AOSX-10-000140 - Apple File (AFP) Sharing must be disabled.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

File Sharing is non-essential and must be disabled. Enabling any service increases the attack surface for an intruder. By disabling unnecessary services, the attack surface is minimized.

Solution

To disable the 'Apple File (AFP) Sharing' service, run the following command:

sudo launchctl disable system/com.apple.AppleFileServer

The system may need to be restarted for the update to take effect.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-10_Workstation_V1R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, Rule-ID|SV-73999r1_rule, STIG-ID|AOSX-10-000140, Vuln-ID|V-59569

Plugin: Unix

Control ID: aa01ae7dea38a8edf970fc0ad27488b128ae7d2fda975e4c41ec6236c5642e67