Catalina - Enforce Apple Mobile File Integrity

Information

Apple Mobile File Integrity (AMFI) is a macOS kernel module that enforces the code-signing validation within Gatekeeper and library validation. AMFI checks the signatures of every app that is run.

NOTE: AMFI is enabled by default on macOS systems.

Solution

[source,bash]
----
/usr/sbin/nvram boot-args=""
----

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, 800-53|SI-7(1), CCE|CCE-84926-5

Plugin: Unix

Control ID: 57a08cd1894e46a5aaef60a84793bf2da6eee4d78ca28e9231a1617d2ef119c3