2.6.5 Review Application Firewall Rules

Information

A firewall minimizes the threat of unauthorized users from gaining access to your system while connected to a network or the Internet. Which applications are allowed access to accept incoming connections through the firewall is important to understand.

Solution

Perform the following to implement the prescribed state: Open System Preferences Select Security & Privacy Select Firewall Options Select unneeded rules Select the minus sign below to delete them Alternatively: Edit and run the following command in Terminal to remove specific applications: /usr/libexec/ApplicationFirewall/socketfilterfw --remove </Applications/badapp.app> Where </Applications/badapp.app> is the one to be removed

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.10_Benchmark_v1.1.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CSCv6|9.2

Plugin: Unix

Control ID: 1dffdbe480a4b82019fff3d30f8035745ef49608a92f38723c562fba063991d4