6.3.3 Ensure Warn When Visiting A Fraudulent Website in Safari Is Enabled

Information

Apple uses the Google Safe Browsing API to check for fraudulent websites and report them to the user attempting to visit one.

Rationale:

Attackers use crafted web pages to social engineer users to load unwanted content. Warning users prior to loading the content enables better security.

Impact:

Once-compromised websites serving malware could be sanitized and remain in the database, though there is no widespread reporting of that risk.

Solution

Profile Method:
Create or edit a configuration profile with the following information:

The PayloadType string is com.apple.Safari

The key to include is WarnAboutFraudulentWebsites

The key must be set to: <true/>

Note: Since the profile method sets a system-wide setting and not a user-level one, the profile method is the preferred method. It is always better to set system-wide than per user.

See Also

https://workbench.cisecurity.org/benchmarks/14562

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|CM-10, 800-53|SC-7(3), 800-53|SC-7(4), 800-53|SC-18, CSCv7|7.1, CSCv7|7.4

Plugin: Unix

Control ID: de4a7b5148c4902a00061850ad886be416112eaee6d9e912db91b0d645c90dae