2.4.2 Disable Internet Sharing

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Internet Sharing uses the open source 'natd' process to share an internet connection with other computers and devices on a local network. This allows the Mac to function as a router and share the connection to other, possibly unauthorized, devices.

Rationale:

Disabling Internet Sharing reduces the remote attack surface of the system.

Solution

Perform the following to implement the prescribed state:

1. Open System Preferences
2. Select Sharing
3. Uncheck Internet Sharing

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: ec741d64bc764a5bfe52dbb83423d48c67690dc4850f9ebadd6f3876c66d0075