2.5.2.1 Enable Gatekeeper

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Gatekeeper is Apple's application white-listing control that restricts downloaded applications from launching. It functions as a control to limit applications from unverified sources from running without authorization.

Rationale:

Disallowing unsigned software will reduce the risk of unauthorized or malicious applications from running on the system.

Solution

Perform the following to implement the prescribed state:
Graphical Method:

Open System Preferences

Select Security & Privacy

Select General

Set Allow apps downloaded from to App Store and identified developers

Terminal Method:
Run the following command to enable Gatekeeper to allow applications from App Store and identified developers:

$ sudo spctl --master-enable

See Also

https://workbench.cisecurity.org/files/3193

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4), CSCv7|2.6, CSCv7|2.7

Plugin: Unix

Control ID: c3f8443dda65f4099b83b262790fab6be4a2cdcdebb23077105880cbf132b4ae