The macOS system must restrict the ability of individuals to write to external optical media.
An XCCDF Rule
Description
External writeable media devices must be disabled for users. External optical media devices can be used to exfiltrate sensitive data if an approved data-loss prevention (DLP) solution is not installed.
- ID
- SV-252539r816431_rule
- Version
- APPL-12-005053
- Severity
- Low
- References
- Updated
Remediation Templates
A Manual Procedure
This setting is enforced using the "Restrictions Policy" configuration profile.