2.6.2 Enable Gatekeeper

Information

Disallowing unsigned software will reduce the risk of unauthorized or malicious applications from running on the system.

Solution

Perform the following to implement the prescribed state:
Open System Preferences
Select Security & Privacy
Select General
Select Allow applications downloaded from: Mac App Store and identified developers
Alternatively, perform the following to ensure the system is configured as:
Run the following command in Terminal:
sudo /usr/sbin/spctl --master-enable

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.9_Benchmark_v1.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7

Plugin: Unix

Control ID: f3074949228f1de4023a1d63d84d069a7fe22ca4ee8a7e958b36a93945c75361