2.6.5 Review Application Firewall Rules

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

A firewall minimizes the threat of unauthorized users from gaining access to your system while connected to a network or the Internet. Which applications are allowed access to accept incoming connections through the firewall is important to understand.

Solution

Perform the following to implement the prescribed state:
1. Open System Preferences
2. Select Security & Privacy
3. Select Firewall Options
4. Select unneeded rules
5. Select the minus sign below to delete them

Alternatively:
1. Edit and run the following command in Terminal to remove specific applications:
/usr/libexec/ApplicationFirewall/socketfilterfw --remove </Applications/badapp.app>
2. Where </Applications/badapp.app> is the one to be removed

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CSCv6|9.2

Plugin: Unix

Control ID: bb0e28bc60c50223638d2ef802b21166a3f99eea26c8201977a57068d13804f6