STIGQter STIGQter: STIG Summary: Apple OS X 10.14 (Mojave) Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

The macOS system must authenticate all endpoint devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.

DISA Rule

SV-209633r610285_rule

Vulnerability Number

V-209633

Group Title

SRG-OS-000379-GPOS-00164

Rule Version

AOSX-14-004020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To disable a network device, run the following command:

/usr/bin/sudo /usr/sbin/networksetup -setnetworkserviceenabled Wi-Fi off

Check Contents

For systems where Wi-Fi is not approved for use, run the following command to disable the Wi-Fi service:

To list the network devices that are enabled on the system, run the following command:

/usr/bin/sudo /usr/sbin/networksetup -listallnetworkservices

If the Wi-Fi service name is not preceded by an asterisk(*), this is a finding.

Vulnerability Number

V-209633

Documentable

False

Rule Version

AOSX-14-004020

Severity Override Guidance

For systems where Wi-Fi is not approved for use, run the following command to disable the Wi-Fi service:

To list the network devices that are enabled on the system, run the following command:

/usr/bin/sudo /usr/sbin/networksetup -listallnetworkservices

If the Wi-Fi service name is not preceded by an asterisk(*), this is a finding.

Check Content Reference

M

Target Key

2930

Comments