Created
April 10, 2026 21:39
-
-
Save crsleeth/e1ad6dd78df72fc75468b96c3fac5e16 to your computer and use it in GitHub Desktop.
Tahoe 26.4 mSCP-JCE CIS LVL1 fresh install results
We can make this file beautiful and searchable if this error is corrected: Illegal quoting in line 10.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Title,Finding,Result value,Expected Result,Name,Discussion | |
| Auditing | |
| Configure Audit Log Folders Group to Wheel,false,0,integer: 0,audit_folder_group_configure,Audit log files _MUST_ have the group set to wheel.The audit service _MUST_ be configured to create log files with the correct group ownership to prevent normal users from reading audit logs.Audit logs contain sensitive data about the system and users. If log files are set to be readable and writable only by system administrators the risk is mitigated. | |
| Configure Audit_Control Owner to Mode 440 or Less Permissive,false,0,integer: 0,audit_control_mode_configure,/etc/security/audit_control _MUST_ be configured so that it is readable only by the root user and group wheel. | |
| Configure Audit Log Folder to Not Contain Access Control Lists,false,0,integer: 0,audit_acls_folders_configure,The audit log folder _MUST_ not contain access control lists (ACLs).Audit logs contain sensitive data about the system and users. This rule ensures that the audit service is configured to create log folders that are readable and writable only by system administrators in order to prevent normal users from reading audit logs. | |
| Enable Security Auditing,true,fail,string: pass,audit_auditd_enabled,The information system _MUST_ be configured to generate audit records.Audit records establish what types of events have occurred when they occurred and which users were involved. These records aid an organization in their efforts to establish correlate and investigate the events leading up to an outage or attack.The content required to be captured in an audit record varies based on the impact level of an organization's system. Content that may be necessary to satisfy this requirement includes for example time stamps source addresses destination addresses user identifiers event descriptions success/fail indications filenames involved and access or flow control rules invoked.The information system initiates session audits at system start-up.NOTE: Security auditing is NOT enabled by default on macOS Tahoe. | |
| Configure Audit Log Files to Mode 440 or Less Permissive,true,21,integer: 0,audit_files_mode_configure,The audit service _MUST_ be configured to create log files that are readable only by the root user and group wheel. To achieve this audit log files _MUST_ be configured to mode 440 or less permissive; thereby preventing normal users from reading modifying or deleting audit logs. | |
| Configure Audit_Control Owner to Root,true,null,integer: 0,audit_control_owner_configure,/etc/security/audit_control _MUST_ have the owner set to root. | |
| Configure Audit Log Files to be Owned by Root,false,0,integer: 0,audit_files_owner_configure,Audit log files _MUST_ be owned by root.The audit service _MUST_ be configured to create log files with the correct ownership to prevent normal users from reading audit logs.Audit logs contain sensitive data about the system and users. If log files are set to only be readable and writable by system administrators the risk is mitigated. | |
| Configure Audit Retention to $ODV,true,null,string: 60d OR 5G,audit_retention_configure,The audit service _MUST_ be configured to require records be kept for a organizational defined value before deletion unless the system uses a central audit record storage facility.When "expire-after" is set to "$ODV" the audit service will not delete audit logs until the log data criteria is met. | |
| Configure Audit Log Folders to be Owned by Root,false,0,integer: 0,audit_folder_owner_configure,Audit log folders _MUST_ be owned by root.The audit service _MUST_ be configured to create log folders with the correct ownership to prevent normal users from reading audit logs.Audit logs contain sensitive data about the system and users. If log folders are set to only be readable and writable by system administrators the risk is mitigated. | |
| Configure Audit_Control to Not Contain Access Control Lists,false,0,integer: 0,audit_control_acls_configure,/etc/security/audit_control _MUST_ not contain Access Control Lists (ACLs). | |
| Configure Audit Log Folders to Mode 700 or Less Permissive,true,666,integer: 700,audit_folders_mode_configure,The audit log folder _MUST_ be configured to mode 700 or less permissive so that only the root user is able to read write and execute changes to folders.Because audit logs contain sensitive data about the system and users the audit service _MUST_ be configured to mode 700 or less permissive; thereby preventing normal users from reading modifying or deleting audit logs. | |
| Configure Audit Log Files Group to Wheel,true,320,integer: 0,audit_files_group_configure,Audit log files _MUST_ have the group set to wheel.The audit service _MUST_ be configured to create log files with the correct group ownership to prevent normal users from reading audit logs.Audit logs contain sensitive data about the system and users. If log files are set to be readable and writable only by system administrators the risk is mitigated. | |
| Configure Audit_Control Group to Wheel,true,null,integer: 0,audit_control_group_configure,/etc/security/audit_control _MUST_ have the group set to wheel. | |
| Configure Audit Log Files to Not Contain Access Control Lists,false,0,integer: 0,audit_acls_files_configure,The audit log files _MUST_ not contain access control lists (ACLs).This rule ensures that audit information and audit files are configured to be readable and writable only by system administrators thereby preventing unauthorized access modification and deletion of files. | |
| System Settings | |
| Ensure Time Machine Volumes are Encrypted,false,0,integer: 0,system_settings_time_machine_encrypted_configure,Time Machine volumes _MUST_ be encrypted. | |
| Enforce macOS Updates are Automatically Installed,false,true,string: true,system_settings_install_macos_updates_enforce,Software Update _MUST_ be configured to enforce automatic installation of macOS updates is enabled. | |
| Enforce Session Lock After Screen Saver is Started,true,false,string: true,system_settings_screensaver_ask_for_password_delay_enforce,A screen saver _MUST_ be enabled and the system _MUST_ be configured to require a password to unlock once the screensaver has been on for a maximum of $ODV seconds.An unattended system with an excessive grace period is vulnerable to a malicious user. | |
| Ensure Location Services Is In the Menu Bar,true,null,boolean: 1,system_settings_location_services_menu_enforce,Location Services menu item _MUST_ be enabled. | |
| Disable Guest Access to Shared SMB Folders,true,null,boolean: 0,system_settings_guest_access_smb_disable,Guest access to shared Server Message Block (SMB) folders _MUST_ be disabled.Turning off guest access prevents anonymous users from accessing files shared via SMB. | |
| Disable Printer Sharing,false,1,boolean: 1,system_settings_printer_sharing_disable,Printer Sharing _MUST_ be disabled. | |
| Require Administrator Password to Modify System-Wide Preferences,true,0,integer: 1,system_settings_system_wide_preferences_configure,The system _MUST_ be configured to require an administrator password in order to modify the system-wide preferences in System Settings.Some Preference Panes in System Settings contain settings that affect the entire system. Requiring a password to unlock these system-wide settings reduces the risk of a non-authorized user modifying system configurations. | |
| Disable Improve Search Information to Apple,true,null,integer: 2,system_settings_improve_search_disable,Sending data to Apple to help improve search _MUST_ be disabled. This will disable "Improve Search" within Spotlight in System Settings.The information system _MUST_ be configured to provide only essential capabilities. Disabling the submission of search data will mitigate the risk of unwanted data being sent to Apple. | |
| Disable the Guest Account,true,false,string: true,system_settings_guest_account_disable,Guest access _MUST_ be disabled.Turning off guest access prevents anonymous users from accessing files. | |
| Enforce Software Update Downloads Updates Automatically,false,true,string: true,system_settings_software_update_download_enforce,Software Update _MUST_ be configured to enforce automatic downloads of updates is enabled. | |
| Disable Personalized Advertising,true,null,string: false,system_settings_personalized_advertising_disable,Ad tracking and targeted ads _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. Disabling ad tracking ensures that applications and advertisers are unable to track users' interests and deliver targeted advertisements. | |
| Disable Remote Management,false,1,integer: 1,system_settings_remote_management_disable,Remote Management _MUST_ be disabled. | |
| Configure Login Window to Prompt for Username and Password,true,null,string: true,system_settings_loginwindow_prompt_username_password_enforce,The login window _MUST_ be configured to prompt all users for both a username and a password.By default the system displays a list of known users on the login window which can make it easier for a malicious user to gain access to someone else's account. Requiring users to type in both their username and password mitigates the risk of unauthorized users gaining access to the information system. | |
| Disable Server Message Block Sharing,true,0,integer: 1,system_settings_smbd_disable,Support for Server Message Block (SMB) file sharing is non-essential and _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. | |
| Enforce Screen Saver Timeout,true,false,string: true,system_settings_screensaver_timeout_enforce,The screen saver timeout _MUST_ be set to $ODV seconds or a shorter length of time.This rule ensures that a full session lock is triggered within no more than $ODV seconds of inactivity. | |
| Disable Password Hints,true,null,integer: 0,system_settings_password_hints_disable,Password hints _MUST_ be disabled.Password hints leak information about passwords that are currently in use and can lead to loss of confidentiality. | |
| Disable Screen Sharing and Apple Remote Desktop,false,PASS,string: PASS,system_settings_screen_sharing_disable,Support for both Screen Sharing and Apple Remote Desktop (ARD) is non-essential and _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. Disabling screen sharing and ARD helps prevent the unauthorized connection of devices the unauthorized transfer of information and unauthorized tunneling. | |
| Ensure Software Update is Updated and Current,false,1,integer: 1,system_settings_softwareupdate_current,Make sure Software Update is updated and current.link:https://support.apple.com/en-us/108382[Update macOS on Mac] or if enrolled in an MDM consult your MDM's documentation for automated methods. | |
| Disable External Intelligence Integrations,true,null,string: false,system_settings_external_intelligence_disable,Integration with external intelligence systems _MUST_ be disabled unless approved by the organization. Disabling external intelligence integration will mitigate the risk of data being sent to unapproved third party.The information system _MUST_ be configured to provide only essential capabilities. | |
| Disable Internet Sharing,true,null,string: true,system_settings_internet_sharing_disable,If the system does not require Internet sharing support for it is non-essential and _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. Disabling Internet sharing helps prevent the unauthorized connection of devices unauthorized transfer of information and unauthorized tunneling. | |
| Enforce FileVault,true,0,integer: 1,system_settings_filevault_enforce,FileVault _MUST_ be enforced.The information system implements cryptographic mechanisms to protect the confidentiality and integrity of information stored on digital media during transport outside of controlled areas.NOTE: See the FileVault supplemental to implement this rule. | |
| Disable SSH Server for Remote Access Sessions,false,PASS,string: PASS,system_settings_ssh_disable,SSH service _MUST_ be disabled for remote access. | |
| Disable Siri,true,null,string: false,system_settings_siri_disable,Support for Siri is non-essential and _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. | |
| Enforce Screen Saver Password,true,null,string: true,system_settings_screensaver_password_enforce,Users _MUST_ authenticate when unlocking the screen saver.The screen saver acts as a session lock and prevents unauthorized users from accessing the current user's account. | |
| Enable macOS Application Firewall,true,null,string: true,system_settings_firewall_enable,The macOS Application Firewall is the built-in firewall that comes with macOS and it _MUST_ be enabled.When the macOS Application Firewall is enabled the flow of information within the information system and between interconnected systems will be controlled by approved authorizations. | |
| Disable Sending Diagnostic and Usage Data to Apple,true,false,string: true,system_settings_diagnostics_reports_disable,The ability to submit diagnostic data to Apple _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. Disabling the submission of diagnostic and usage information will mitigate the risk of unwanted data being sent to Apple. | |
| Enforce Critical Security Updates to be Installed,false,true,string: true,system_settings_critical_update_install_enforce,Ensure that security updates are installed as soon as they are available from Apple. | |
| Ensure Wake for Network Access Is Disabled,true,1,integer: 0,system_settings_wake_network_access_disable,Wake for network access _MUST_ be disabled. | |
| Disable Bluetooth Sharing,true,null,boolean: 0,system_settings_bluetooth_sharing_disable,Bluetooth Sharing _MUST_ be disabled.Bluetooth Sharing allows users to wirelessly transmit files between the macOS and Bluetooth-enabled devices including personally owned cellphones and tablets. A malicious user might introduce viruses or malware onto the system or extract sensitive files via Bluetooth Sharing. When Bluetooth Sharing is disabled this risk is mitigated.[NOTE]====The check and fix are for the last logged in user. To get the last logged in user run the following.[sourcebash]----CURRENT_USER=$( /usr/bin/defaults read /Library/Preferences/com.apple.loginwindow lastUserName )----==== | |
| Disable Unattended or Automatic Logon to the System,true,null,string: true,system_settings_automatic_login_disable,Automatic logon _MUST_ be disabled.When automatic logons are enabled the default user account is automatically logged on at boot time without prompting the user for a password. Even if the screen is later locked a malicious user would be able to reboot the computer and find it already logged in. Disabling automatic logons mitigates this risk. | |
| Configure Login Window to Show A Custom Message,true,null,base64: Q2VudGVyIGZvciBJbnRlcm5ldCBTZWN1cml0eSBUZXN0IE1lc3NhZ2UK,system_settings_loginwindow_loginwindowtext_enable,The login window _MUST_ be configured to show a custom access warning message. | |
| Disable Improve Siri and Dictation Information to Apple,true,null,integer: 2,system_settings_improve_siri_dictation_disable,The ability for Apple to store and review audio of your Siri and Dictation interactions _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. Disabling the submission of Siri and Dictation information will mitigate the risk of unwanted data being sent to Apple. | |
| Disable External Intelligence Integration Sign In,true,null,string: false,system_settings_external_intelligence_sign_in_disable,The ability to sign into an external intelligence systems _MUST_ be disabled unless approved by the organization. Disabling external intelligence integration will mitigate the risk of data being sent to unapproved third party.The information system _MUST_ be configured to provide only essential capabilities. | |
| Configure macOS to Use an Authorized Time Server,true,null,string: time.apple.com,system_settings_time_server_configure,Approved time server _MUST_ be the only server configured for use. As of macOS 10.13 only one time server is supported.This rule ensures the uniformity of time stamps for information systems with multiple system clocks and systems connected over a network. | |
| Enforce macOS Time Synchronization,true,null,string: true,system_settings_time_server_enforce,Time synchronization _MUST_ be enforced on all networked systems.This rule ensures the uniformity of time stamps for information systems with multiple system clocks and systems connected over a network. | |
| Disable Sending Audio Recordings and Transcripts to Apple,true,null,string: false,system_settings_improve_assistive_voice_disable,The ability for Apple to store and review audio of your audio recordings and transcripts of your vocal shortcuts and voice control interactions _MUST_ be disabled. This will disable "Improve Assistive Voice Features" in Privacy & Security within System Settings.The information system _MUST_ be configured to provide only essential capabilities. Disabling the submission of this information will mitigate the risk of unwanted data being sent to Apple. | |
| Disable Airplay Receiver,true,null,string: false,system_settings_airplay_receiver_disable,Airplay Receiver allows you to send content from another Apple device to be displayed on the screen as it's being played from your other device.Support for Airplay Receiver is non-essential and _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. | |
| Enable Firewall Stealth Mode,true,null,string: true,system_settings_firewall_stealth_mode_enable,Firewall Stealth Mode _MUST_ be enabled.When stealth mode is enabled the Mac will not respond to any probing requests and only requests from authorized applications will still be authorized.[IMPORTANT]====Enabling firewall stealth mode may prevent certain remote mechanisms used for maintenance and compliance scanning from properly functioning. Information System Security Officers (ISSOs) are advised to first fully weigh the potential risks posed to their organization before opting not to enable stealth mode.==== | |
| Disable Remote Apple Events,true,0,integer: 1,system_settings_rae_disable,If the system does not require Remote Apple Events support for Apple Remote Events is non-essential and _MUST_ be disabled.The information system _MUST_ be configured to provide only essential capabilities. Disabling Remote Apple Events helps prevent the unauthorized connection of devices the unauthorized transfer of information and unauthorized tunneling. | |
| macOS | |
| Disable Power Nap,false,0,integer: 1,os_power_nap_disable,Power Nap _MUST_ be disabled.NOTE: Power Nap allows your Mac to perform actions while a Mac is asleep. This can interfere with USB power and may cause devices such as smartcards to stop functioning until a reboot and must therefore be disabled on all applicable systems.The following Macs support Power Nap:* MacBook (Early 2015 and later)* MacBook Air (Late 2010 and later)* MacBook Pro (all models with Retina display)* Mac mini (Late 2012 and later)* iMac (Late 2012 and later)* Mac Pro (Late 2013 and later) | |
| Ensure Warn When Visiting A Fraudulent Website in Safari Is Enabled,true,0,integer: 1,os_safari_warn_fraudulent_website_enable,Warn when visiting a fraudulent website _MUST_ be enabled in Safari. | |
| Disable Root Login,true,0,integer: 1,os_root_disable,To assure individual accountability and prevent unauthorized access logging in as root at the login window _MUST_ be disabled.The macOS system _MUST_ require individuals to be authenticated with an individual authenticator prior to using a group authenticator and administrator users _MUST_ never log in directly as root. | |
| Disable Apple Intelligence Notes Transcription,true,null,string: false,os_notes_transcription_disable,Apple Intelligence features such as Notes Transcription that use off device AI _MUST_ be disabled. | |
| Must Use an Approved Antivirus Program,false,2,integer: 2,os_anti_virus_installed,An approved antivirus product _MUST_ be installed and configured to run.Malicious software can establish a base on individual desktops and servers. Employing an automated mechanism to detect this type of software will aid in elimination of the software from the operating system.' | |
| Ensure No World Writable Files Exist in the System Folder,false,0,integer: 0,os_world_writable_system_folder_configure,Folders in /System/Volumes/Data/System _MUST_ not be world-writable. | |
| Disable Automatic Opening of Safe Files in Safari,true,0,integer: 1,os_safari_open_safe_downloads_disable,Open "safe" files after downloading _MUST_ be disabled in Safari. | |
| Disable Apple Intelligence Mail Summary,true,null,string: false,os_mail_summary_disable,Apple Intelligence features such as Apple Mail Summary that use off device AI _MUST_ be disabled. | |
| Disable Apple Intelligence Notes Transcription Summary,true,null,string: false,os_notes_transcription_summary_disable,Apple Intelligence features such as Notes Transcription Summary that use off device AI _MUST_ be disabled. | |
| Enable Authenticated Root,false,1,integer: 1,os_authenticated_root_enable,Authenticated Root _MUST_ be enabled.When Authenticated Root is enabled the macOS is booted from a signed volume that is cryptographically protected to prevent tampering with the system volume.NOTE: Authenticated Root is enabled by default on macOS systems.WARNING: If more than one partition with macOS is detected the csrutil command will hang awaiting input. | |
| Ensure Advertising Privacy Protection in Safari Is Enabled,true,0,integer: 1,os_safari_advertising_privacy_protection_enable,Allow privacy-preserving measurement of ad effectiveness _MUST_ be enabled in Safari. | |
| Enforce Installation of XProtect Remediator and Gatekeeper Updates Automatically,false,true,string: true,os_config_data_install_enforce,Software Update _MUST_ be configured to update XProtect Remediator and Gatekeeper automatically.This setting enforces definition updates for XProtect Remediator and Gatekeeper; with this setting in place new malware and adware that Apple has added to the list of malware or untrusted software will not execute. These updates do not require the computer to be restarted.link:https://support.apple.com/en-us/HT207005[]NOTE: Software update will automatically update XProtect Remediator and Gatekeeper by default in the macOS. | |
| Remove Guest Folder if Present,false,0,integer: 0,os_guest_folder_removed,The guest folder _MUST_ be deleted if present. | |
| Remove Password Hint From User Accounts,false,PASS,string: PASS,os_password_hint_remove,User accounts _MUST_ not contain password hints. | |
| Enforce Software Update App Update Updates Automatically,true,null,string: true,os_software_update_app_update_enforce,Software Update _MUST_ be configured to enforce automatic updates of App Updates is enabled. | |
| Configure Sudo To Log Events,true,0,integer: 1,os_sudo_log_enforce,Sudo _MUST_ be configured to log privilege escalation. | |
| Disable Apple Intelligence Writing Tools,true,null,string: false,os_writing_tools_disable,Apple Intelligence features such as writing tools that use off device AI _MUST_ be disabled. | |
| Disable AirDrop,true,null,string: false,os_airdrop_disable,AirDrop _MUST_ be disabled to prevent file transfers to or from unauthorized devices.AirDrop allows users to share and receive files from other nearby Apple devices. | |
| Configure Sudoers Timestamp Type,false,tty,string: tty,os_sudoers_timestamp_type_configure,The file /etc/sudoers _MUST_ be configured to not include a timestamp_type of global or ppid and be configured for timestamp record types of tty.This rule ensures that the "sudo" command will prompt for the administrator's password at least once in each newly opened terminal window. This prevents a malicious user from taking advantage of an unlocked computer or an abandoned logon session by bypassing the normal password prompt requirement. | |
| Disable Network File System Service,true,fail,string: pass,os_nfsd_disable,Support for Network File Systems (NFS) services is non-essential and therefore _MUST_ be disabled. | |
| Disable the Built-in Web Server,false,PASS,string: PASS,os_httpd_disable,The built-in web server which is managed by launchd is a non-essential service built into macOS and _MUST_ be disabled and not running.NOTE: The built in web server service is disabled at startup by default macOS. | |
| Ensure Show Full Website Address in Safari Is Enabled,true,0,integer: 1,os_safari_show_full_website_address_enable,Show full website address _MUST_ be enabled in Safari. | |
| Enable Apple Mobile File Integrity,false,0,integer: 0,os_mobile_file_integrity_enable,Mobile file integrity _MUST_ be enabled. | |
| Enable Gatekeeper,true,null,string: true,os_gatekeeper_enable,Gatekeeper _MUST_ be enabled.Gatekeeper is a security feature that ensures that applications are digitally signed by an Apple-issued certificate before they are permitted to run. Digital signatures allow the macOS host to verify that the application has not been modified by a malicious third party.Administrator users will still have the option to override these settings on a case-by-case basis. | |
| Ensure System Integrity Protection is Enabled,false,1,integer: 1,os_sip_enable,System Integrity Protection (SIP) _MUST_ be enabled.SIP is vital to protecting the integrity of the system as it prevents malicious users and software from making unauthorized and/or unintended modifications to protected files and folders; ensures the presence of an audit record generation capability for defined auditable events for all operating system components; protects audit tools from unauthorized access modification and deletion; restricts the root user account and limits the actions that the root user can perform on protected parts of the macOS; and prevents non-privileged users from granting other users direct access to the contents of their home directories and folders.NOTE: SIP is enabled by default in macOS. | |
| Ensure Secure Keyboard Entry Terminal.app is Enabled,true,null,string: true,os_terminal_secure_keyboard_enable,Secure keyboard entry _MUST_ be enabled in Terminal.app. | |
| Enable Time Synchronization Daemon,false,1,integer: 1,os_time_server_enabled,The macOS time synchronization daemon (timed) _MUST_ be enabled for proper time synchronization to an authorized time server.NOTE: The time synchronization daemon is enabled by default on macOS. | |
| Disable Login to Other User's Active and Locked Sessions,true,FAIL,string: PASS,os_unlock_active_user_session_disable,The ability to log in to another user's active or locked session _MUST_ be disabled.macOS has a privilege that can be granted to any user that will allow that user to unlock active user's sessions. Disabling the admins and/or user's ability to log into another user's active and locked session prevents unauthorized persons from viewing potentially sensitive and/or personal information.NOTE: Configuring this setting will change the user experience and disable TouchID from unlocking the screensaver. A configuration profile will be generated to include the setting that restores the expected behavior. You can also apply the settings using `/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow screenUnlockMode -int 1`.WARNING: Do not apply this rule if your organization uses smartcards and Platform Single Sign-On (PSSO). | |
| Configure Sudo Timeout Period to $ODV,true,0,integer: 1,os_sudo_timeout_configure,The file /etc/sudoers _MUST_ include a timestamp_timeout of $ODV. | |
| Ensure Show Safari shows the Status Bar is Enabled,true,0,integer: 1,os_safari_show_status_bar_enabled,Safari _MUST_ be configured to show the status bar. | |
| Ensure Appropriate Permissions Are Enabled for System Wide Applications,false,0,integer: 0,os_system_wide_applications_configure,Applications in the System Applications Directory (/Applications) _MUST_ not be world-writable. | |
| Ensure Software Update Deferment Is Less Than or Equal to $ODV Days,false,true,string: true,os_software_update_deferral,Software updates _MUST_ be deferred for $ODV days or less.If you need to defer software updates create a Restrictions profile using the com.apple.applicationaccess domain and the key enforcedSoftwareUpdateDelay. | |
| Secure User's Home Folders,true,1,integer: 0,os_home_folders_secure,The system _MUST_ be configured to prevent access to other user's home folders.The default behavior of macOS is to allow all valid users access to the top level of every other user's home folder while restricting access only to the Apple default folders within. | |
| Enforce On Device Dictation,true,null,string: true,os_on_device_dictation_enforce,Dictation _MUST_ be restricted to on device only to prevent potential data exfiltration.The information system _MUST_ be configured to provide only essential capabilities.IMPORTANT: This rule only applies to Apple Silicon devices. | |
| Configure Install.log Retention to $ODV,true,all_max setting is configured, must be removed | |
| TTL not configured,string: Yes,os_install_log_retention_configure,The install.log _MUST_ be configured to require records be kept for a organizational defined value before deletion unless the system uses a central audit record storage facility. | |
| Ensure Prevent Cross-site Tracking in Safari Is Enabled,true,0,integer: 1,os_safari_prevent_cross-site_tracking_enable,Prevent cross-site tracking _MUST_ be enabled in Safari. | |
| Password Policy | |
| Restrict Maximum Password Lifetime to $ODV Days,true,null,string: pass,pwpolicy_max_lifetime_enforce,The macOS _MUST_ be configured to enforce a maximum password lifetime limit of at least $ODV days.This rule ensures that users are forced to change their passwords frequently enough to prevent malicious users from gaining and maintaining access to the system.NOTE: To comply with Executive Order 14028 “Improving the Nation's Cybersecurity” OMB M-22-09 “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles” and NIST SP-800-63b “Digital Identity Guidelines: Authentication and Lifecycle Management” federal military and intelligence communities must adopt the following configuration settings. Password policies must not require the use of complexity policies such as upper characters lower characters or special characters. Password policies must also not require the use of regular rotation. Password policies should define a minimum length. Multifactor authentication should be used where ever possible. | |
| Prohibit Password Reuse for a Minimum of $ODV Generations,true,null,string: pass,pwpolicy_history_enforce,The macOS _MUST_ be configured to enforce a password history of at least $ODV previous passwords when a password is created.This rule ensures that users are not allowed to reuse a password that was used in any of the $ODV previous password generations.Limiting password reuse protects against malicious users attempting to gain access to the system via brute-force hacking methods.NOTE: The guidance for password based authentication in NIST 800-53 (Rev 5) and NIST 800-63B state that complexity rules should be organizationally defined. The values defined are based off of common complexity values. But your organization may define its own password complexity rules. | |
| Limit Consecutive Failed Login Attempts to $ODV,true,null,string: pass,pwpolicy_account_lockout_enforce,The macOS _MUST_ be configured to limit the number of failed login attempts to a maximum of $ODV. When the maximum number of failed attempts is reached the account _MUST_ be locked for a period of time after.This rule protects against malicious users attempting to gain access to the system via brute-force hacking methods. | |
| Set Account Lockout Time to $ODV Minutes,true,null,string: pass,pwpolicy_account_lockout_timeout_enforce,The macOS _MUST_ be configured to enforce a lockout time period of at least $ODV minutes when the maximum number of failed logon attempts is reached.This rule protects against malicious users attempting to gain access to the system via brute-force hacking methods. | |
| Require a Minimum Password Length of $ODV Characters,true,fail,string: pass,pwpolicy_minimum_length_enforce,The macOS _MUST_ be configured to require a minimum of $ODV characters be used when a password is created.This rule enforces password complexity by requiring users to set passwords that are less vulnerable to malicious users.NOTE: To comply with Executive Order 14028 “Improving the Nation's Cybersecurity” OMB M-22-09 “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles” and NIST SP-800-63b “Digital Identity Guidelines: Authentication and Lifecycle Management” federal military and intelligence communities must adopt the following configuration settings. Password policies must not require the use of complexity policies such as upper characters lower characters or special characters. Password policies must also not require the use of regular rotation. Password policies should define a minimum length. Multifactor authentication should be used where ever possible. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment