1.3 Enable app update installs

Information

Ensure that application updates are installed after they are available from Apple. These updates do not require reboots or admin privileges for end users.

Rationale:

Patches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited

Impact:

Unpatched software may be exploited

Solution

Perform the following to implement the prescribed state:

Open a terminal session and enter the following command to enable the auto update feature:

sudo defaults write /Library/Preferences/com.apple.commerce AutoUpdate -bool TRUE

The remediation requires a log out and log in to show in the GUI. Please note that.

See Also

https://workbench.cisecurity.org/files/3092

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(5)

Plugin: Unix

Control ID: a2cf8f931f249e2e51d9dbcce108da34bd52a297deeb5ad1325a935889d744ae