Monterey - Enable Recovery Lock

Information

A recovery lock password _MUST_ be enabled and set.

Single user mode, recovery mode, the Startup Manager, and several other tools are available on macOS by holding down specific key combinations during startup. Setting a recovery lock restricts access to these tools.

NOTE: Recovery lock passwords are not supported on Intel devices. This rule is only applicable to Apple Silicon devices.

Solution

NOTE: The SetRecoveryLock command can be used to set a Recovery Lock password.

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CCE|CCE-90989-5

Plugin: Unix

Control ID: 9f86f0e0ec291e127b8b9fb729b2ba1d19d3f1326cdaeb8c18584f7ca1e0c8a2