STIGQter STIGQter: STIG Summary: Apple OS X 10.15 (Catalina) Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 23 Apr 2021:

The macOS system must disable iCloud photo library.

DISA Rule

SV-225192r610901_rule

Vulnerability Number

V-225192

Group Title

SRG-OS-000095-GPOS-00049

Rule Version

AOSX-15-002043

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This setting is enforced using the "Restrictions Policy" configuration profile.

Check Contents

Verify that iCloud has been disabled:

/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep -A 6 DisabledPreferencePanes | grep AppleIDPrefPane

If the return is not “com.apple.preferences.AppleIDPrefPane”, this is a CAT I finding.

To view the setting for the iCloud Photo Library configuration, run the following command:

/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep allowCloudPhotoLibrary

If the output is null or not "allowCloudPhotoLibrary = 0", this is a finding.

Vulnerability Number

V-225192

Documentable

False

Rule Version

AOSX-15-002043

Severity Override Guidance

Verify that iCloud has been disabled:

/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep -A 6 DisabledPreferencePanes | grep AppleIDPrefPane

If the return is not “com.apple.preferences.AppleIDPrefPane”, this is a CAT I finding.

To view the setting for the iCloud Photo Library configuration, run the following command:

/usr/sbin/system_profiler SPConfigurationProfileDataType | /usr/bin/grep allowCloudPhotoLibrary

If the output is null or not "allowCloudPhotoLibrary = 0", this is a finding.

Check Content Reference

M

Target Key

4212

Comments