1.2 Ensure Auto Update Is Enabled

Information

Auto Update verifies that your system has the newest security patches and software updates. If "Automatically check for updates" is not selected, background updates for new malware definition files from Apple for XProtect and Gatekeeper will not occur.

It is important that a system has the newest updates applied so as to prevent unauthorized persons from exploiting identified vulnerabilities.

Solution

Graphical Method:

Perform the following steps to enable the system to automatically check for updates:

- Open System Settings
- Select General
- Select Software Update
- Select the i
- Set Check for updates to enabled
- Select Done

Terminal Method:

Run the following command to enable auto update:

$ /usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate AutomaticCheckEnabled -bool true

Profile Method:

Create or edit a configuration profile with the following information:

- The PayloadType string is com.apple.SoftwareUpdate
- The key to include is AutomaticCheckEnabled
- The key must be set to <true/>

Impact:

Without automatic update, updates may not be made in a timely manner and the system will be exposed to additional risk.

See Also

https://workbench.cisecurity.org/benchmarks/15550

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4, CSCv7|3.5

Plugin: Unix

Control ID: d6380e9e1fabf0a6c35e35a6d83b9bc2d4984692316138bf58b813bda0f748fe