into iCloud or remember their password Select Restrictions to turn it on

(prerequisite to enabling FindMy) 
Track all inventory by device serial numbers or  When asked, make a four-digit passcode

Report to Apple if a device was lost or asset tags
 
Enter the four digits again to confirm,
stolen while enabling the ability to initiate 
Report to Apple if a device was lost or stolen then select OK
wipe/erase while enabling the ability to initiate wipe/erase
Remember the passcode


Track all inventory by Mac serial numbers or 
Enable parental controls on an individual
asset tags Repeat for all Apple TVs

device, creating different accounts for

Enable parental controls on the device to each device
To restrict Airplay for Apple TV:
block inappropriate content and malicious 
Keep iOS-based devices up to date
websites (using Safari browser) 
From the main menu, go to Settings >
with all system and app updates to
Select AirPlay

Keep Macs up to date with all system and minimize vulnerabilities
app updates to minimize vulnerabilities 
Turn AirPlay on or off

Configure and harden device settings to

Configure and harden device settings to minimize misconfigurations that could leave Choose from:

minimize misconfigurations that could leave data unsecured  Everyone


data unsecured 
Deploy managed applications and keep  Anyone on the Same Network

Deploy supported applications and keep them updated
 Repeat for all Apple TVs
them updated 
Install endpoint security to monitor devices,

Install and configure endpoint security identify and remediate threats
to monitor devices, identify and
remediate threats

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 13


SECURING DEVICES

On a best-of-breed MDM solution, like Jamf Pro, the same management tasks performed above to secure or restrict
devices goes like this:

Mac, iPhone, iPad and Apple TV


Set all restrictions and security features from the first use 
Implement parental controls and block access to risky or
or enable them automatically with Supervision and trusted inappropriate apps, applying granular restrictions based on
configuration profiles and policies certain criteria or to all devices at once


Lock or wipe any lost or misused device remotely, 
Deploy managed applications necessary for users to remain
regardless of its physical location — and regardless of productive at home, in the office, at school or anywhere else.
whether the device has an iCloud account signed in or not Pre-approve apps to be hosted within the Self Service app,
(no Apple ID required) empowering users to access the software they need exactly
when they need it

Enable multiple users to securely share devices by wiping
a device between uses and allowing users to use their 
Integrate endpoint security solutions with your MDM to ensure
credentials and settings that are connected to the user — that devices are constantly monitored and protected against
not the device security threats while sharing rich telemetry data with the
MDM to enable policy-based management for automating

Configure managed Apple IDs to be assigned to the
incident response
device for business tasks while allowing the user to access
personal apps, data and settings stored in iCloud with their 
Manage each facet of device management tasks centrally to
consumer Apple ID ensure devices, users and data remain secure against cyber
threats while upholding user privacy

Maintain inventory of all devices, including the ability to
group them by any category — not just serial number or
asset tag — to glean any data necessary, such as user
Not only does this experience streamline work for IT administrators
assignments, OS version or apps installed to name a few
and staff, but it also supports the end users. It provides the experience

Perform management tasks that issue commands to a people love and have come to expect from Apple without sacrificing
single device or in bulk, such as deploying security updates, organizational, industry compliance and security requirements or user
upgrading to a new OS version or administratively clearing privacy in favor of tighter security controls.
forgotten passcodes on locked devices

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 14


4
Whether your organization is a school protecting student information, a healthcare facility
guarding patient health histories or a business intent on protecting your intellectual property,
encryption is no longer an option for your organization: it’s a critical requirement for any
business wishing to keep sensitive, confidential and mission-critical data, or really data of any
classification type safeguarded, the best practice is to encrypt all data on devices.

Below is a summary of the three states of data at any given time on a device:
BUILDING BLOCK FOUR:
Data at rest: stored locally Data in motion: transferred Data in use: neither kept

Encrypting Data (usually) on a device that is


currently not being accessed
data — both being received
or transmitted — over a
in permanent storage nor
transmitted over networks, this
or used. communications channel, like a refers to data currently being
wired or wireless network. worked on by applications or
other processes.
The basics of data at rest and data
in transit, and how to keep both
Each has inherent risks unique to its state, meaning that, generally speaking, a solution for
types secure. one state may not fully compensate (or work at all) for another. While this adds complexity to
your security strategy, fret not, because effective solutions all center around the fundamental
function of encryption.

REAL-WORLD SCENARIOS

A new hire in the HR department at your organization receives their new Mac and quickly
completes the setup process to begin working. One of their job functions requires creating an
emergency contact tree using spreadsheet software, including each employee’s name, job title,
company email address, personal address, personal contact number and specifying whether they
are a primary or alternate contact. This information is to be backed up locally to the computer,
including the personal contact information for members of the management and C-suite teams,
and a duplicate copy must be made available to authorized stakeholders to access from a cloud
repository securely.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 15


ENCRYPTING DATA

In the scenario above, the portions in bold indicate a specific example of each data
state. First, “using spreadsheet software” is an example of data in use, indicating that
data must remain secure while it’s being worked with within the app. This requires
the software’s integrity to be checked and verified to ensure that a threat actor
or malicious code has not compromised its internal security. Second, “backed up
locally” is an example of data at rest, indicating the criticality of enabling encryption
to prevent data from being accessed and read by unauthorized individuals. Third,
“securely access from a cloud repository” is an example of data in motion, as in
data sent and received across a network connection. The network connections
used for communication must be encrypted end-to-end, ensuring that only the two
connections at either end can successfully decrypt the message and protect this data
from unauthorized receipt or eavesdropping attacks.

And while this third data state may sound a lot like legacy VPN services, the
component that separates it from legacy VPN is the wording “authorized
stakeholders,” since Zero Trust Network Access (ZTNA) provides encryption for
data in motion, ZTNA also integrates with your identity provider (IdP) ensuring only
users and devices that have both authenticated successfully and are provisioned
the necessary access permissions are granted access to the requested resources
behind additional layers of protection, upholding the principle of least privilege.
Also, unlike legacy VPN services which often grant access to the entire network
once authenticated, ZTNA’s implementation of securing connections utilizes micro-
tunnels to establish a unique tunnel for each protected app or service. This provides
greater security by enforcing the principle of least privilege while employing health
checks to ensure that devices meet minimum requirements — in conjunction
with user authentication requirements — each time a request is made and before
granting access.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 16


ENCRYPTING DATA

How to encrypt the three states of data


Data at rest
Volume or full device encryption
Encrypting the data stored on a mobile device or within a volume on your computer is a best practice for several reasons. Consisting of proactive and
reactive measures, the easy-to-configure process of enabling encryption provides the maximum safety and security for data at rest in permanent storage.
Utilizing algorithms that would take attackers hundreds, or more likely thousands of years of working around the clock using the most powerful computers to
defeat given the relatively minimal effort required to setup encryption, it’s a “no brainer” when it comes to including this security control as part of a defense-
in-depth strategy — like The Alamo, or the proverbial “last stand” between a threat actor and confidential data.

Take for example some common security incidents that are effectively mitigated by enabling full device or volume encryption:

Loss or theft of a device Physical access Regulatory compliance


Misplaced devices, like iPhones, iPads or MacBook Similar to the lost or stolen Depending on the industry your organization belongs to,
laptops, are especially common for mobile devices. The devices section above, obtaining you may be subject to laws — known as regulations — that
greater the mobility, the greater the risk of loss or theft. physical access to a device govern minimum requirements for safeguarding data and
That said, once a device is out of your hands, threat doesn’t mean it must first be how it is processed while also mandating limitations over
actors have free rein to attempt to obtain the data stored misplaced. Think of a shared which job roles are allowed to work with protected data
on the device. device in a workspace, perhaps types. Specific industries are regulated more aggressively
the dedicated computer assigned than others; these are highly regulated industries, like
to you at your desk or any the finance sector and healthcare, while others may only
Sure, a complex passcode or strong password should
computing device that a threat focus on certain aspects of data security, like education
protect your device. However, depending on the device,
actor may attempt to use when no regulations that aim to protect the welfare of students and
there could still be alternate means for attackers to
one is looking. When your session the PII associated with them.
access some or all of the data contained within the
is over and you log out, shut down
device — except when it’s encrypted. The simple
or even lock your device while As mentioned before, regulations are based on laws and
act of enabling encryption scrambles the data to the
stepping away or not in use, the violating them could have dire consequences for the
degree that it is unreadable unless the decryption key
data contained in the volume or organization or institution if they did not properly adhere
unscrambles it. It doesn’t matter if the device is booted
device is and remains encrypted. to the rules of the governing bodies. Often, encrypting
to the login screen or the SSD is somehow accessed
A decryption or recovery key data is a tentpole security control required during different
and connected to another device as an external drive.
is required to decrypt the data data states, like at rest or in motion to minimize the risk
Encrypted data remains encrypted until the decryption or
to gain readable access to the of regulated information falling into the wrong hands
recovery key is used to decrypt it — any other scenario
secured data. through data leakage, exfiltration or even exposure to
renders the data unreadable and, therefore, useless.
unauthorized users.

TABLE OF CO N T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 17


ENCRYPTING DATA

Data encryption and Apple devices


macOS already has built in volume encryption in FileVault. To manually enable
You don’t have to add any additional software to encrypt a
folder, disk or volume on a Mac.
FileVault on macOS:

Newer Macs, like those powered by Apple Silicon, rely on
the secure enclave. A dedicated hardware component that Navigate to System Settings > Privacy & Security > FileVault
handles the creation and storage of encryption keys while
Select the button “Turn On…” to enable volume encryption
also performing algorithmic calculations.
Repeat for all devices

Intel-based Macs rely on a similar dedicated hardware
component named the T2 security chip to perform similar
functionality to the secure enclave. To enable FileVault across your organization’s devices, leverage your

FileVault is FIPS 140-2 certified. That means Apple’s MDM solution to automate, deploy and enforce encryption. You can
encryption system is certified by and meets the highest deploy a configuration profile or policy that will enable FileVault. IT
standards for federal government encryption. can retrieve recovery keys if staff need to decrypt the volume down
the road.

You can enable FileVault manually or remotely: personal
users can choose the option on one device, or IT can
automate and enforce enablement (using Jamf Pro) across Create a configuration profile through a simple selection of

hundreds or even thousands of devices with one policy. options within Jamf Pro

Grant users access to encrypt/decrypt volumes simply by Deploy granularly to as many devices as you’d like or to all

authenticating to macOS or entering their passcode on macOS-based devices
iOS and iPadOS devices. Users of supported devices can
There is no step three
leverage Apple’s TouchID or FaceID technologies to add a
layer of security to data protection through biometrics using
either their fingerprint or facial recognition patterns. With Jamf Pro, you can also configure recovery key redirection —
even if the user turns on FileVault themselves. IT will then have
the key saved within its management solution for easy retrieval by
device record.

TABLE OF CO N T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 18


ENCRYPTING DATA

What about an iPad or iPhone?

Encrypting iOS and iPadOS devices is even easier. iOS-based devices have built in encryption
enabled as soon as a passcode is set. You can do this individually, or you can require it from
Jamf Pro, as well as setting the parameters for passcode strength, such as minimum length and
complexity requirements.

Data in transit
Encrypting network connections from end-to-end
Conventional best practices dictated the use of a VPN to protect data as it moves from one device
to another service. This method heralds back decades, being developed at a time when VPNs
were used to bridge two disparate networks securely over an untrusted network, like the Internet.

And while this security control still remains in active use by many personal and enterprise users,
changes in the computing landscape over the last few years, stemming from the adoption of Apple
at work, the explosive growth of mobile devices for personal and business use and organizations
migrating to fully remote and hybrid work environments has revealed the limits of VPN technology
to effectively protect devices, users and data across the modern threat landscape.

These changes have all combined to revolutionize the way we work — and play — on computers
and mobile devices. So, why are you still relying on legacy processes for your security strategy to
keep data in motion safe?

The answer short answer is Zero Trust Network Access, or ZTNA for short. The long answer is
that this solution was developed from the very real-world need to keep various types of devices,
local and distributed users and teams. Also, data accessed over untrusted networks and relying on
cloud-based services to extend infrastructure while eroding the organization’s network perimeter.
All this while securing them against existing and novel security threats employed by threat actors,
with a notable increase in threats targeting macOS and mobile devices in general.

Simply put: Securing network connections is no longer just for employees traveling or a few special
use cases to remain productive remotely.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 19


ENCRYPTING DATA

It also extends beyond merely encrypting communications


between two points, requiring granular security protections,
to safeguard stakeholders and prevent access to company What you’ll need for data in transit
resources while minimizing the introduction of threats. Some
A secure network connection to a VPN server
of the ways ZTNA accomplishes this is by:
To connect to a VPN manually:

Integrating with cloud-based IdPs to extend centrally-
managed user accounts to include permissions that iOS and iPadOS macOS
follow the user around.
 Go to System Settings> VPN  Go to System Settings>

Frequent device checks ensure that endpoints meet Network>VPN & Filters
minimum requirements, such as being up to date with  Select “Add VPN Configuration”

patches, ensure that security integrity remains intact  Select “Add VPN
 T
 ype in the VPN server address
by checking for jailbroken or rooted devices and that Configuration”
on the device
endpoint security is both installed and configured  T
 ype in the VPN server
properly.  S
 elect it from your
address on the device
 network options
If endpoints fail a health check or have been deemed
 S
 elect it from your
compromised, ZTNA integration with a best-of-breed  Repeat for each device
network options
MDM solution, like Jamf Pro, enables policy-based
management by securely sharing telemetry data to  Repeat for each device
suspend access and execute remediation workflows
to perform the necessary tasks to bring the endpoint
into compliance, verifying that any detected issue(s) are To connect multiple devices to a VPN: “How can I be sure that my
resolved. encryption is seamless?”
After you have set up a VPN provider

Forgoing implicit trust, like legacy VPNs, instead One important way of ensuring
 C
 reate a configuration profile in an
operating by the mantra of “never trust — always security and consistent encryption is
MDM such as Jamf for iOS
verify” each time access to any requested company to host your MDM in the cloud. With a
and/or macOS
resource is made. It is only after verification has occurred reputable product such as Jamf Cloud,
 D
 eploy configurations to however you can rest easy knowing that your
successfully that access to the requested resource
many devices you’d like server is secure and your data safe,
is granted.
 Y
 ou guessed it — there is no and that any updates or patches are
step three immediately available.

TABLE OF CO N T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 20


ENCRYPTING DATA

Benefits of ZTNA over legacy VPN:


Security is enhanced by shifting from implicit trust to the explicit Zero Trust model that
requires verifying users and devices before granting access to requested resources.

Split-tunneling secures business traffic while personal traffic is routed directly to the
Internet — not back to a central network, reducing overhead and saving bandwidth,
which equals greater performance and improved privacy protection for end users.

Always-on protection means that resources are protected — even if the service is
disabled — upon requesting access, it will automatically enable to ensure traffic
remains protected every time.

A minimal footprint and cloud hosting means no expensive support contracts, complex
configurations or hardware to manage.

It also supports macOS, iOS, iPadOS, Android and Windows, which lowers the TCO
and alleviates the administrative burden on IT teams supporting multiple hardware and
software types.

In this section, we’ve discussed the basics of data encryption, the types of solutions native
to Apple devices and even explained the steps to enable this security control on macOS,
iOS and iPadOS. We’ve also discussed how modern ZTNA technology goes beyond legacy
VPN protection by continuing to secure remote network connections while including
additional layers of security to verify users and devices before granting access requests
and ensuring that data remains secure at rest (former) and in motion (latter). But what about
when data is being used, or processed by apps?

Unlock the other two data states; data in use does not have a specific security control to
mitigate this risk. Instead the solution lies in conjunction with ongoing management and
security workflows.

TABLE OF CO N T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 21


ENCRYPTING DATA

When apps access and process data, the data passes from the memory (RAM) to the app for
processing, then gets swapped back to memory before being saved permanently on the device’s
storage. Apps developed by known, trusted developers all contain security mechanisms to ensure
the app’s internal security remains intact. Among the many reasons for this, one such reason is to
ensure that data processed within an app is not shared with or leaked with other apps, services
or processes running on the device. This is designed to uphold the integrity of the data while the
app’s integrity is maintained.
However, apps that have become compromised through an exploit to a vulnerability had
unauthorized modifications to their internal security or are rogue apps, marketed as performing one
task really performing other clandestine tasks all place data security at risk while in use.

So, what’s the best solution, you ask? The answers below include a combination of best practices,
a defense-in-depth strategy, and processes and workflows leveraging Jamf Pro to keep data in use
as secure as possible:


A continual patch management policy that procures applications from legitimate sources, like
the Apple App Store, developer website, or from a trusted management vendor — like App
Installers with Jamf.

Deploying managed apps through your preferred MDM solution and implementing policy-
based management to keep apps up to date.

Verifying secure device settings by installing configuration profiles to minimize the possibility of
threats from misconfigurations.

Harden device settings to restrict risky behaviors that could introduce threats, like jailbreaking
iOS or iPadOS, or side-loading applications from unauthorized or insecure sources.

Implementing an ongoing user training program to keep stakeholders informed of common
threats and how certain actions, like Shadow IT, introduce risk.

Develop an Acceptable Use Policy (AUP) that all stakeholders sign to make them aware of
behavior expectations and consequences of violating company policy.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 22


By continuously gathering rich telemetry data, the details of each device that provides

5 insight into the security controls, settings and health status, IT can better protect
devices, users and data while making sure that endpoints that are out-of-scope are
quickly remediated and brought back into compliance before threats can lead to far
worse outcomes, like data breaches.

BUILDING BLOCK FIVE: As with most of the building blocks in this e-book, there are multiple paths to
monitor endpoint compliance: manual and automated methods. Depending on your

Compliance
organization’s requirements, compliance monitoring’s efficacy can be impacted by
contributing factors, such as knowledge base, device and security management
solutions used and budgetary considerations, to name a few of the most critical.

Monitoring Monitoring and managing inventory and compliance manually means:


Ensuring that all of your organization’s devices are protected by constantly
auditing devices
Know the status of protocols and Physically tracking down each device for inventory management needs
controls in place on all devices Individually updating software applications on each device to ensure they are up to date
Verify that security settings, like encryption, are configured consistently on every device
A security system is only as good as its Monitoring and confirming that no one has introduced risks, such as malware or
suspicious apps
weakest point. For the best coverage,
Performing OS and critical security updates as soon as they’re available to patch known
administrators must monitor the
vulnerabilities and fix bugs in software
organization’s devices to verify that
Deploying adequate personnel to triage detected issues, quarantine compromised devices
every device is updated, has received and perform remediation tasks to bring affected endpoints back into compliance
the most recent patches and has the
This method requires constant vigilance and large windows of time for administrative
correct configuration options set.
overhead related to completing management tasks. A great deal of buy in and
cooperation across stakeholders and management teams is needed to be successful.
“Awareness of ignorance is the It is also important to note that this method is largely reactive in nature, meaning that
beginning of wisdom.” time-sensitive issues, like incident response times, will likely be lengthened, occurring
— Socrates
after issues are detected — yet seldom beforehand.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 23


COMPLIANCE MONITORING

As a last consideration, the number and types of devices supported an increase in size, the
time for IT and Security to respond to issues manually will also increase exponentially. This
gives threat actors more time to expand threats in their attack chain against organizations,
simultaneously increasing the risk of a data breach.

Monitoring inventory with Jamf means:


View up-to-date, real-time information on all devices simultaneously

Deploy updates and security configurations for any device that is not secured properly
Say it with us: there is no step three

The ability to see device inventory statuses helps administrators keep their finger on the pulse
of every Apple device in their fleet. By knowing the current status of a device, administrators
can efficiently manage devices and security by knowing which updates to send where, and
which security features to configure respectively. Creating Smart Groups, based on dynamic
criteria means that administrators can be as targeted or all-encompassing in updates as they
choose. Whether based on granular permissions, specific device types, or virtually any other
categorization method, Jamf Pro provides powerful tools to make short work of compliance-
related tasks while maintaining the flexibility to zero in (or send tasks to all devices in your fleet)
through customizable criteria. Learn more with our Inventory Management for Beginners e-book.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 24


Managing compliance with Jamf means:


Audit endpoints based on Center for Internet Security (CIS) benchmarks

Stream all your compliance data to the cloud for centralized management

Access macOS unified logs and comprehensive endpoint telemetry to identify
threats quickly and efficiently

Enforce compliance using policies to automate remediation tasks and keep
endpoints in-scope

Monitor for Common Vulnerabilities and Exposures (CVE) to understand the
vulnerabilities that exist in your environment

Prevent security threats using comprehensive analytics mapped to the MITRE
&TTACK framework

Securely share telemetry data between management (Jamf Pro) and security (Jamf
Protect) solutions via API to develop advanced workflows to automatically minimize
incident response times and resolve identified issues without delay

It’s not enough to secure your devices; many regulations mandate that organizations be
able to prove that devices continue to be secure and meet compliance requirements.
This means organizations must provide documentation to corroborate compliance levels
during various points in their timeline. After all, if you can’t provide evidence the device
was compliant at a given time, then for all intents and purposes — it wasn’t compliant.
However, Jamf’s data and reporting provides organizations with the necessary tools
to obtain telemetry data from every endpoint and organize this data using critical
categorizations, like patch levels, vulnerabilities detected and timestamps that identify
actions performed during the device’s lifecycle. Plus, integration allows the secure
sharing of telemetry data with first- and third-party tools to further extend data through
centralized dashboards to include data visualizations and export to other formats for
sharing compliance reports with regulatory investigators.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 25


6

BUILDING BLOCK SIX:

Application Application Security

Security and Knowing that identified vulnerabilities are patched is vital to the
device’s security posture. But do you know where your applications

Management
come from? And are you confident that they don’t contain malware or
other malicious code? The answer to those questions is critical to your
organization because if you can’t trust your application sources, you
risk compromising the security of your devices, as well as end-user
privacy and exposing sensitive data.
Patch reporting, policies and App
Installers to maintain apps updated Apple makes preserving security and privacy a top priority. When
while enforcing security easily. it comes to app security, they make apps as safe as possible to
download and use.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 26


APPLICATION SECURITY
AND MANAGEMENT

Features of application security and management:

1 Apps run in a sandbox: Each app runs in its unique space


and can’t interact with other applications. Before allowing 4 Gatekeeper blocks suspicious apps from running:
Before any macOS application is permitted to run the first
apps to read/write to/from others’ shared data, explicit time (and following each subsequent update), notarization
approval is required from an authenticated user. tickets assigned are checked against Gatekeeper to
determine if the ticket is valid or revoked. Suppose the
former, the app is allowed to run without issue. In that

2  entralized and secure app procurement: Apps in Apple’s


C case, if the latter, the app is restricted from running,
App Store are vetted to alleviate security risks. Part of this informing the user that it may have been modified by
is achieved by notarization while the other part provides an unauthorized party, impacting the integrity of its
a secure, cloud-based repository managed by Apple to internal security.
host apps that have passed rigorous security assessments.
It also provides a means for developers to place the

5
latest version of their hosted apps directly in the hands of Restrictions on app usage: On iOS-based devices, the
users, eliminating the possibility of introducing risk from only secure way to get apps is via the App Store. That
downloading illegitimate software from risky sources. said, jailbreaking iOS and iPadOS devices introduces
the ability to access third-party app stores that are often
used to distribute apps that have been “cracked”, or had
their internal security removed, such as paid apps that

3
are made available for free but often have been injected
Notarization signs off on security integrity: Notarizing
with malicious code by threat actors to steal data or spy
apps gives users more confidence that software signed by
on users. With an MDM, like Jamf Pro, administrators
a developer’s unique ID — and downloaded to your Mac —
can set up alerts to notify them when jailbroken devices
has been checked by Apple for malicious components and
are identified, allowing them to perform remediation
code-signing issues. When an app is notarized, you can
workflows to correct the security issue.
trust it hasn’t been tampered with or compromised.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 27


ENCRYPTING DATA

On macOS, users (or administrators with an MDM) may select from two
Gatekeeper options:

Mac App Store


Mac App Store and identified developers

Confining macOS users to the Mac App Store for their apps allows adminstrators to
control app security device-wide while minimizing the risk of introducing threats —
malicious or otherwise — from suspicious, risky and/or compromised apps. However,
if requiring third-party apps that are only available from the developer’s website,
the second option permits obtaining apps from both the App Store and identified
developers that are vetted by Apple and create software packages signed with their
respective developer ID for greater security.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 28


Best practices

For macOS, configure allowing the Mac App Store and identified developers selection,
especially if you create your own applications or repackage apps for deployment. Also,
apply for a developer ID from Apple and sign internally-developed applications by the
organization so Gatekeeper will trust them. Lastly, by using Jamf Pro as your MDM solution,
the Self Service app catalog can be deployed to all devices, whereby IT pre-approves apps,
settings, configurations and much more to end users, allowing them to access and install the
tools and services they need, when they need them, without requiring a help desk ticket,
modification of permissions or an Apple ID.

Setting up Gatekeeper options manually:

Navigate to: System Settings > Privacy & Security > Security

Select from the two options available

Repeat for every device in your organization

Setting up Gatekeeper options with Jamf Pro:

 et up and deploy a configuration profile with your Gatekeeper settings to all your
S
devices.

That’s it!

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 29


BEST PRACTICES

Application and security patches and updates


OS updates, version control with MDM commands, rapid security response and more

Organizations must implement a patch management strategy to test for Let’s review some of the options available to administrators managing
and incorporate bug fixes as quickly as possible to keep their hardware, patches manually and via MDM:
data and users protected. Testing is an often overlooked necessity when
Options for managing patches manually:
deploying patches, especially when bugs present themselves in the form
 Educate users to perform updates themselves as soon as they receive
of security vulnerabilities that need to be addressed as quickly as possible.
update notifications on their devices.
By performing both as soon as possible, IT reduces the impact of security
 Collect all devices when a new patch is released a new patch and
threats spreading while introducing greater issues — stemming from patches
manually deploy.
that fix one thing but inadvertently break other, more critical functions — to
 Remediate devices missing patches as part of your ongoing compliance
a minimum.
monitoring processes.

Throughout this e-book, the trend of how long administrative tasks performed
by IT will take to complete is directly correlated to the number of devices Options for managing patches via MDM (i.e. Jamf Pro):
managed. When managing patches, this rule continues to be the case except
for one variable: the number of patches required to deploy could range from 
Updates and patch notifications are automatically received by Jamf, along
few to many, exponentially increasing the administrative tasks by an unknown with tools for deploying patches to all of your organization’s devices, so
quantity per device. you can update on your timetable — not someone else’s.

Jamf’s Self Service app catalog makes it easy to empower users to
update anytime a new patch is available by notifying users that they need
to update before continuing to use an affected app.

Eliminate the reliance on end users while alleviating the burden on IT by
automating patch distribution. Send out patches as policies to all devices,
or target them with dynamic Smart Groups to ensure that devices are up
to date.

To learn more about the app lifecycle and automating and deploying apps, check out our white paper.

TABLE OF CO N T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 30


BEST PRACTICES

Leveling up your security


If you haven’t guessed by now, security is not a “one-size-fits-all” solution. Each of the solutions above can theoretically work as a standalone solution
There are layers to a comprehensive strategy that will holistically protect to provide home security. But on its own, it only provides one piece of the
your devices, users and data while also providing granular protections that overall security necessary, right? However, when you combine them, the
weave together to form a digital safety net. This is referred to as defense-in- multiple pieces fit together like a puzzle to illustrate the full picture and
depth, meaning that if one layer does not catch a threat, the next one above comprehensively target the full range of issues. Cybersecurity and the
or below it is there to contain it. management and security of your Apple device fleet are based on similar
principles, forming the crux of empowering and informing users to have and
You’re likely already familiar with the layered security approach and may not
follow good security practices to minimize risk and mitigate threats.
even know it. Let’s use something you’re very familiar with as an example:
your home. One such layer of endpoint security is being alerted to risks to devices. For
example, some users may be able to detect a phishing attack and therefore
With the blend of legacy and new security protections available for home
not click on a malicious link yet; some users may be a little too trusting
safety, you’ve no doubt got some (or maybe all) protecting your loved ones
and carry out the instructions of the malicious link, thereby potentially
and yourself at home:
introducing risk to the device, user and data. How would this affected user
 D
 eadbolt locks on your doors even know they clicked on a malicious link or performed an action that has
 H
 ome alarm system compromised their device or credentials?

 V
 ideo camera surveillance There’s an app for that! Jamf Trust protects against user-initiated risks, like
 S
 ecurity guards that patrol the grounds the above phishing attack example, by notifying users in the form of Apple
Push Notifications when Jamf detects a threat on their device — like if that
 S
 moke and carbon monoxide detectors
malicious link that was clicked on previously delivered malicious code in the
 F
 ire extinguisher form of malware currently recording keystrokes on the device.
 H
 omeowner’s or renter’s insurance
The solution has determined a threat exists and has informed the user (and
the administrator, as well). Helping the user to be mindful of the danger and
to look out for those like it in the future while IT can respond to the incident
and remediate it quickly, utilizing a combination of Jamf Pro and Jamf
Protect to quarantine the device from the network, clean out the infection,
patch any vulnerabilities present and restore the device to its baseline.
Lastly, use the lessons learned to inform future security awareness training
for stakeholders.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 31


Device and data security
is no laughing matter.

Organizations have the choice to get ahead of many possible attacks or data thefts by implementing the strongest possible
security protections through Apple — and Jamf can make this easier, faster and far more secure and efficient than manual
security protocols.

When it comes to cybersecurity, no one likes surprises and certainly doesn’t want to find themselves scrambling in response
to an attack if they can help it. Get the best security options for your organization by taking Jamf product solutions for
a free trial run, or start by contacting a Jamf representative today to discuss what a customized, comprehensive Apple
management and security solution looks like for your organization’s unique needs.

You’ve tried the rest…now go with the best!

Try Jamf

Or contact your preferred reseller of Apple devices for a free trial.

TABLE OF CON T EN TS — A PPLE D E V I C E S E C U R I T Y FOR BE G I NNE R S | 32

[Link]
© 2023 Jamf, LLC. All rights reserved.

You might also like