2.13 Ensure EFI version is valid and being regularly checked - itegrity-check

Information

In order to mitigate firmware attacks Apple has created a automated Firmware check to ensure that the EFI version running is a known good version from Apple. There is also an automated process to check it every seven days.

Rationale:

If the Firmware of a computer has been compromised the Operating System that the Firmware loads cannot be trusted either.

Solution

If EFI does not pass the integrity check you may send a report to Apple. Backing up files and clean installing a known good Operating System and Firmware is recommended.

See Also

https://workbench.cisecurity.org/files/3013

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(9)

Plugin: Unix

Control ID: 4b266187573d5d771194ec28d416986356e32bbb040431a7ccdb2a0ebc5f2334