Check: OSX8-00-00155
Apple OSX 10.8 STIG:
OSX8-00-00155
(in version v1 r2)
Title
The system firewall must be configured with a default-deny policy. (Cat II impact)
Discussion
Information flow control regulates where information is allowed to travel within an information system and between information systems (as opposed to who is allowed to access the information) and without explicit regard to subsequent accesses to the information. Information flow control policies and enforcement mechanisms are commonly employed by organizations to control the flow of information between designated sources and destinations (e.g., networks, individuals, devices) within information systems and between interconnected systems. Flow control is based on the characteristics of the information and/or the information path.
Check Content
Ask the SA or IAO if an approved firewall is loaded on the system. The recommended system is the McAfee HBSS. If there is no local firewall installed on the system, and configured with a default deny policy, this is a finding.
Fix Text
Install an approved HBSS or firewall solution onto the system.
Additional Identifiers
Rule ID: SV-65621r1_rule
Vulnerability ID: V-51411
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001414 |
The information system enforces approved authorizations for controlling the flow of information between interconnected systems based on organization-defined information flow control policies. |
Controls
Number | Title |
---|---|
AC-4 |
Information Flow Enforcement |