APPL-13-005051 - The macOS system must restrict the ability of individuals to use USB storage devices.

Information

External writeable media devices must be disabled for users. External USB devices are a potential vector for malware and can be used to exfiltrate sensitive data if an approved data-loss prevention (DLP) solution is not installed.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure the macOS system to disable USB storage devices by installing the 'Restrictions Policy' configuration profile.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_13_V1R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-257243r991589_rule, STIG-ID|APPL-13-005051, Vuln-ID|V-257243

Plugin: Unix

Control ID: 100356743a36f4bfa40fcc30a5bb2b7f50f364d93d3d73f7b4bb2dcfa385bcdc