2.3.3.7 Ensure Remote Apple Events Is Disabled

Information

Apple Events is a technology that allows one program to communicate with other programs. Remote Apple Events allows a program on one computer to communicate with a program on a different computer.

Disabling Remote Apple Events mitigates the risk of an unauthorized program gaining access to the system.

Solution

Graphical Method:

Perform the following steps to disable Remote Apple Events:

- Open System Settings
- Select General
- Select Sharing
- Set Remote Apple Events to disabled

Terminal Method:

Run the following commands to set Remote Apple Events to Off:

% /usr/bin/sudo /usr/sbin/systemsetup -setremoteappleevents off

setremoteappleevents: Off

Impact:

With remote Apple events turned on, an AppleScript program running on another Mac can interact with the local computer.

See Also

https://workbench.cisecurity.org/benchmarks/18635

Item Details

Category: CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

References: 800-53|CM-2, 800-53|CM-6, 800-53|CM-7, 800-53|CM-7(1), 800-53|CM-9, 800-53|SA-3, 800-53|SA-8, 800-53|SA-10, CSCv7|5.1, CSCv7|9.2

Plugin: Unix

Control ID: 3553f691319ba6294be7702b2fa9c304ed39155ba9eb0edb3e75ef1524531b0a