AOSX-10-000140 - Apple File (AFP) Sharing must be disabled.

Information

File Sharing is non-essential and must be disabled. Enabling any service increases the attack surface for an intruder. By disabling unnecessary services, the attack surface is minimized.

Solution

To disable the 'Apple File (AFP) Sharing' service, run the following command:

sudo launchctl disable system/com.apple.AppleFileServer

The system may need to be restarted for the update to take effect.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-10_Workstation_V1R5_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CCI|CCI-000381, Rule-ID|SV-73999r1_rule, STIG-ID|AOSX-10-000140, Vuln-ID|V-59569

Plugin: Unix

Control ID: aa01ae7dea38a8edf970fc0ad27488b128ae7d2fda975e4c41ec6236c5642e67