5.22 Create specialized keychains for different purposes

Information

The keychain is a secure database store for passwords and certificates and is created for each user account on macOS. The system software itself uses keychains for secure storage. Users can create more than one keychain to protect various passwords separately.

Rationale:

If the user can logically split password and other entries into different keychains with different passwords, a compromise of one password will have limited effect.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

1. Open 'Utilities'
2. Select 'Keychain Access'
3. Select 'File'
4. Select 'New Keychain'
5. Input name of new keychain next to 'Save As'
6. Select 'Create'
7. Drag and drop desired keychain items into new keychain from login keychain

See Also

https://workbench.cisecurity.org/files/2105