5.3.3 Audit Connected FAT32 and ExFAT Drives

Information

While FAT32 and exFAT offer cross-platform convenience, they introduce critical security gaps. These formats do not support encryption without third-party products (on any platform). Consequently, FAT32 and exFAT should be reserved strictly for temporary, non-sensitive data transfers, while any sustained use or sensitive data storage should utilize APFS (Encrypted).

Note: While the recommendation for FAT32 and ExFAT drives is not automated, we have included a script check within CIS-CAT if your organization does want to not allow either format to be used and does not have an existing solution.

Prohibiting FAT32 and exFAT devices centers on the total absence of native access controls and data-at-rest protection. Unlike APFS or HFS+, which allow for granular folder restrictions, FAT32 and exFAT operate with an effective "777" permission state, granting every user and process on a system full read, write, and delete privileges without requiring administrative escalation. This creates a significant vulnerability where malicious processes can compromise data silently.

Furthermore these drives lack volume-level encryption. If a device is lost or stolen, it constitutes an immediate and total data breach, as the contents are accessible to any person on any device. While third-party encryption containers can be used as a workaround, they introduce unnecessary operational complexity and a higher risk of file system corruption compared to native macOS security solutions. Lastly, it is likely that FAT32 and ExFAT drives are not subject to any organizational management controls.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Any connected FAT32 or ExFAT volumes need to be audited to verify that they meet your organization's existing device policies for external drives.

Note: Removable storage is generally formatted in FAT32 or ExFAT. Those drives generally are used by additional non-Apple devices and are outside the scope of the benchmark. If your organization has a use for those devices, removable storage should only be connected when importing data to your Apple device. After import, those drive(s) should be immediately ejected and then disconnected from the computer.

Impact:

If FAT32 and exFAT drives are disabled, users may experience a temporary disruption in their ability to easily share large files with non-macOS systems, such as Windows or Linux machines. However, this shift effectively eliminates the risk of accidental data exposure by ensuring all external storage adheres to the organization's mandatory encryption and access control standards.

See Also

https://workbench.cisecurity.org/benchmarks/24637

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5(1), 800-53|SC-28, 800-53|SC-28(1), CSCv7|13.6, CSCv7|14.8

Plugin: Unix

Control ID: 38f42d4b85060120cd53735384939832d591e62231157d6d9ea1298f67a967c9