1.5 Ensure System Data Files and Security Updates Are Downloaded Automatically Is Enabled

Information

Ensure that system and security updates are installed after they are available from Apple. This setting enables definition updates for XProtect and Gatekeeper. With this setting in place, new malware and adware that Apple has added to the list of malware or untrusted software will not execute. These updates do not require reboots or end user admin rights.

Silently updated security data files in Monterey

https://support.apple.com/en-us/HT202491

XProtect is Apple's built-in, signature-based security tool for detection and removal of malware.

Protecting against malware in macOS

Patches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited.

Solution

Run the following commands to enable automatic checking of system data files and security updates:

% /usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate ConfigDataInstall -bool true

% /usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate CriticalUpdateInstall -bool true

Impact:

Unpatched software may be exploited.

See Also

https://workbench.cisecurity.org/benchmarks/17467

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|RA-5(2), 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4, CSCv7|3.5

Plugin: Unix

Control ID: dfe8e3a14d1a3cd4071e394f798280a6660b56ab1df27aea74e55715d3345a80