| 3.1 Ensure Security Auditing Is Enabled | CIS Apple macOS 14.0 Sonoma Cloud-tailored v1.1.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-000024 - The macOS system must enforce SSH to display the Standard Mandatory DOD Notice and Consent Banner. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL |
| APPL-14-000052 - The macOS system must configure SSHD ClientAliveCountMax to 1. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-14-000057 - The macOS system must limit SSH to FIPS-compliant connections. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-14-001010 - The macOS system must configure system to shut down upon audit failure. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-001012 - The macOS system must configure audit log files to be owned by root. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-001015 - The macOS system must configure audit log folders group to wheel. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-001016 - The macOS system must configure audit log files to mode 440 or less permissive. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-001023 - The macOS system must be configured to audit all failed write actions on the system. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-001031 - The macOS system must configure audit failure notification. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-001100 - The macOS system must disable root logon for SSH. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| APPL-14-001110 - The macOS system must configure audit_control group to wheel. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-001120 - The macOS system must configure audit_control owner to root. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-001140 - The macOS system must configure audit_control to not contain access control lists. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-002001 - The macOS system must disable Server Message Block sharing. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL |
| APPL-14-002003 - The macOS system must disable Network File System service. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL |
| APPL-14-002008 - The macOS system must disable the built-in web server. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL |
| APPL-14-002009 - The macOS system must disable AirDrop. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-14-002010 - The macOS system must disable FaceTime.app. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002012 - The macOS system must disable the iCloud Calendar services. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002015 - The macOS system must disable iCloud Mail. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002020 - The macOS system must disable Siri. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002021 - The macOS system must disable sending diagnostic and usage data to Apple. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| APPL-14-002037 - The macOS system must disable iCloud Storage Setup during Setup Assistant. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002041 - The macOS system must disable iCloud Document synchronization. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002042 - The macOS system must disable iCloud Bookmarks. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002052 - The macOS system must disable the System Settings pane for Wallet and Apple Pay. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002062 - The macOS system must disable Bluetooth when no approved device is connected. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-14-002063 - The macOS system must disable the guest account. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002066 - The macOS system must disable unattended or automatic log on to the system. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002080 - The macOS system must disable Airplay Receiver. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-14-002090 - The macOS system must disable TouchID for unlocking the device. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL |
| APPL-14-002100 - The macOS system must disable Media Sharing. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL |
| APPL-14-002110 - The macOS system must disable Bluetooth sharing. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-14-002120 - The macOS system must disable AppleID and Internet Account modifications. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002140 - The macOS system must disable content caching service. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002190 - The macOS system must disable password autofill. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002200 - The macOS system must disable personalized advertising. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002210 - The macOS system must disable sending Siri and Dictation information to Apple. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002220 - The macOS system must enforce on device dictation. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002240 - The macOS system must disable Printer Sharing. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-002270 - The macOS system must disable the iCloud Freeform services. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-003012 - The macOS system must disable password hints. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-14-004040 - The macOS system must configure system log files to mode 640 or less permissive. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| APPL-14-004050 - The macOS system must configure install.log retention to 365. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-14-005001 - The macOS system must ensure System Integrity Protection is enabled. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT |
| APPL-14-005050 - The macOS system must enable the application firewall. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-005058 - The macOS system must disable Handoff. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-14-005110 - The macOS system must enforce enrollment in mobile device management. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |
| APPL-14-005130 - The macOS system must enforce installation of XProtect Remediator and Gatekeeper updates automatically. | DISA Apple macOS 14 Sonoma STIG v2r4 | Unix | CONFIGURATION MANAGEMENT |