2.6.1.2 Ensure all user storage APFS volumes are encrypted

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Apple developed a new file system that was first made available in 10.12 and then became the default in 10.13. The file system is optimized for Flash and Solid State storage and encryption.
https://en.wikipedia.org/wiki/Apple_File_System
macOS computers generally have several volumes created as part of APFS formatting including Preboot, Recovery and Virtual Memory (VM) as well as traditional user disks.

All APFS volumes that do not have specific roles that do not require encryption should be encrypted. 'Role' disks include Preboot, Recovery and VM. User disks are labelled with '(No specific role)' by default.

Rationale:

In order to protect user data from loss or tampering volumes carrying data should be encrypted

Solution

Use Disk Utility to erase a user disk and format as APFS (Encrypted)

Note: APFS Encrypted disks will be described as 'FileVault' whether they are the boot volume or not in the ap list

See Also

https://workbench.cisecurity.org/files/2105

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: f8c8c599795f5289fd3c894de5f49c921a6e69e40025d4341540bd2ea3df73d6