1.3 Enable app update installs

Information

Ensure that application updates are installed after they are available from Apple. These updates do not require reboots or admin privileges for end users. Patches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited

Solution

Perform the following to implement the prescribed state: Open a terminal session and enter the following command to enable the auto update feature: sudo defaults write /Library/Preferences/com.apple.storeagent AutoUpdate -int 1 The remediation requires a log out and log in to show in the GUI. Please note that. Impact: Unpatched software may be exploited

See Also

https://workbench.cisecurity.org/files/299

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(5)

Plugin: Unix

Control ID: 16d48fdbccc9033104c14812c8c4aee6570c6c5ba2114770aaf09a3f29c791cf