2.6.1.3 Ensure all user storage CoreStorage volumes are encrypted

Information

Apple introduced Core Storage with 10.7. It is used as the default for formatting on macOS volumes prior to 10.13.

All HFS and Core Storage Volumes should be encrypted

Rationale:

In order to protect user data from loss or tampering volumes carrying data should be encrypted

Solution

Use Disk Utility to erase a disk and format as macOS Extended (Journaled, Encrypted)

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: 3b2925ab3ac9254d1b8d60c3fe21543596210f76994aace557a2238341d70190