The macOS system must have the security assessment policy subsystem enabled.

STIG ID: APPL-13-002064  |  SRG: SRG-OS-000366-GPOS-00153 |  Severity: high |  CCI: CCI-001749 |  Vulnerability Id: V-257220

Vulnerability Discussion

Any changes to the hardware, software, and/or firmware components of the information system and/or application can potentially have significant effects on the overall security of the system.

Accordingly, software defined by the organization as critical must be signed with a certificate that is recognized and approved by the organization.

Check

Verify the macOS system is configured with the security assessment policy subsystem enabled with the following command:

/usr/sbin/spctl --status

assessments enabled

If "assessments enabled" is not returned, this is a finding.

Fix

Configure the macOS system to enable the security assessment policy subsystem by installing the "Custom Policy" configuration profile.