The macOS system must be configured to disable iCloud Address Book services.
DISA Rule
SV-209579r610285_rule
Vulnerability Number
V-209579
Group Title
SRG-OS-000095-GPOS-00049
Rule Version
AOSX-14-002014
Severity
CAT III
CCI(s)
- CCI-000381 - The organization configures the information system to provide only essential capabilities.
- CCI-001774 - The organization employs a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the information system.
Weight
10
Fix Recommendation
This setting is enforced using the "Restrictions Policy" configuration profile.
Check Contents
/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep allowCloudAddressBook
If the result is not “allowCloudAddressBook = 0”, this is a finding.
Vulnerability Number
V-209579
Documentable
False
Rule Version
AOSX-14-002014
Severity Override Guidance
/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep allowCloudAddressBook
If the result is not “allowCloudAddressBook = 0”, this is a finding.
Check Content Reference
M
Target Key
2930
Comments