Check: APPL-15-005160
Apple macOS 15 (Sequoia) STIG:
APPL-15-005160
(in versions v1 r3 through v1 r1)
Title
The macOS system must disable Apple Intelligence Writing Tools. (Cat II impact)
Discussion
Apple Intelligence features that use off device Artificial Intelligence must be disabled. Use of off-device AI poses a data loss risk.
Check Content
Verify the macOS system is configured to disable Apple Intelligence Writing Tools with the following command: /usr/bin/osascript -l JavaScript << EOS $.NSUserDefaults.alloc.initWithSuiteName('com.apple.applicationaccess')\ .objectForKey('allowWritingTools').js EOS If the result is not "false", this is a finding.
Fix Text
Configure the macOS system to disable Apple Intelligence Writing Tools by installing the "com.apple.applicationaccess" configuration profile.
Additional Identifiers
Rule ID: SV-268574r1034662_rule
Vulnerability ID: V-268574
Group Title: SRG-OS-000095-GPOS-00049
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
Configure the system to provide only organization-defined mission essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |