1.3 Ensure Download New Updates When Available Is Enabled

Information

In the GUI, both "Install macOS updates" and "Install app updates from the App Store" are dependent on whether "Download new updates when available" is selected.

It is important that a system has the newest updates downloaded so that they can be applied.

Solution

Perform the following to enable the system to automatically check for updates:

Graphical Method:

- Open System Settings
- Select General
- Select Software Update
- Select the i
- Set Download new updates when available to enabled
- Select Done

Terminal Method:

Run the following command to enable auto update:

$ /usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate AutomaticDownload -bool true

Profile Method:

Create or edit a configuration profile with the following information:

- The PayloadType string is com.apple.SoftwareUpdate
- The key to include is AutomaticDownload
- The key must be set to <true/>

Impact:

If "Download new updates when available" is not selected, updates may not be made in a timely manner and the system will be exposed to additional risk.

See Also

https://workbench.cisecurity.org/benchmarks/15550

Item Details

Category: RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|RA-5, 800-53|SI-2, 800-53|SI-2(2), CSCv7|3.4, CSCv7|3.5

Plugin: Unix

Control ID: 5c716125a4cff53d57f8cbeccc6575c1a51586abacf66fb5a19a8f9bf1d27832