5.16 Secure individual keychain and items

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Each keychain entry can have different access controls. It's possible to set the keychain item to require a keychain password every time an item is accessed, even if the keychain is unlocked. This level of security could be useful for bank passwords or other passwords that need extra security.

NOTE : Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

1. Open Utilities
2. Select Keychain Access
3. Double-click keychain
4. Select Access Control
5. Check box next to 'Ask for Keychain Password'

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf