7.2.4 Ensure Warn When Visiting A Fradulent Website in Safari Is Enabled

Information

Apple uses the Google Safe Browsing API to check for fraudulent websites and report them to the user attempting visit one.

Rationale:

Attackers use crafted web pages to social engineer users to load unwanted content. Warning users prior to loading the content enables better security.

Impact:

Once-compromised websites serving malware could be sanitized and remain in the database, though there is no widespread reporting of that risk.

Solution

Profile Method:
Create or edit a configuration profile with the following information:

The PayloadType string is com.apple.Safari

The key to include is WarnAboutFraudulentWebsites

The key must be set to: <true/>

See Also

https://workbench.cisecurity.org/benchmarks/11683