Catalina - Enforce Apple Mobile File Integrity

Information

Apple Mobile File Integrity (AMFI) is a macOS kernel module that enforces the code-signing validation within Gatekeeper and library validation. AMFI checks the signatures of every app that is run.

NOTE: AMFI is enabled by default on macOS systems.

Solution

[source,bash]
----
/usr/sbin/nvram boot-args=""
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, 800-53|SI-7(1), CCE|CCE-84926-5

Plugin: Unix

Control ID: 15e4fd3504db11a5de271c30c92d85e9480add2e4fb0a0fd802445c69f898c26