2.4.4 Ensure Gatekeeper Is Enabled

Information

Gatekeeper is Apple's application that utilizes allowlisting to restrict downloaded applications from launching. It functions as a control to limit applications from unverified sources from running without authorization.

Disallowing unsigned software will reduce the risk of unauthorized or malicious applications from running on the system.

Solution

Run the following command to enable Gatekeeper to allow applications from App Store and identified developers:

% /usr/bin/sudo /usr/sbin/spctl --master-enable

See Also

https://workbench.cisecurity.org/benchmarks/17467

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, 800-53|SI-16, CSCv7|8.2, CSCv7|8.4

Plugin: Unix

Control ID: 525b386ed2de1c92712ae69f7fe2f663715dc3780d91ff0a47700161c351a41b