2.6.2 Enable Gatekeeper

Information

Disallowing unsigned software will reduce the risk of unauthorized or malicious applications from running on the system.

Solution

Perform the following to implement the prescribed state:
1. Open System Preferences
2. Select Security & Privacy
3. Select General
4. Select Allow applications downloaded from: Mac App Store and identified developers
Alternatively, perform the following to ensure the system is configured as:
1. Run the following command in Terminal:
sudo spctl --master-enable

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: f3685fcb9a50ed647338d275bb16a73c3f343fde1909f3d3bf897399e5988e8d