Glossary
System Integrity Protection (SIP)
System Integrity Protection is a macOS security layer that stops even the root user from modifying protected system files and processes.
System Integrity Protection (SIP) is a macOS security technology, introduced in OS X El Capitan, that restricts what the root user can do. Even with administrator privileges, processes cannot modify protected system locations, inject code into Apple-signed system processes, or load unsigned kernel extensions. The protected areas include system directories such as /System and /usr (with exceptions like /usr/local), as well as sensitive data stores such as the TCC privacy databases.
The point of SIP is to limit the damage when something on the Mac gains root, whether that is malware, a compromised installer or a mistaken script. Without it, root access would be enough to tamper with the operating system itself.
SIP status can be checked with csrutil status, but its configuration can only be changed from recoveryOS, not from a running system. Disabling it lowers the security of the whole Mac and should not happen on production devices. On current macOS, SIP works alongside the Signed System Volume to keep the OS in a known-good state.
See the System Integrity Protection guide for details and verification commands.