5.9 Ensure Legacy EFI Is Valid and Updating

Information

In order to mitigate firmware attacks, Apple has created an automated Firmware check to ensure that the EFI version running is a known good version from Apple. There is also an automated process to check it every seven days.

This check is only valid on T1 chips and prior. Neither T2 chips nor Apple silicon require this control check

If the Firmware of a computer has been compromised, the Operating System that the Firmware loads cannot be trusted, either.

Solution

If EFI does not pass the integrity check, you may send a report to Apple. Backing up files and clean installing a known good Operating System and Firmware is recommended.

See Also

https://workbench.cisecurity.org/benchmarks/15551

Item Details

Category: SYSTEM AND SERVICES ACQUISITION

References: 800-53|SA-22, CSCv7|2.2

Plugin: Unix

Control ID: f943b993695b512cb4bc655f7ef6f60bcfaee0f2bff4bd0914ca21b65f354c7a