4.6 Audit Wi-Fi Settings

Information

Some organizations have comprehensive rules that cover the use of wireless technologies in order to implement operational security. There are specific policies governing the use of both Bluetooth and Wi-Fi (802.11) that often include disabling the wireless capability in either software or hardware or both.

Wireless access is part of the feature set required for mobile computers and is considered essential for most users.

Rationale:

The general use case for macOS is to use wireless connectivity. In the current hardware offering very few computers made by Apple provide a built-in wired network capability. While it is possible to get an ethernet adapter for wired connectivity it is not the default. The almost exclusive Apple use case is to support mobile connectivity for users of their devices through wireless connections. For use cases that wireless connectivity is not allowed an Apple model with built-in ethernet is the best option. Wireless can be turned off in those situations in the network system preference pane.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Perform the following to set Airport to the correct status:
Graphical Method:

Open System Preferences

Select Network

Select Wi-Fi

Set Status to your organization's parameters

Terminal Method:
Run the following command to set Airport to the correct status:

$ sudo networksetup -setairportpower <network device number> <on/off>

Example:

$ sudo networksetup -setairportpower en1 on

See Also

https://workbench.cisecurity.org/files/3569

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-18, 800-53|CM-6, 800-53|CM-7, 800-53|SC-23, CSCv7|15.4, CSCv7|15.5

Plugin: Unix

Control ID: 92a7deb16db2958126d6662fa3697f029baed6a1a57d3ae9ced471553c5a7e8b