DISA Apple macOS 26 Tahoe STIG v1r1

Audit Details

Name: DISA Apple macOS 26 Tahoe STIG v1r1

Updated: 3/5/2026

Authority: DISA STIG

Plugin: Unix

Revision: 1.1

Estimated Item Count: 161

File Details

Filename: DISA_STIG_Apple_macOS_26_Tahoe_v1r1.audit

Size: 326 kB

MD5: f9a58ea229a7b2d0dcab5a2fd44fe828
SHA256: f89d8b7e912e8d7a5f732cc212e2aeceb9316fd27bb3cd5196879d79feab35d3

Audit Changelog

 
Revision 1.1

Mar 5, 2026

Functional Update
  • APPL-26-000001 - The macOS system must prevent Apple Watch from terminating a session lock.
  • APPL-26-000002 - The macOS system must enforce screen saver password.
  • APPL-26-000009 - The macOS system must prevent AdminHostInfo from being available at LoginWindow.
  • APPL-26-000014 - The macOS system must enforce time synchronization.
  • APPL-26-000033 - The macOS system must disable FileVault automatic login.
  • APPL-26-002005 - The macOS system must disable Bonjour multicast.
  • APPL-26-002007 - The macOS system must disable Internet Sharing.
  • APPL-26-002009 - The macOS system must disable AirDrop.
  • APPL-26-002010 - The macOS system must disable FaceTime.app.
  • APPL-26-002012 - The macOS system must disable the iCloud Calendar services.
  • APPL-26-002013 - The macOS system must disable iCloud Reminders.
  • APPL-26-002014 - The macOS system must disable iCloud Address Book.
  • APPL-26-002015 - The macOS system must disable iCloud Mail.
  • APPL-26-002016 - The macOS system must disable iCloud Notes.
  • APPL-26-002017 - The macOS system must disable the camera.
  • APPL-26-002020 - The macOS system must disable Siri.
  • APPL-26-002021 - The macOS system must disable sending diagnostic and usage data to Apple.
  • APPL-26-002023 - The macOS system must disable sending audio recordings and transcripts to Apple.
  • APPL-26-002040 - The macOS system must disable iCloud Keychain Sync.
  • APPL-26-002041 - The macOS system must disable iCloud Document Sync.
  • APPL-26-002042 - The macOS system must disable iCloud Bookmarks.
  • APPL-26-002043 - The macOS system must disable iCloud Photo Library.
  • APPL-26-002060 - The macOS system must apply gatekeeper settings to block applications from unidentified developers.
  • APPL-26-002062 - The macOS system must disable Bluetooth when no approved device is connected.
  • APPL-26-002063 - The macOS system must disable the guest account.
  • APPL-26-002064 - The macOS system must enable gatekeeper.
  • APPL-26-002066 - The macOS system must disable unattended or automatic login to the system.
  • APPL-26-002080 - The macOS system must disable Airplay Receiver.
  • APPL-26-002090 - The macOS system must disable TouchID for unlocking the device.
  • APPL-26-002100 - The macOS system must disable Media Sharing.
  • APPL-26-002120 - The macOS system must disable AppleID and internet Account Modification.
  • APPL-26-002140 - The macOS system must disable Content Caching service.
  • APPL-26-002150 - The macOS system must disable iCloud Desktop and Document folder sync.
  • APPL-26-002160 - The macOS system must disable iCloud Game Center.
  • APPL-26-002170 - The macOS system must disable iCloud Private Relay.
  • APPL-26-002180 - The macOS system must disable Find My service.
  • APPL-26-002200 - The macOS system must disable Personalized Advertising.
  • APPL-26-002220 - The macOS system must enforce On Device Dictation.
  • APPL-26-002230 - The macOS system must disable Dictation.
  • APPL-26-002270 - The macOS system must disable the iCloud Freeform services.
  • APPL-26-002271 - The macOS system must disable iPhone Mirroring.
  • APPL-26-003020 - The macOS system must enforce smart card authentication.
  • APPL-26-003030 - The macOS system must allow smart card authentication.
  • APPL-26-005020 - The macOS system must enforce FileVault.
  • APPL-26-005050 - The macOS system must enable macOS Application Firewall.
  • APPL-26-005052 - The macOS system must configure the login window to prompt for username and password.
  • APPL-26-005058 - The macOS system must disable Handoff.
  • APPL-26-005060 - The macOS system must disable proximity-based password sharing requests.
  • APPL-26-005061 - The macOS system must disable Erase Content and Settings.
  • APPL-26-005080 - The macOS system must prohibit user installation of software into /users/.
  • APPL-26-005090 - The macOS system must authorize USB devices before allowing connection.
  • APPL-26-005130 - The macOS system must enforce installation of XProtect Remediator and Gatekeeper updates automatically.
  • APPL-26-005140 - The macOS system must disable Genmoji AI Creation.
  • APPL-26-005150 - The macOS system must disable Apple Intelligence Image Playground.
  • APPL-26-005160 - The macOS system must disable Apple Intelligence Writing Tools.
Miscellaneous
  • Metadata updated.