2.5.1.3 Ensure all user storage CoreStorage volumes are encrypted

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Apple introduced CoreStorage with 10.7. It is used as the default for formatting on macOS volumes prior to 10.13.

All HFS and CoreStorage Volumes should be encrypted.

Rationale:

In order to protect user data from loss or tampering, volumes carrying data should be encrypted.

Impact:

While FileVault protects the boot volume, data may be copied to other attached storage and reduce the protection afforded by FileVault. Ensure all user volumes are encrypted to protect data.

Solution

Use Disk Utility to erase a disk and format as macOS Extended (Journaled, Encrypted).

See Also

https://workbench.cisecurity.org/files/4004