5.10 Require an administrator password to access system-wide preferences

Information

System Preferences controls system and user settings on a macOS Computer. System Preferences allows the user to tailor their experience on the computer as well as allowing the System Administrator to configure global security settings. Some of the settings should only be altered by the person responsible for the computer.

Rationale:

By requiring a password to unlock system-wide System Preferences the risk is mitigated of a user changing configurations that affect the entire system and requires an admin user to re-authenticate to make changes

Impact:

If Automatic login is not disabled an unauthorized user could login without supplying a user password or credential.

Solution

Perform the following to verify that an administrator password is required to access system-wide preferences:
Graphical Method:

Open System Preferences

Select Security & Privacy

Select General

Select Advanced...

Set Require an administrator password to access system-wide preferences

Terminal Method:
The authorizationdb settings cannot be written to directly, so the plist must be exported out to temporary file. Changes can be made to the temporary plist, then imported back into the authorizationdb settings.
Run the following commands to enable that an administrator password is required to access system-wide preferences:

$ sudo security authorizationdb read system.preferences > /tmp/system.preferences.plist

YES (0)

$ sudo defaults write /tmp/system.preferences.plist shared -bool false

$ sudo security authorizationdb write system.preferences < /tmp/system.preferences.plist

YES (0)

See Also

https://workbench.cisecurity.org/files/3569

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: 3041e95b7c66f8c96d68c8530605d1966a2e23ab396d82219c49a8da74200add