2.6.2 Enable Gatekeeper

Information

Disallowing unsigned software will reduce the risk of unauthorized or malicious applications from running on the system.

Solution

Perform the following to implement the prescribed state:
Open System Preferences
Select Security & Privacy
Select General
Select Allow applications downloaded from: Mac App Store and identified developers
Alternatively, perform the following to ensure the system is configured as:
Run the following command in Terminal:
sudo /usr/sbin/spctl --master-enable

See Also

https://workbench.cisecurity.org/files/300

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4)

Plugin: Unix

Control ID: 90a219d52b71610d7930950c1fec4b66787710c99079af6b7ec77476159c8827