AOSX-13-000140 - The macOS system must be configured to disable Apple File (AFP) Sharing.

Information

File Sharing is non-essential and must be disabled. Enabling any service increases the attack surface for an intruder. By disabling unnecessary services, the attack surface is minimized.

Solution

To disable the Apple File (AFP) Sharing service, run the following command:

/usr/bin/sudo /bin/launchctl disable system/com.apple.AppleFileServer

The system may need to be restarted for the update to take effect.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_OS_X_10-13_V2R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-214824r609363_rule, STIG-ID|AOSX-13-000140, STIG-Legacy|SV-96223, STIG-Legacy|V-81509, Vuln-ID|V-214824

Plugin: Unix

Control ID: 27d637735287cc8f072162d62fa848f9924d6d99f54a27f02dca2e01e48b46e4