Information
System Integrity Protection (SIP) _MUST_ be enabled.
SIP is vital to protecting the integrity of the system as it prevents malicious users and software from making unauthorized and/or unintended modifications to protected files and folders; ensures the presence of an audit record generation capability for defined auditable events for all operating system components; protects audit tools from unauthorized access, modification, and deletion; restricts the root user account and limits the actions that the root user can perform on protected parts of the macOS; and prevents non-privileged users from granting other users direct access to the contents of their home directories and folders.
NOTE: SIP is enabled by default in macOS.
Solution
[source,bash]
----
/usr/bin/csrutil enable
----
NOTE: To reenable "System Integrity Protection", boot the affected system into "Recovery" mode, launch "Terminal" from the "Utilities" menu, and run the command.
Item Details
Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY
References: 800-53|AC-3, 800-53|AU-6(4), 800-53|AU-7, 800-53|AU-7(1), 800-53|AU-7a., 800-53|AU-7b., 800-53|AU-9, 800-53|AU-9(3), 800-53|AU-12a., 800-53|CM-5, 800-53|CM-5(6), 800-53|SC-4, 800-53|SI-2, 800-53|SI-7, CCE|CCE-91000-0, CCI|CCI-000154, CCI|CCI-000158, CCI|CCI-000169, CCI|CCI-001493, CCI|CCI-001494, CCI|CCI-001495, CCI|CCI-001499, CCI|CCI-001875, CCI|CCI-001876, CCI|CCI-001877, CCI|CCI-001878, CCI|CCI-001879, CCI|CCI-001880, CCI|CCI-001881, CCI|CCI-001882
Control ID: b7fb44d0d6edbf30c9795684602da5269d3644edc695236dd1a5b5283eae9166