1.4 Ensure Installation of App Update Is Enabled

Information

Ensure that application updates are installed after they are available from Apple. These updates do not require reboots or administrator privileges for end users.

Rationale:

Patches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited.

Impact:

Unpatched software may be exploited.

Solution

Graphical Method:
Perform the following steps to enable App Store updates to install automatically:

Open System Preferences

Select Software Updates

Select Advanced

Set Install app updates from the App Store to enabled

Terminal Method:
Run the following command to to enable automatic checking and installing of macOS updates:

$ /usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.commerce AutoUpdate -bool TRUE

Profile Method:
Create or edit a configuration profile with the following information:

The PayloadType string is com.apple.SoftwareUpdate

The key to include is AutomaticallyInstallAppUpdates

The key must be set to <true/>

See Also

https://workbench.cisecurity.org/benchmarks/14563

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4, CSCv7|3.5

Plugin: Unix

Control ID: 1fb25a75bfa8c7c7bc29c822ea651775753dd8c4a28cebd6dbd7963c98cd98f3