Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-51537 | OSX8-00-00705 | SV-65747r1_rule | Medium |
Description |
---|
The operating system must enforce software installation by users based upon what types of software installations are permitted (e.g., updates and security patches to existing software) and what types of installations are prohibited (e.g., software whose pedigree with regard to being potentially malicious is unknown or suspect) by the organization. |
STIG | Date |
---|---|
Apple OS X 10.8 (Mountain Lion) Workstation STIG | 2015-02-10 |
Check Text ( C-53869r1_chk ) |
---|
To check if there is a configuration policy defined for Application Restrictions, run the following command: sudo profiles -Pv | grep "Application Restrictions" If nothing is returned, this is a finding. |
Fix Text (F-56341r1_fix) |
---|
A configuration profile should exist to restrict launching of applications. |