UCF STIG Viewer Logo

The macOS system must be configured with Bluetooth turned off unless approved by the organization.


Overview

Finding ID Version Rule ID IA Controls Severity
V-214812 AOSX-13-000065 SV-214812r609363_rule Low
Description
The Bluetooth kernel extension must be disabled, as wireless access introduces unnecessary security risks. Disabling Bluetooth support with a configuration profile mitigates this risk.
STIG Date
Apple OS X 10.13 Security Technical Implementation Guide 2021-11-19

Details

Check Text ( C-16012r397008_chk )
If Bluetooth connectivity is required to facilitate use of approved external devices, this is not applicable.

To check if Bluetooth is disabled, run the following command:

/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep DisableBluetooth

If the return is null or is not "DisableBluetooth = 1", this is a finding.
Fix Text (F-16010r397009_fix)
This setting is enforced using the "Bluetooth Policy" configuration profile.