NIST macOS Catalina v1.5.0 - 800-171

Audit Details

Name: NIST macOS Catalina v1.5.0 - 800-171

Updated: 9/7/2023

Authority: TNS

Plugin: Unix

Revision: 1.4

Estimated Item Count: 137

File Details

Filename: NIST_macOS_Catalina_800-171_v1.5.0.audit

Size: 235 kB

MD5: 5aa30856ad8d7c7e9f4f21c7004cfabb
SHA256: b33b3a32409a08e44771dc13e5101561420c5dc37227086b356d1efaab0a0f22

Audit Items

DescriptionCategories
Catalina - Apply Gatekeeper Settings to Block Applications from Unidentified Developers

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

Catalina - Configure Audit Failure Notification

AUDIT AND ACCOUNTABILITY

Catalina - Configure Audit Log Files Group to Wheel

AUDIT AND ACCOUNTABILITY

Catalina - Configure Audit Log Files to be Owned by Root

AUDIT AND ACCOUNTABILITY

Catalina - Configure Audit Log Files to Mode 440 or Less Permissive

AUDIT AND ACCOUNTABILITY

Catalina - Configure Audit Log Files to Not Contain Access Control Lists

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

Catalina - Configure Audit Log Folder to Not Contain Access Control Lists

AUDIT AND ACCOUNTABILITY, SYSTEM AND INFORMATION INTEGRITY

Catalina - Configure Audit Log Folders Group to Wheel

AUDIT AND ACCOUNTABILITY

Catalina - Configure Audit Log Folders to be Owned by Root

AUDIT AND ACCOUNTABILITY

Catalina - Configure Audit Log Folders to Mode 700 or Less Permissive

AUDIT AND ACCOUNTABILITY

Catalina - Configure Gatekeeper to Disallow End User Override

CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY

Catalina - Configure Login Window to Prompt for Username and Password

IDENTIFICATION AND AUTHENTICATION

Catalina - Configure macOS to Use an Authorized Time Server

AUDIT AND ACCOUNTABILITY

Catalina - Configure SSH ServerAliveInterval option set to 900 or less

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Configure System to Audit All Administrative Action Events

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

Catalina - Configure System to Audit All Authorization and Authentication Events

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

Catalina - Configure System to Audit All Failed Change of Object Attributes

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

Catalina - Configure System to Audit All Failed Program Execution on the System

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

Catalina - Configure System to Audit All Failed Read Actions on the System

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

Catalina - Configure System to Audit All Failed Write Actions on the System

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT, MAINTENANCE

Catalina - Configure System to Audit All Log In and Log Out Events

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

Catalina - Configure System to Shut Down Upon Audit Failure

AUDIT AND ACCOUNTABILITY

Catalina - Configure the System for Nonlocal Maintenance

MAINTENANCE

Catalina - Configure the System to Block Non-Privileged Users from Executing Privileged Functions

ACCESS CONTROL

Catalina - Configure the System to Implement Approved Cryptography to Protect Information

SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Configure the System to Prevent the Unauthorized Disclosure of Data via Shared Resources

SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Configure the System to Separate User and System Functionality - separate

MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Configure User Session Lock When a Smart Token is Removed

ACCESS CONTROL

Catalina - Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall Policy

ACCESS CONTROL, SECURITY ASSESSMENT AND AUTHORIZATION, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Disable Accounts after 35 Days of Inactivity

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Ad Tracking

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Disable AirDrop

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Apple Filing Protocol Sharing

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Apple ID Setup during Setup Assistant

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Bluetooth Sharing

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Bluetooth When no Approved Device is Connected

ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Disable Bonjour Multicast

CONFIGURATION MANAGEMENT

Catalina - Disable Calendar.app

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Content Caching Service

CONFIGURATION MANAGEMENT

Catalina - Disable FaceTime.app

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable FileVault Automatic Login

ACCESS CONTROL, CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Find My Service

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Guest Access to Shared Apple File Protocol Folders

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Guest Access to Shared SMB Folders

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

Catalina - Disable Handoff

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Hot Corners

ACCESS CONTROL

Catalina - Disable iCloud Address Book

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Disable iCloud Bookmarks

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Disable iCloud Desktop and Document Folder Sync

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

Catalina - Disable iCloud Document Sync

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION