Skip to main content
Guidance

Application development

Recommendations for the secure development, procurement and deployment of generic and platform-specific applications.

Page 8 of 16

Apple iOS application development

Recommendations for the secure development, procurement and deployment of Apple iOS applications.

This guidance contains recommendations for the secure development,procurement and deployment of iOS applications. Please familiarise yourself with the generic application development guidance section before continuing.

Regarding data at rest and keychain protection classes, the following terminology will be used:

Availability class nameData protection classKeychain protection class
A (when unlocked)NSFileProtectionCompletekSecAttrAccessibleWhenUnlocked
B (while unlocked)NSFileProtectionCompleteUnlessOpenN/A
C (after first unlock)NSFileProtectionCompleteUntilFirstUserAuthentication (default on iOS 7 and above)kSecAttrAccessibleAfterFirstUnlock
D (always)NSFileProtectionNonekSecAttrAccessibleAlways
Passcode enabledN/AkSecAttrAccessible WhenPasscodeSetThisDeviceOnly*

Note that the other keychain classes have a ‘This device only’ counterpart. More information about these protection classes can be found within Apple’s security guide document and API documentation.

Reviewed

Version

1.0