Item Search

NameAudit NamePluginCategory
1.5 Enable macOS update installsCIS Apple macOS 10.12 L1 v1.2.0Unix

SYSTEM AND INFORMATION INTEGRITY

1.6 Ensure Install of macOS Updates Is EnabledCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

APPL-11-000004 - The macOS system must initiate a session lock after a 15-minute period of inactivity.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL

APPL-11-000011 - The macOS system must disable the SSHD service.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-11-000014 - The macOS system must, for networked systems, compare internal information system clocks at least every 24 hours with a server that is synchronized to one of the redundant United States Naval Observatory (USNO) time servers or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet) and/or the Global Positioning System (GPS) - Network Time ServerDISA STIG Apple macOS 11 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-11-000016 - The macOS system must be integrated into a directory services infrastructure.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-000023 - The macOS system must display the Standard Mandatory DoD Notice and Consent Banner before granting remote access to the operating system.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL

APPL-11-000031 - The macOS system must be configured so that log folders must not contain access control lists (ACLs).DISA STIG Apple macOS 11 v1r8Unix

AUDIT AND ACCOUNTABILITY

APPL-11-000033 - The macOS system must be configured to disable password forwarding for FileVault2.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL

APPL-11-000055 - The macOS system must use only Message Authentication Codes (MACs) employing FIPS 140-2 validated cryptographic hash algorithms.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-11-001003 - The macOS system must initiate session audits at system startup, using internal clocks with time stamps for audit records that meet a minimum granularity of one second and can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT), to generate audit records containing information to establish what type of events occurred, the identity of any individual or process associated with the event, including individual identities of group account users, establish where the events occurred, source of the event, and outcome of the events including all account enabling actions, full-text recording of privileged commands, and information about the use of encryption for access wireless access to and from the system.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

APPL-11-001013 - The macOS system must be configured with audit log folders owned by root.DISA STIG Apple macOS 11 v1r8Unix

AUDIT AND ACCOUNTABILITY

APPL-11-001020 - The macOS system must audit the enforcement actions used to restrict access associated with changes to the system - fdDISA STIG Apple macOS 11 v1r8Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

APPL-11-001020 - The macOS system must audit the enforcement actions used to restrict access associated with changes to the system - frDISA STIG Apple macOS 11 v1r8Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

APPL-11-002003 - The macOS system must be configured to disable the Network File System (NFS) daemon unless it is required.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002009 - The macOS system must be configured to disable AirDrop.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002016 - The macOS system must be configured to disable the iCloud Notes services.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002020 - The macOS system must be configured to disable Siri and dictation - Assistant AllowedDISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002022 - The macOS system must be configured to disable Remote Apple Events.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002031 - The macOS system must be configured to disable the system preference pane for Apple ID.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002035 - The macOS system must be configured to disable the Cloud Setup services.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002037 - The macOS system must be configured to disable the Cloud Storage Setup services.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002062 - The macOS system must be configured with Bluetooth turned off unless approved by the organization - DisableBluetoothDISA STIG Apple macOS 11 v1r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-11-002068 - The macOS system must set permissions on user home directories to prevent users from having access to read or modify another user's files - User directory home permissionsDISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002068 - The macOS system must set permissions on user home directories to prevent users from having access to read or modify another user's files - User directory permissionsDISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002068 - The macOS system must set permissions on user home directories to prevent users from having access to read or modify another user's files - User subdirectory Public permissionsDISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002069 - The macOS system must authenticate peripherals before establishing a connection.DISA STIG Apple macOS 11 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-002070 - The macOS system must use an approved antivirus program.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-003011 - The macOS system must enforce password complexity by requiring that at least one special character be used - allowSimpleDISA STIG Apple macOS 11 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-003011 - The macOS system must enforce password complexity by requiring that at least one special character be used - allowSimpleDISA STIG Apple macOS 11 v1r8Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-005051 - The macOS system must restrict the ability to utilize external writeable media devices.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-13-000004 - The macOS system must initiate a session lock after a 15-minute period of inactivity.DISA STIG Apple macOS 13 v1r5Unix

ACCESS CONTROL

APPL-13-000006 - The macOS system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.DISA STIG Apple macOS 13 v1r5Unix

ACCESS CONTROL

APPL-13-000014 - The macOS system must compare internal information system clocks at least every 24 hours with a server that is synchronized to one of the redundant United States Naval Observatory (USNO) time servers or a time server designated for the appropriate DOD network (NIPRNet/SIPRNet) and/or the Global Positioning System (GPS).DISA STIG Apple macOS 13 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-13-000031 - The macOS system must be configured so that log folders do not contain access control lists (ACLs).DISA STIG Apple macOS 13 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-13-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-001001 - The macOS system must generate audit records for all account creations, modifications, disabling, and termination events; privileged activities or other system-level access; all kernel module load, unload, and restart actions; all program initiations; and organizationally defined events for all nonlocal maintenance and diagnostic sessions.DISA STIG Apple macOS 13 v1r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE

APPL-13-001012 - The macOS system must be configured with audit log files owned by root.DISA STIG Apple macOS 13 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-13-001014 - The macOS system must be configured with audit log files group-owned by wheel.DISA STIG Apple macOS 13 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-13-001020 - The macOS system must audit the enforcement actions used to restrict access associated with changes to the system.DISA STIG Apple macOS 13 v1r5Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

APPL-13-001030 - The macOS system must provide an immediate warning to the System Administrator (SA) and Information System Security Officer (ISSO) (at a minimum) when allocated audit record storage volume reaches 75 percent of repository maximum audit record storage capacity.DISA STIG Apple macOS 13 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-13-001031 - The macOS system must provide an immediate real-time alert to the System Administrator (SA) and Information System Security Officer (ISSO), at a minimum, of all audit failure events requiring real-time alerts.DISA STIG Apple macOS 13 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-13-002001 - The macOS system must be configured to disable SMB File Sharing unless it is required.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-002016 - The macOS system must be configured to disable the iCloud Notes services.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-002038 - The macOS system must be configured to disable the "tftp" service.DISA STIG Apple macOS 13 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

APPL-13-002040 - The macOS system must disable iCloud Keychain synchronization.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-003009 - The macOS system must prohibit password reuse for a minimum of five generations.DISA STIG Apple macOS 13 v1r5Unix

IDENTIFICATION AND AUTHENTICATION

APPL-13-003012 - The macOS system must be configured to prevent displaying password hints.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

GOOG-12-006100 - Google Android 12 must be configured to not allow passwords that include more than two repeating or sequential characters - Complex CharactersMobileIron - DISA Google Android 12 COBO v1r2MDM

CONFIGURATION MANAGEMENT

GOOG-12-006100 - Google Android 12 must be configured to not allow passwords that include more than two repeating or sequential characters - NumbersAirWatch - DISA Google Android 12 COPE v1r2MDM

CONFIGURATION MANAGEMENT