| 1.2 Ensure Auto Update Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| 1.5 Ensure Install Application Updates from the App Store Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| 1.6 Ensure Install Security Responses and System Files Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY |
| 2.1.1.4 Audit Security Keys Used With Apple Accounts | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 2.1.1.5 Audit Freeform Sync to iCloud | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 2.1.1.6 Audit Find My Mac | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 2.2.2 Ensure Firewall Stealth Mode Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 2.3.3.6 Ensure Remote Apple Events Is Disabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 2.3.3.8 Ensure Content Caching Is Disabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | CONFIGURATION MANAGEMENT |
| 2.5.1 Ensure Siri Is Disabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 2.6.1.3 Audit Location Services Access | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 2.6.7 Audit Lockdown Mode | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | CONFIGURATION MANAGEMENT, MAINTENANCE |
| 2.6.8 Ensure an Administrator Password Is Required to Access System-Wide Preferences | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 2.8.1 Audit Universal Control Settings | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 2.9.3 Ensure Wake for Network Access Is Disabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 2.12.2 Ensure Guest Access to Shared Folders Is Disabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | ACCESS CONTROL, MEDIA PROTECTION |
| 2.14.1 Audit Game Center Settings | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | CONFIGURATION MANAGEMENT |
| 2.17.1 Audit Internet Accounts for Authorized Use | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 3.2 Ensure Security Auditing Flags For User-Attributable Events Are Configured Per Local Organizational Requirements | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY |
| 3.3 Ensure install.log Is Retained for 365 or More Days and No Maximum Size | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 3.4 Ensure Security Auditing Logs Are Retained for 30 Days | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | AUDIT AND ACCOUNTABILITY |
| 3.6 Ensure Firewall Logging Is Enabled and Configured | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | AUDIT AND ACCOUNTABILITY, SYSTEM AND COMMUNICATIONS PROTECTION |
| 4.1 Ensure Bonjour Advertising Services Is Disabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 4.2 Ensure HTTP Server Is Disabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 5.1.2 Ensure System Integrity Protection Status (SIP) Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND INFORMATION INTEGRITY |
| 5.1.3 Ensure Apple Mobile File Integrity (AMFI) Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 5.1.4 Ensure Signed System Volume (SSV) Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| 5.2.2 Ensure Password Minimum Length Is Configured | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.2.7 Ensure Password Age Is Configured | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | ACCESS CONTROL |
| 5.2.8 Ensure Password History Is Set to at least 24 | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | IDENTIFICATION AND AUTHENTICATION |
| 5.4 Ensure the Sudo Timeout Period Is Set to Zero | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | ACCESS CONTROL |
| 5.7 Ensure an Administrator Account Cannot Login to Another User's Active and Locked Session | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | ACCESS CONTROL |
| 5.9 Ensure the Guest Home Folder Does Not Exist | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION |
| 5.10 Ensure XProtect Is Running and Updated | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| 6.1.1 Audit Show All Filename Extensions | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| 6.3.2 Audit History and Remove History Items | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.3.3 Ensure Warn When Visiting A Fraudulent Website in Safari Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.3.5 Audit Hide IP Address in Safari Setting | CIS Apple macOS 14.0 Sonoma v3.1.0 L2 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.3.6 Ensure Advertising Privacy Protection in Safari Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.3.7 Ensure Show Full Website Address in Safari Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION |
| 6.4.1 Ensure Secure Keyboard Entry Terminal.app Is Enabled | CIS Apple macOS 14.0 Sonoma v3.1.0 L1 | Unix | CONFIGURATION MANAGEMENT |
| O365-WD-000019 - File validation in Word must be enabled. | DISA Microsoft Office 365 ProPlus STIG v3r5 | Windows | SYSTEM AND COMMUNICATIONS PROTECTION |
| Turn off file validation - enableonload - excel | MSCT Microsoft 365 Apps for Enterprise 2206 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Turn off file validation - enableonload - powerpoint | MSCT Microsoft 365 Apps for Enterprise 2112 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Turn off file validation - enableonload - powerpoint | MSCT Microsoft 365 Apps for Enterprise 2206 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| Turn off file validation - powerpoint | MSCT M365 Apps for enterprise 2412 v1.0.0 | Windows | CONFIGURATION MANAGEMENT |
| WN19-DC-000350 - Windows Server 2019 Add workstations to domain user right must only be assigned to the Administrators group on domain controllers. | DISA Microsoft Windows Server 2019 STIG v3r8 | Windows | ACCESS CONTROL |
| WN22-DC-000150 - Windows Server 2022 directory data (outside the root DSE) of a nonpublic directory must be configured to prevent anonymous access. | DISA Microsoft Windows Server 2022 STIG v2r8 | Windows | CONFIGURATION MANAGEMENT |
| WN25-DC-000150 - Windows Server 2025 directory data (outside the root DSE) of a nonpublic directory must be configured to prevent anonymous access. | DISA Microsoft Windows Server 2025 STIG v1r1 | Windows | CONFIGURATION MANAGEMENT |
| WN25-DC-000400 - The Windows Server 2025 'Deny log on locally' user right on domain controllers must be configured to prevent unauthenticated access. | DISA Microsoft Windows Server 2025 STIG v1r1 | Windows | ACCESS CONTROL |