2.6.2.1 Audit Full Disk Access for Applications

Information

Starting with macOS 10.14 Mojave, Apple introduced Transparency, Consent, and Control (TCC) to enhance user privacy by requiring apps to get explicit permission before accessing sensitive data or system features.Full Disk Access (FDA) is a privacy category managed by the TCC (Transparency, Consent, and Control) framework. It controls whether applications can access certain protected areas of the file system, such as Mail, Messages, Safari data, and system logs.

Only applications from verified developers with a legitimate operational need-such as security monitoring or system management tools-should be granted Full Disk Access. The access and trust-worthiness of applications should be verified on a regular basis.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Graphical Method:

Perform the following steps to set full disk access for applications that meet your organization's requirements:

- Open System Settings
- Select Privacy & Security
- Select Full Disk Access
- Set any listed applications to your organization's requirements
- (Optional) Select the + to add applications to the list, or - to remove them

Impact:

Applications with Full Disk Access can access data from certain protected areas of the file system such as Mail, Messages, Safari data, and system logs.

See Also

https://workbench.cisecurity.org/benchmarks/23041

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1

Plugin: Unix

Control ID: 4839b1ff775b861ec619301f65df4f85d3896f190a5cdc576d48447c2b828a9d