OSX00295 M6 - The guest account must be disabled - 'AuthenticationAuthority: ;basic;'

Information

The guest account is used to give a user temporary access to a computer. The guest account should be disabled by default because it does not require a password to login on the computer. If this account is enabled and is not securely configured malicious users can gain access to a computer without the use of a password.

Solution

1. Open System Preferences->Accounts Panel.
2. Click on Guest Account.
3. Deselect 'Allow guests to login to this computer'.

See Also

http://iase.disa.mil/stigs/os/mac/u_mac_osx_10.6_v1r3_stig_20130426.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, Rule-ID|SV-37218r1_rule, STIG-ID|OSX00295-M6, Vuln-ID|V-25299

Plugin: Unix

Control ID: 0f1ddd5bbfe2c2a95df3897e88425ec4cd560809e9fbd30d3223621460a1edfe