# SP-024 iPhone Pattern

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for managing iOS devices in enterprise environments. Covers device encryption, remote wipe, application control, acceptable use policies, and mobile device lifecycle management for iPhones carrying corporate or sensitive data.
Use when: Apply this pattern whenever iPhones carry corporate or sensitive data, including email, documents, credentials, or access to corporate applications. It applies to both corporate-owned and BYOD devices that access organisational resources.
Not when: If an iPhone is used purely for personal purposes with no corporate data, email, or application access, this pattern does not apply.

## Controls (8, NIST SP 800-53 ids)
- Critical (4): IA-07, SA-07, SC-13, SI-03
- Important (4): AT-02, PL-04, PS-06, SA-03
- Withdrawn in SP 800-53 Rev 5: SA-07 (now in CM-11, SI-07)

## What each critical control mitigates (4)
- IA-07 Cryptographic Module Authentication: T-IP-001, T-IP-005
- SA-07 User Installed Software: T-IP-002, T-IP-003, T-IP-004
- SC-13 Use Of Cryptography: T-IP-001, T-IP-005, T-IP-008
- SI-03 Malicious Code Protection: T-IP-002, T-IP-003, T-IP-008

## Threats and the controls that mitigate them (8)
- T-IP-001 Device Theft or Loss Leading to Data Breach: SC-13, IA-07, PL-04
- T-IP-002 Malicious Application Installation: SA-07, SI-03, SA-03
- T-IP-003 Jailbreak Bypassing iOS Security Model: SI-03, SA-07, PL-04
- T-IP-004 Corporate Data Leakage to Personal Apps: SA-07, PS-06, PL-04
- T-IP-005 Remote Wipe Prevention by Shielding Device: SC-13, IA-07, AT-02
- T-IP-006 User Weakening Security Configuration: PL-04, PS-06, AT-02
- T-IP-007 Delayed Device Loss Reporting Extending Exposure Window: AT-02, PL-04, PS-06
- T-IP-008 Targeted Spyware or Zero-Day Exploitation: SI-03, SA-03, SC-13

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-024/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-024/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 18 KB: /api/v1/patterns/SP-024
- Page for people: /patterns/sp-024/
- Related: SP-001 Client Module; SP-003 Privacy Mobile Device Pattern; SP-006 Wireless Private Network Pattern; SP-007 Wireless Public Hotspot Pattern; SP-013 Data Security Pattern; SP-014 Awareness and Training Pattern

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
