2.4.2 Disable Internet Sharing

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Disabling Internet Sharing reduces the remote attack surface of the system.

Solution

Perform the following to implement the prescribed state:
Run the following commands in Terminal:
sudo /usr/bin/defaults write /Library/Preferences/SystemConfiguration/com.apple.nat NAT -dict Enabled -int 0
sudo /bin/launchctl unload -w /System/Library/LaunchDaemons/ com.apple.InternetSharing.plist

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.9_Benchmark_v1.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: c88e7a992663ecd49594c5d61e9370c4ca70083c7099021b10989d2c36d9f350