2.5.1 Disable 'Wake for network access'

Information

This feature allows other users to be able to access your computers shared resources, such as shared printers or iTunes playlists, even when your computer is in sleep mode. In a closed network when only authorized devices could wake a computer it could be valuable to wake computers in order to do management push activity. Where mobile workstations and agents exist the device will more likely check in to receive updates when already awake. Mobile devices should not be listening for signals on unmanaged network where untrusted devices could send wake signals.

Rationale:

Disabling this feature mitigates the risk of an attacker remotely waking the system and gaining access.

Solution

Perform the following to implement the prescribed state:

Run the following command in Terminal:

sudo pmset -a womp 0

See Also

https://workbench.cisecurity.org/files/2112

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-11, CSCv6|3.1

Plugin: Unix

Control ID: 63a293f5684f203e145ab5797259be501f829ecc1a5aae9eb4f24edac98ed33c