Catalina - Disable Wi-Fi Interface

Information

The macOS system must be configured with Wi-Fi support software disabled if not connected to an authorized trusted network.

Allowing devices and users to connect to or from the system without first authenticating them allows untrusted access and can lead to a compromise or attack. Since wireless communications can be intercepted it is necessary to use encryption to protect the confidentiality of information in transit.Wireless technologies include for example microwave packet radio (UHF/VHF) 802.11x and Bluetooth. Wireless networks use authentication protocols (e.g. EAP/TLS PEAP) which provide credential protection and mutual authentication.

NOTE: If the system requires Wi-Fi to connect to an authorized network, this is not applicable.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To disable Wi-Fi on a macOS system, run the following command.
[source,bash]
----
/usr/sbin/networksetup -setnetworkserviceenabled "Wi-Fi" off
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-4, 800-53|AC-18, 800-53|AC-18(1), 800-53|AC-18(3), 800-53|IA-3(1), CCE|CCE-84938-0, CCI|CCI-001443, CCI|CCI-001444, CCI|CCI-001967, STIG-ID|AOSX-15-000008

Plugin: Unix

Control ID: 8595f843d359331e7c6695353e5b9522da7b96b5ab45cce37230d849fec89565