2.11.2 Audit Touch ID and Wallet & Apple Pay Settings

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Apple has integrated Touch ID with macOS and allows fingerprint use for many common operations. All use of Touch ID requires the presence of a password and the use of that password after every reboot, or when more than 48 hours has elapsed since the device was last unlocked.

Touch ID is a prerequisite for using Apple Pay and Wallet on macOS. Apple Pay allows an Apple account holder to enroll their credit cards in Apple Pay and pay enrolled vendors without using the physical card or number. Apple's service eliminates the requirement to send the credit card number itself to the vendor. Apple Pay on a Mac allows the use of credit cards the user has already enrolled and reduces user risk for credit card purchases.

Rationale:

Touch ID allows for an account-enrolled fingerprint to access a key that uses a previously provided password.

Some environments may have rules around purchases from organizationally managed computers and may want to discourage shopping from them. It is difficult to block access to websites that allow purchases, and Apple Pay has more controls for user protection than the manual entry of credit card information.

Impact:

Touch ID is more convenient for use with aggressive screen lock controls.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Graphical Method:
Perform the following steps to set Touch ID to your organization's settings:

Open System Settings

Select Touch ID & Password

Set the Touch ID settings to your organization's requirements

Select Wallet & Apple Pay

Set the Wallet & Apple Pay settings to your organization's requirements

See Also

https://workbench.cisecurity.org/files/4159