The macOS system must ensure Secure Boot level is set to "full".
DISA Rule
SV-268568r1034644_rule
Vulnerability Number
V-268568
Group Title
SRG-OS-000445-GPOS-00199
Rule Version
APPL-15-005100
Severity
CAT II
CCI(s)
- CCI-002696 - Verify correct operation of organization-defined security functions.
- CCI-002699 - Perform verification of the correct operation of organization-defined security functions: when the system is in an organization-defined transitional state; upon command by a user with appropriate privileges; and/or on an organization-defined frequency.
- CCI-002702 - Shut the system down, restart the system, and/or initiate organization-defined alternative action(s) when anomalies in the operation of the organization-defined security functions are discovered.
Weight
10
Fix Recommendation
Configure the macOS system to ensure Secure Boot level is set to "full" by booting into Recovery Mode and enabling Full Secure Boot.
Check Contents
Verify the macOS system is configured to ensure Secure Boot level is set to "full" using the following command:
/usr/libexec/mdmclient QuerySecurityInfo | /usr/bin/grep -c "SecureBootLevel = full"
If the result is not "1", this is a finding.
Vulnerability Number
V-268568
Documentable
False
Rule Version
APPL-15-005100
Severity Override Guidance
Verify the macOS system is configured to ensure Secure Boot level is set to "full" using the following command:
/usr/libexec/mdmclient QuerySecurityInfo | /usr/bin/grep -c "SecureBootLevel = full"
If the result is not "1", this is a finding.
Check Content Reference
M
Target Key
5661