5.3.2 Ensure all user storage CoreStorage volumes are encrypted

Information

Apple introduced CoreStorage with Mac OS X 10.7 Lion. It is used as the default for formatting on macOS volumes prior to macOS 10.13 High Sierra.

All HFS and CoreStorage Volumes should be encrypted.

CoreStorage has been deprecated and replaced with APFS for volume encryption.

In order to protect user data from loss or tampering, volumes carrying data should be encrypted.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Use Disk Utility to erase a disk and format as macOS Extended (Journaled, Encrypted).

Impact:

While FileVault protects the boot volume, data may be copied to other attached storage and reduce the protection afforded by FileVault. Ensure all user volumes are encrypted to protect data.

See Also

https://workbench.cisecurity.org/benchmarks/23042

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, MEDIA PROTECTION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|MP-5, 800-53|MP-7, 800-53|SC-28, 800-53|SC-28(1), CSCv7|13.6, CSCv7|14.8

Plugin: Unix

Control ID: 63c6a846adee4f531ea216b35def3d61fb5f04225891e1a5e76b362f6518b739