2.5.5 Ensure Sending Diagnostic and Usage Data to Apple Is Disabled

Information

Apple provides a mechanism to send diagnostic and analytics data back to Apple to help them improve the platform. Information sent to Apple may contain internal organizational information that should be controlled and not available for processing by Apple. Turn off all Analytics and Improvements sharing.

Share Mac Analytics (Share with App Developers dependent on Mac Analytic sharing)

Includes diagnostics, usage and location data

Share iCloud Analytics

Includes iCloud data and usage information

Share analytics information from your Mac with Apple

Rationale:

Organizations should have knowledge of what is shared with the vendor and the setting automatically forwards information to Apple.

Solution

Perform the following to disable diagnostic data being sent to Apple:
Graphical Method:

Open System Preferences

Select Security & Privacy

Select Privacy

Select Analytics & Improvements

Uncheck 'Share Mac Analytics'

Uncheck 'Share with App Developers'

Terminal Method:

$ sudo /usr/bin/defaults write /Library/Application Support/CrashReporter/DiagnosticMessagesHistory.plist AutoSubmit -bool false

$ sudo /bin/chmod 644 /Library/Application Support/CrashReporter/DiagnosticMessagesHistory.plist

$ sudo /usr/sbin/chgrp admin /Library/Application Support/CrashReporter/DiagnosticMessagesHistory.plist

Profile Method:

Create or edit a configuration profile with the PayLoadType of com.apple.applicationaccess

Add the key allowDiagnosticSubmission

Set the key to </false>

See Also

https://workbench.cisecurity.org/files/3569

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-1, 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1, CSCv7|9.2

Plugin: Unix

Control ID: c72e7dd22067aaa2fa952b183050dba36cca81d95816bcb23b2714747ead378c