Files
macos_security/rules/os/os_password_proximity_disable.yaml
2023-09-14 14:21:06 -04:00

61 lines
1.3 KiB
YAML

id: os_password_proximity_disable
title: "Disable Proximity Based Password Sharing Requests"
discussion: |
Proximity based password sharing requests _MUST_ be disabled.
The default behavior of macOS is to allow users to request passwords from other known devices (macOS and iOS). This feature _MUST_ be disabled to prevent passwords from being shared.
check: |
/usr/bin/osascript -l JavaScript << EOS
$.NSUserDefaults.alloc.initWithSuiteName('com.apple.applicationaccess')\
.objectForKey('allowPasswordProximityRequests').js
EOS
result:
string: "false"
fix: |
This is implemented by a Configuration Profile.
references:
cce:
- CCE-92845-7
cci:
- CCI-000381
800-53r5:
- IA-5
800-53r4:
- IA-5
srg:
- SRG-OS-000095-GPOS-00049
disa_stig:
- N/A
800-171r2:
- 3.5.1
- 3.5.2
cis:
benchmark:
- N/A
controls v8:
- 4.1
- 4.8
cmmc:
- IA.L2-3.5.8
- IA.L2-3.5.9
macOS:
- "14.0"
tags:
- 800-53r5_low
- 800-53r5_moderate
- 800-53r5_high
- 800-53r4_low
- 800-53r4_moderate
- 800-53r4_high
- 800-171
- cisv8
- cnssi-1253_moderate
- cnssi-1253_low
- cnssi-1253_high
- cmmc_lvl2
severity: "medium"
mobileconfig: true
mobileconfig_info:
com.apple.applicationaccess:
allowPasswordProximityRequests: false