4.3 Create network specific locations

Information

The network location feature of the Mac is very powerful tool to manage network security. By creating different network locations, a user can easily (and without administrative privileges) change the network settings on the Mac. By only using the network interfaces needed at any specific time, exposure to network attacks is limited.

A little understanding of how the Network System Preferences pane works is required.

Rationale:

Network locations allow the computer to have specific configurations ready for network access when required. Locations can be used to manage which network interfaces are available for specialized network access

Impact:

Unneeded network interfaces increases the attack surface and could lead to a successful exploit.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Create multiple network locations as needed.
Delete the Automatic location for any device that does not use multiple network services set for DHCP or dynamic addressing. If network services like FireWire, VPN, AirPort or Ethernet are not used by a specific device class those services should be deleted:

Select Edit Locations from the Locations popup menu.

Select the Automatic location.

Click the minus button for any unneeded service.




Additional Information:

Deleting the Automatic location cannot be undone.

See Also

https://workbench.cisecurity.org/files/3092

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7(1), CSCv7|15.10

Plugin: Unix

Control ID: 8550ad0ab4d4e10fe6177178d7e93ebdb78964f3d589c465e36309308f871656