5.18 System Integrity Protection status

Information

Running with System Integrity Protection on a production system runs the risk of modification system binaries or code injection of system processes that would otherwise be protected by SIP.

Solution

Perform the following while booted in OS X Recovery Partition.
1. Select Terminal from the Utilities menu

2. Run the following command in Terminal:
/usr/bin/csrutil enable

3. The output should be:
Successfully enabled System Integrity Protection. Please restart the machine for the changes to take effect.

4. Reboot.

If a change is to the status is attempted from the booted Operating System rather than the recovery partition an error will be generated.
csrutil: failed to modify system integrity configuration. This tool needs to be executed from the Recovery OS.

See Also

https://workbench.cisecurity.org/files/301

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-7(1)

Plugin: Unix

Control ID: b95dc4cb607fdc3615c0d5bea4537c3614ac3be845f1e4896d4cb5816db14618