AOSX-09-000786 - System must implement cryptographic mechanisms to prevent unauthorized modification of all information at rest.

Information

FileVault Disk Encryption must be enabled. This ensures that any data stored on the hard drive will be protected by cryptographic means when the system is powered off, mitigating the risk of unauthorized disclosure of that data. Selection of a cryptographic mechanism is based on the need to protect the integrity of organizational information. The strength of the mechanism is commensurate with the security category and/or classification of the information. Organizations have the flexibility to either encrypt all information on storage devices (i.e., full disk encryption) or encrypt specific data structures (e.g., files, records, or fields).

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Open System Preferences->Security & Privacy, and navigate to the FileVault tab. Use this panel to configure full-disk encryption.

Alternately, from the command line, run the following command to enable FileVault:

sudo fdesetup enable

After FileVault is initially set up, additional users can be added.

See Also

http://iasecontent.disa.mil/stigs/zip/U_Apple_OS_X_10-9_Workstation_V1R2_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-28(1), CAT|II, CCI|CCI-002476, CSCv6|13.2, Group-ID|V-58393, Rule-ID|SV-72823r1_rule, STIG-ID|AOSX-09-000786

Plugin: Unix

Control ID: 08232342a8359f562b50089b91bbff020f5aa7b2474968e49a554116698614fa