Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 6 checks on this page
- Ensure Apple-Provided Software Updates Are Installed
- Ensure Download New Updates When Available Is Enabled
- Ensure Install Application Updates From the App Store Is Enabled
- Ensure Install of macOS Updates Is Enabled
- Ensure Install Security Responses and System Files Is Enabled
- Ensure Software Update Deferment Is 30 Days or Less
Ensure Apple-Provided Software Updates Are Installed
Finding: Apple software updates are pending installation.
Checks whether any Apple-provided software updates are waiting to be installed.
This rule fails when recommendedUpdates is non-empty (updates are available but not installed).
Rationale: Unapplied security patches leave known vulnerabilities open to exploitation.
Impact: Installing updates can be disruptive and some require a restart; schedule during downtime.
Remediation
Open System Settings > General > Software Update and select Update All to install all available updates.
From the command line:
/usr/bin/sudo /usr/sbin/softwareupdate -i -a
- Framework mappings
- CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Download New Updates When Available Is Enabled
Finding: Automatic download of updates is disabled.
Checks whether macOS automatically downloads updates when they become available.
This rule fails when automaticDownload is not true.
Rationale: Updates must be downloaded before they can be applied in a timely manner.
Remediation
Open System Settings > General > Software Update, select the info button, and turn on Download new updates when available.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate AutomaticDownload -bool true
- Framework mappings
- CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Install Application Updates From the App Store Is Enabled
Finding: Automatic App Store application updates are disabled.
Checks whether App Store application updates install automatically.
This rule fails when installUpdatesFromAppStore is not true.
Rationale: Application patches must be applied promptly to reduce exploitation risk.
Remediation
Open System Settings > General > Software Update, select the info button, and turn on Install application updates from the App Store.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.commerce AutoUpdate -bool true
- Framework mappings
- CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Install of macOS Updates Is Enabled
Finding: Automatic installation of macOS updates is disabled.
Checks whether macOS updates are configured to install automatically.
This rule fails when automaticallyInstallMacOSUpdates is not true.
Rationale: Patches must be applied promptly to reduce the window of exploitation.
Remediation
Open System Settings > General > Software Update, select the info button, and turn on Install macOS updates.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate AutomaticallyInstallMacOSUpdates -bool true
- Framework mappings
- CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Install Security Responses and System Files Is Enabled
Finding: Automatic security responses and system file updates are disabled.
Checks whether Rapid Security Responses and system data files (including XProtect and Gatekeeper definitions) install automatically.
This rule fails when installSRAndSS is not true.
Rationale: Rapid definition updates block newly identified malware without waiting for a full update.
Remediation
Open System Settings > General > Software Update, select the info button, and turn on Install Security Responses and System files.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate ConfigDataInstall -bool true
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.SoftwareUpdate CriticalUpdateInstall -bool true
- Framework mappings
- CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management; 7.7 Remediate Detected Vulnerabilities
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- NIST SP 800-171 Rev. 2: 3.11.3 Remediate vulnerabilities in accordance with risk assessments; 3.14.1 Identify, report, and correct system flaws in a timely manner
- CMMC 2.0 Level 1: SI.L1-b.1.xii Identify, report, and correct information and information system flaws in a timely manner
- CMMC 2.0 Level 2: RA.L2-3.11.3 Remediate vulnerabilities in accordance with risk assessments; SI.L2-3.14.1 Identify, report, and correct system flaws in a timely manner
- PCI DSS v4.0.1: 11.3.1 Run quarterly internal vulnerability scans and fix high-risk findings; 11.3.2.1 Run external scans after significant changes and fix CVSS 4.0+ findings
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Software Update Deferment Is 30 Days or Less
Finding: Software update deferment exceeds 30 days.
Checks the MDM-enforced software update deferment period.
This rule fails when enforcedSoftwareUpdateDelay exceeds 30 days.
Rationale: Deferring updates too long leaves systems exposed to publicly known vulnerabilities.
Impact: Some organizations may need more than 30 days to evaluate update impact.
Remediation
Open System Settings > General > Device Management and set any Deferred Software Update Delay to 30 days or fewer.
- Framework mappings
- CIS Controls v8: 7.3 Perform Automated Operating System Patch Management; 7.4 Perform Automated Application Patch Management
- NIST SP 800-53 Rev. 5: RA-5 Vulnerability Monitoring and Scanning; RA-7 Risk Response; SI-2 Flaw Remediation
- Risk
- Vulnerability
- MITRE ATT&CK tactic
- Execution (TA0002)