Check: APPL-13-005053
Apple macOS 13 (Ventura) STIG:
APPL-13-005053
(in versions v1 r4 through v1 r1)
Title
The macOS system must restrict the ability of individuals to write to external optical media. (Cat III impact)
Discussion
External writeable media devices must be disabled for users. External optical media devices can be used to exfiltrate sensitive data if an approved data-loss prevention (DLP) solution is not installed.
Check Content
Verify the macOS system is configured to disable writing to external optical media devices with the following command: /usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep "BurnSupport" BurnSupport = off; If "BurnSupport" is not set to "off" and is not documented with the Information System Security Officer (ISSO) as an operational requirement, this is a finding.
Fix Text
Configure the macOS system to disable writing to external optical media devices by installing the "Restrictions Policy" configuration profile.
Additional Identifiers
Rule ID: SV-257245r905368_rule
Vulnerability ID: V-257245
Group Title: SRG-OS-000480-GPOS-00227
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |