Files
macos_security/rules/os/os_password_sharing_disable.yaml
2023-09-14 14:21:06 -04:00

58 lines
1.2 KiB
YAML

id: os_password_sharing_disable
title: "Disable Password Sharing"
discussion: |
Password Sharing _MUST_ be disabled.
The default behavior of macOS is to allow users to share a password over Airdrop between other macOS and iOS devices. This feature _MUST_ be disabled to prevent passwords from being shared.
check: |
/usr/bin/osascript -l JavaScript << EOS
$.NSUserDefaults.alloc.initWithSuiteName('com.apple.applicationaccess')\
.objectForKey('allowPasswordSharing').js
EOS
result:
string: "false"
fix: |
This is implemented by a Configuration Profile.
references:
cce:
- CCE-92846-5
800-53r5:
- IA-5
800-53r4:
- IA-5
srg:
- N/A
disa_stig:
- N/A
800-171r2:
- 3.5.1
- 3.5.2
cis:
benchmark:
- N/A
controls v8:
- 4.1
- 4.8
cmmc:
- IA.L2-3.5.8
- IA.L2-3.5.9
macOS:
- "14.0"
tags:
- 800-53r5_low
- 800-53r5_moderate
- 800-53r5_high
- 800-53r4_low
- 800-53r4_moderate
- 800-53r4_high
- 800-171
- cisv8
- cnssi-1253_moderate
- cnssi-1253_low
- cnssi-1253_high
- cmmc_lvl2
mobileconfig: true
mobileconfig_info:
com.apple.applicationaccess:
allowPasswordSharing: false