Item Search

NameAudit NamePluginCategory
2.9.4 Ensure Writing Tools Is DisabledAirWatch - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.9.4 Ensure Writing Tools Is DisabledMobileIron - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.10.4 Ensure Writing Tools Is DisabledAirWatch - CIS Apple iOS 26 v1.0.0 L1 Institution OwnedMDM

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

APPL-11-000014 - The macOS system must, for networked systems, compare internal information system clocks at least every 24 hours with a server that is synchronized to one of the redundant United States Naval Observatory (USNO) time servers or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet) and/or the Global Positioning System (GPS) - Network Time ServerDISA STIG Apple macOS 11 v1r8Unix

AUDIT AND ACCOUNTABILITY

APPL-11-000015 - The macOS system must utilize an Endpoint Security Solution (ESS) and implement all DoD required modules.DISA STIG Apple macOS 11 v1r8Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-11-000052 - The macOS system must be configured with the SSH daemon ClientAliveCountMax option set to 0.DISA STIG Apple macOS 11 v1r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-11-000054 - The macOS system must implement approved ciphers to protect the confidentiality of SSH connections.DISA STIG Apple macOS 11 v1r8Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-11-001020 - The macOS system must audit the enforcement actions used to restrict access associated with changes to the system - fmDISA STIG Apple macOS 11 v1r8Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

APPL-11-001044 - The macOS system must generate audit records for DoD-defined events such as successful/unsuccessful logon attempts, successful/unsuccessful direct access attempts, starting and ending time for user access, and concurrent logons to the same account from different sources.DISA STIG Apple macOS 11 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-11-002001 - The macOS system must be configured to disable SMB File Sharing unless it is required.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002007 - The macOS system must be configured to disable Internet Sharing.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002015 - The macOS system must be configured to disable the Mail iCloud services.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002017 - The macOS system must cover or disable the built-in or attached camera when not in use.DISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-11-002020 - The macOS system must be configured to disable Siri and dictation - Ironwood AllowedDISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002021 - The macOS system must be configured to disable sending diagnostic and usage data to Apple.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002032 - The macOS system must be configured to disable the system preference pane for Internet Accounts - HiddenPreferencePanesDISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002036 - The macOS system must be configured to disable the Privacy Setup services.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002038 - Apple macOS must be configured to disable the tftp service.DISA STIG Apple macOS 11 v1r8Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-002039 - The macOS system must be configured to disable the Siri Setup services.DISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002043 - The macOS system must disable iCloud photo library.DISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002053 - The macOS system must be configured to disable the system preference pane for Siri - DisabledPreferencePanesDISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002053 - The macOS system must be configured to disable the system preference pane for Siri - HiddenPreferencePanesDISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002062 - The macOS system must be configured with Bluetooth turned off unless approved by the organization - DisabledPreferencesPanesDISA STIG Apple macOS 11 v1r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-11-002066 - The macOS system must not allow an unattended or automatic logon to the system.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002068 - The macOS system must set permissions on user home directories to prevent users from having access to read or modify another user's files - User directory home permissionsDISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-002068 - The macOS system must set permissions on user home directories to prevent users from having access to read or modify another user's files - User directory permissionsDISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-002069 - The macOS system must authenticate peripherals before establishing a connection.DISA STIG Apple macOS 11 v1r8Unix

IDENTIFICATION AND AUTHENTICATION

APPL-11-003001 - The macOS system must issue or obtain public key certificates under an appropriate certificate policy from an approved service provider.DISA STIG Apple macOS 11 v1r8Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-11-003013 - Apple macOS must be configured with a firmware password to prevent access to single user mode and booting from alternative media.DISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-003013 - Apple macOS must be configured with a firmware password to prevent access to single user mode and booting from alternative media.DISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-11-003052 - The macOS system must be configured so that the sudo command requires smart card authentication.DISA STIG Apple macOS 11 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-11-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - newsyslogDISA STIG Apple macOS 11 v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-11-004001 - The macOS system must be configured with system log files owned by root and group-owned by wheel or admin - newsyslogDISA STIG Apple macOS 11 v1r8Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-11-005001 - The macOS system must enable System Integrity Protection.DISA STIG Apple macOS 11 v1r5Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

APPL-11-005001 - The macOS system must enable System Integrity Protection.DISA STIG Apple macOS 11 v1r8Unix

AUDIT AND ACCOUNTABILITY, CONFIGURATION MANAGEMENT

APPL-11-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.DISA STIG Apple macOS 11 v1r8Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-11-005050 - The macOS Application Firewall must be enabled - EnableFirewallDISA STIG Apple macOS 11 v1r8Unix

CONFIGURATION MANAGEMENT

APPL-13-000015 - The macOS system must use an Endpoint Security Solution (ESS) and implement all DOD required modules.DISA STIG Apple macOS 13 v1r5Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-13-000024 - The macOS system must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the system via SSH.DISA STIG Apple macOS 13 v1r5Unix

ACCESS CONTROL

APPL-13-001002 - The macOS system must monitor remote access methods and generate audit records when successful/unsuccessful attempts to access/modify privileges occur.DISA STIG Apple macOS 13 v1r5Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

APPL-13-001010 - The macOS system must shut down by default upon audit failure (unless availability is an overriding concern).DISA STIG Apple macOS 13 v1r5Unix

AUDIT AND ACCOUNTABILITY

APPL-13-002008 - The macOS system must be configured to disable Web Sharing.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-002009 - The macOS system must be configured to disable AirDrop.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-002013 - The macOS system must be configured to disable the iCloud Reminders services.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-002063 - The macOS system must disable the guest account.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-002069 - The macOS system must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.DISA STIG Apple macOS 13 v1r5Unix

ACCESS CONTROL

APPL-13-003050 - The macOS system must be configured so that the login command requires smart card authentication.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-005020 - The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.DISA STIG Apple macOS 13 v1r5Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-13-005051 - The macOS system must restrict the ability of individuals to use USB storage devices.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT

APPL-13-005054 - The macOS system must be configured to disable prompts to configure Touch ID.DISA STIG Apple macOS 13 v1r5Unix

CONFIGURATION MANAGEMENT