Big Sur - Configure the System to Protect Memory from Unauthorized Code Execution

Information

The information system _IS_ configured to implement non-executable data to protect memory from code execution.

Some adversaries launch attacks with the intent of executing code in non-executable regions of memory or in memory locations that are prohibited (e.g., buffer overflow attacks). Security safeguards (e.g., data execution prevention and address space layout randomization) can be employed to protect non-executable regions of memory. Data execution prevention safeguards can either be hardware-enforced or software-enforced; hardware-enforced methods provide the greater strength of mechanism.

macOS supports address space layout randomization (ASLR), position-independent executable (PIE), Stack Canaries, and NX stack and heap protection.

link:https://developer.apple.com/library/archive/documentation/Darwin/Conceptual/64bitPorting/transition/transition.html[]

link:https://developer.apple.com/library/archive/qa/qa1788/_index.html[]

link:https://www.apple.com/macos/security/[]

Solution

The technology inherently meets this requirement. No fix is required.

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CCE|CCE-85327-5, CCI|CCI-002824

Plugin: Unix

Control ID: e4b97bea625f5c2e687263763bd994093a349ef7f8dca01b60727aa47868617c