APPL-13-005053 - The macOS system must restrict the ability of individuals to write to external optical media.

Information

External writeable media devices must be disabled for users. External optical media devices can be used to exfiltrate sensitive data if an approved data-loss prevention (DLP) solution is not installed.

Solution

Configure the macOS system to disable writing to external optical media devices by installing the 'Restrictions Policy' configuration profile.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Apple_macOS_13_V1R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-257245r905368_rule, STIG-ID|APPL-13-005053, Vuln-ID|V-257245

Plugin: Unix

Control ID: 87208ef8c9b0bba3d0d9661dd4ab0931947571d1146fe3a2bd7240f39feda4f0