Check: AOSX-15-000007
Apple OS X 10.15 (Catalina) STIG:
AOSX-15-000007
(in versions v1 r10 through v1 r1)
Title
The macOS system must be configured to disable hot corners. (Cat II impact)
Discussion
Although hot corners can be used to initiate a session lock or launch useful applications, they can also be configured to disable an automatic session lock from initiating. Such a configuration introduces the risk that a user might forget to manually lock the screen before stepping away from the computer.
Check Content
To check if the system is configured to disable hot corners, run the following commands: /usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep wvous If the return is null or does not equal the following, this is a finding: "wvous-bl-corner = 0 wvous-br-corner = 0; wvous-tl-corner = 0; wvous-tr-corner = 0;"
Fix Text
This setting is enforced using the "Custom Policy" configuration profile.
Additional Identifiers
Rule ID: SV-225124r610901_rule
Vulnerability ID: V-225124
Group Title: SRG-OS-000031-GPOS-00012
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000060 |
The information system conceals, via the session lock, information previously visible on the display with a publicly viewable image. |
Controls
Number | Title |
---|---|
AC-11 (1) |
Pattern-Hiding Displays |