AOSX-11-000710 - The system must allow only applications downloaded from the App Store to run. - EnableAssessment

Information

Gatekeeper settings must be configured correctly to only allow the system to run applications downloaded from the Mac App Store or applications signed with a valid Apple Developer ID code. Administrator users will still have the option to override these settings on a per app basis. Gatekeeper is a security feature that ensures that applications must be digitally signed by an Apple issued certificate in order to run. Digital signatures allow the OS X to verify that the application has not been modified by a malicious third-party.

Solution

This setting is enforced using the "Security Privacy Policy" configuration profile.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-11_V1R6_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(5), CAT|II, CCI|CCI-001749, Rule-ID|SV-82107r2_rule, STIG-ID|AOSX-11-000710, Vuln-ID|V-67617

Plugin: Unix

Control ID: 409fc3e1db0a24150e3fdd15952dca33c06e3da664d2a2e04f04656e3befd67f