2.12 Configure Secure Empty Trash

Information

Secure Empty Trash not only removes the file information from the file directory, it also overwrites the data in the file with meaningless data, thus preventing the file from being recovered. Configuring Secure Empty Trash mitigates the risk of an admin user on the system recovering sensitive files that the user has deleted. It is possible for anyone with physical access to the device to get access if FileVault is not used, or to recover deleted data if the FileVault volume is already mounted.

Solution

Perform the following to implement the prescribed state: Select Finder Select Preferences Select Advanced Check Empty Trash Securely Impact: Secure Empty Trash can take a long time, with FileVault in place the protection is erasing data within an already encrypted volume. This control does not effect the use of the rm command in the terminal. Users who rarely have large files to erase can use rm as a workaround cd ~/.Trash rm myproject-cui.pptx

See Also

https://workbench.cisecurity.org/files/299

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Unix

Control ID: beb0eb9a43b62457b1f05d9d672dac87e7fb3f6ca747ca4e0d46e2977baa2e2c