Files
macos_security/rules/os/os_root_disable.yaml
2020-09-10 17:28:46 -04:00

39 lines
906 B
YAML

id: os_root_disable
title: "Disable Root Login"
discussion: |
To assure individual accountability and prevent unauthorized access, logging in as root at the login window _MUST_ be disabled.
The macOS system _MUST_ require individuals to be authenticated with an individual authenticator prior to using a group authenticator, and administrator users _MUST_ never log in directly as root.
check: |
/usr/bin/dscl . -read /Users/root UserShell 2>&1 | /usr/bin/grep -c "/usr/bin/false"
result:
integer: 1
fix: |
[source,bash]
----
/usr/bin/dscl . -create /Users/root UserShell /usr/bin/false
----
references:
cce:
- CCE-84783-0
800-53r4:
- IA-2
disa_stig:
- N/A
srg:
- N/A
cci:
- N/A
800-171r2:
- 3.5.1
- 3.5.2
macOS:
- "10.15"
tags:
- 800-171
- cnssi-1253
- fisma-low
- fisma-moderate
- fisma-high
mobileconfig: false
mobileconfig_info: