CCI-000060 in U Apple macOS 14 V2R2

ℹ️ The items you can view are limited because you do not have a subscription. Contact us at [email protected] to purchase one.

UNCLASSIFIED
Group Title
SRG-OS-000031-GPOS-00012
Group ID
V-259422
Rule Version
APPL-14-000007
Rule Title
The macOS system must disable hot corners.
Rule ID
SV-259422r958404_rule
Rule Severity
Medium
Rule Weight
10.0
Vuln Discussion

Hot corners must be disabled.

The information system conceals, via the session lock, information previously visible on the display with a publicly viewable image. Although hot corners can be used to initiate a session lock or to launch useful applications, they can also be configured to disable an automatic session lock from initiating. Such a configuration introduces the risk that a user might forget to manually lock the screen before stepping away from the computer.

Documentable
False
Check Content

Verify the macOS system is configured to disable hot corners with the following command:

/usr/bin/profiles -P -o stdout | /usr/bin/grep -Ec '"wvous-bl-corner" = 0|"wvous-br-corner" = 0|"wvous-tl-corner" = 0|"wvous-tr-corner" = 0'

If the result is not "4", this is a finding.

Check System
C-63161r940886_chk
Fix Reference
F-63069r940887_fix
Fix Text

Configure the macOS system to disable hot corners by installing the "com.apple.ManagedClient.preferences" configuration profile.

Identities
CCI-000060

Conceal, via the device lock, information previously visible on the display with a publicly viewable image.

  • 800-53 :: AC-11 (1)
  • 800-53 Rev. 4 :: AC-11 (1)
  • 800-53 Rev. 5 :: AC-11 (1)
  • 800-53A :: AC-11 (1).1
UNCLASSIFIED