5.16 Secure individual keychain and items

Information

Each keychain entry can have different access controls. It's possible to set the keychain item to require a keychain password every time an item is accessed, even if the keychain is unlocked. This level of security could be useful for bank passwords or other passwords that need extra security.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. Open Utilities
2. Select Keychain Access
3. Double-click keychain
4. Select Access Control
5. Check box next to 'Ask for Keychain Password'

See Also

https://workbench.cisecurity.org/files/300

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)

Plugin: Unix

Control ID: 5d47c1c2b75091bbeff46b470e9f16e7ea3ea2ed87b2744027441d657c596843