1.5 Enable macOS update installs

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Ensure that macOS updates are installed after they are available from Apple. This setting enables macOS updates to be automatically installed. Some environments will want to approve and test updates before they are delivered. It is best practice to test first where updates can and have caused disruptions to operations. Automatic updates should be turned off where changes are tightly controlled and there are mature testing and approval processes. Automatic updates should not be turned off so the admin can call the users first to let them know it's ok to install. A dependable repeatable process involving a patch agent or remote management tool should be in place before auto-updates are turned off.

Rationale:

Patches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited

Solution

Perform the following to implement the prescribed state:

1. Open a terminal session and enter the following command to enable install system data files and security updates:

sudo defaults write /Library/Preferences/com.apple.commerce AutoUpdateRestartRequired -bool TRUE

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-2(5)

Plugin: Unix

Control ID: c1a62dd28560d2f7f6391a070e7a94bd137058d141da0aacee16a59985db6613