2.5.1.1 Ensure FileVault Is Enabled

Information

FileVault secures a system's data by automatically encrypting its boot volume and requiring a password or recovery key to access it.

FileVault should be used with a saved escrow key to ensure that the owner can decrypt their data if the password is lost.

FileVault may also be enabled using command line using the fdesetup command. To use this functionality, consult the Der Flounder blog for more details (see link below under References).

Rationale:

Encrypting sensitive data minimizes the likelihood of unauthorized users gaining access to it.

Impact:

Mounting a FileVault encrypted volume from an alternate boot source will require a valid password to decrypt it.

Solution

Perform the following to enable FileVault:
Graphical Method:

Open System Preferences

Select Security & Privacy

Select FileVault

Select Turn on FileVault

Profile Method:

Create or edit a configuration profile with the PayLoadType of com.apple.MCX

Add the key dontAllowFDEDisable

Set the key to <true/>

Note: This profile is required to pass the audit.

See Also

https://workbench.cisecurity.org/files/4000