The OS X system must have the security assessment policy subsystem enabled.

From Apple OS X 10.12 Security Technical Implementation Guide

Part of SRG-OS-000366-GPOS-00153

Associated with: CCI-001749

SV-90723r1_rule The OS X system must have the security assessment policy subsystem enabled.

Vulnerability discussion

Any changes to the hardware, software, and/or firmware components of the information system and/or application can potentially have significant effects on the overall security of the system.Accordingly, software defined by the organization as critical must be signed with a certificate that is recognized and approved by the organization.

Check content

To check the status of the Security assessment policy subsystem, run the following command: /usr/bin/sudo /usr/sbin/spctl --status | /usr/bin/grep enabled If nothing is returned, this is a finding.

Fix text

To enable the Security assessment policy subsystem, run the following command: /usr/bin/sudo /usr/sbin/spctl --master-enable

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer