Information
The macOS should be configured to require users to reauthenticate when the device authenticator is changed.
Without reauthentication, users may access resources or perform tasks for which they are not authorization. When operating systems provide the capability to change device authenticators, it is critical the device reauthenticate.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
This requirement is a permanent finding and cannot be fixed. An appropriate mitigation for the system must be implemented, but this finding cannot be considered fixed.