mirror of
https://github.com/usnistgov/macos_security.git
synced 2026-02-03 05:53:24 +00:00
system_settings_cd_dvd_sharing_disable rule missing from macOS 14 Sequoia and macOS 15 Sonoma #26
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @erefneb on GitHub.
The rule system_settings_cd_dvd_sharing_disable is missing from macOS 14 Sequoia and macOS 15 Sonoma.
Although Apple did remove the GUI for CD/DVD Sharing from System Settings the LaunchDaemon is still present in the OS (even in Tahoe), and could be enabled from the command line.
This rule is still active and listed in the following baselines:
DISA STIG macOS 15 - https://stigviewer.com/stigs/apple_macos_15_sequoia/2024-12-04/finding/V-268520
CIS Level 1 - 2.3.3.1
Fix:
Add system_settings_cd_dvd_sharing_disable into:
macOS Sonoma
macOS Sequoia
macOS Tahoe
future versions macOS that include the LaunchDaemon com.apple.ODSAgent.plist
Include system_settings_cd_dvd_sharing_disable in the baseline yaml files for:
800-53r5_low
800-53r5_moderate
800-53r5_high
800-53r4_low
800-53r4_moderate
800-53r4_high
cis_lvl1
cis_lvl2
cisv8
cnssi-1253_moderate
cnssi-1253_low
cnssi-1253_high
cmmc_lvl2