system_settings_cd_dvd_sharing_disable rule missing from macOS 14 Sequoia and macOS 15 Sonoma #26

Closed
opened 2026-01-19 18:28:58 +00:00 by michael · 0 comments
Owner

Originally created by @erefneb on GitHub.

The rule system_settings_cd_dvd_sharing_disable is missing from macOS 14 Sequoia and macOS 15 Sonoma.
Although Apple did remove the GUI for CD/DVD Sharing from System Settings the LaunchDaemon is still present in the OS (even in Tahoe), and could be enabled from the command line.

This rule is still active and listed in the following baselines:
DISA STIG macOS 15 - https://stigviewer.com/stigs/apple_macos_15_sequoia/2024-12-04/finding/V-268520
CIS Level 1 - 2.3.3.1

Fix:
Add system_settings_cd_dvd_sharing_disable into:
macOS Sonoma
macOS Sequoia
macOS Tahoe
future versions macOS that include the LaunchDaemon com.apple.ODSAgent.plist

Include system_settings_cd_dvd_sharing_disable in the baseline yaml files for:
800-53r5_low
800-53r5_moderate
800-53r5_high
800-53r4_low
800-53r4_moderate
800-53r4_high
cis_lvl1
cis_lvl2
cisv8
cnssi-1253_moderate
cnssi-1253_low
cnssi-1253_high
cmmc_lvl2

Originally created by @erefneb on GitHub. The rule [system_settings_cd_dvd_sharing_disable](https://github.com/usnistgov/macos_security/blob/ventura/rules/system_settings/system_settings_cd_dvd_sharing_disable.yaml) is missing from macOS 14 Sequoia and macOS 15 Sonoma. Although Apple did remove the GUI for CD/DVD Sharing from System Settings the LaunchDaemon is still present in the OS (even in Tahoe), and could be enabled from the command line. This rule is still active and listed in the following baselines: DISA STIG macOS 15 - [https://stigviewer.com/stigs/apple_macos_15_sequoia/2024-12-04/finding/V-268520](https://stigviewer.com/stigs/apple_macos_15_sequoia/2024-12-04/finding/V-268520) CIS Level 1 - 2.3.3.1 Fix: Add system_settings_cd_dvd_sharing_disable into: macOS Sonoma macOS Sequoia macOS Tahoe future versions macOS that include the LaunchDaemon com.apple.ODSAgent.plist Include system_settings_cd_dvd_sharing_disable in the baseline yaml files for: 800-53r5_low 800-53r5_moderate 800-53r5_high 800-53r4_low 800-53r4_moderate 800-53r4_high cis_lvl1 cis_lvl2 cisv8 cnssi-1253_moderate cnssi-1253_low cnssi-1253_high cmmc_lvl2
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: usnistgov/macos_security#26