Guidance
Application development
Recommendations for the secure development, procurement and deployment of generic and platform-specific applications.
Pages
Page 8 of 16
Apple iOS application development
Recommendations for the secure development, procurement and deployment of Apple iOS applications.
This guidance contains recommendations for the secure development,procurement and deployment of iOS applications. Please familiarise yourself with the generic application development guidance section before continuing.
- Note that this guidance also refers to concepts described in the NCSC End User Devices Security Guidance. We recommend you familiarise yourself with this before reading the guidance below.
- A general guide to secure Apple programming can be found in Apple’s security guide.
Regarding data at rest and keychain protection classes, the following terminology will be used:
| Availability class name | Data protection class | Keychain protection class |
|---|---|---|
| A (when unlocked) | NSFileProtectionComplete | kSecAttrAccessibleWhenUnlocked |
| B (while unlocked) | NSFileProtectionCompleteUnlessOpen | N/A |
| C (after first unlock) | NSFileProtectionCompleteUntilFirstUserAuthentication (default on iOS 7 and above) | kSecAttrAccessibleAfterFirstUnlock |
| D (always) | NSFileProtectionNone | kSecAttrAccessibleAlways |
| Passcode enabled | N/A | kSecAttrAccessible WhenPasscodeSetThisDeviceOnly* |
Note that the other keychain classes have a ‘This device only’ counterpart. More information about these protection classes can be found within Apple’s security guide document and API documentation.