Item Search

NameAudit NamePluginCategory
1.156 APPL-26-005150CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

1.157 APPL-26-005160CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.1.1.1 Audit iCloud Passwords & KeychainCIS Apple macOS 26 Tahoe v1.1.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.11 Java 6 is not the default Java runtimeCIS Apple macOS 10.12 L2 v1.2.0Unix

CONFIGURATION MANAGEMENT

APPL-12-000002 - The macOS system must retain the session lock until the user reestablishes access using established identification and authentication procedures.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000003 - The macOS system must initiate the session lock no more than five seconds after a screen saver is started.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000005 - The macOS system must be configured to lock the user session when a smart token is removed.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000006 - The macOS system must conceal, via the session lock, information previously visible on the display with a publicly viewable image.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000007 - The macOS system must be configured to disable hot corners.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000012 - The macOS system must automatically remove or disable temporary and emergency user accounts after 72 hours.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000014 - The macOS system must, for networked systems, compare internal information system clocks at least every 24 hours with a server that is synchronized to one of the redundant United States Naval Observatory (USNO) time servers or a time server designated for the appropriate DoD network (NIPRNet/SIPRNet) and/or the Global Positioning System (GPS).DISA STIG Apple macOS 12 v1r9Unix

AUDIT AND ACCOUNTABILITY

APPL-12-000015 - The macOS system must utilize an ESS solution and implement all DoD required modules - ESS and implement all DoD required modules.DISA STIG Apple macOS 12 v1r9Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-12-000023 - The macOS system must display the Standard Mandatory DoD Notice and Consent Banner before granting remote access to the operating system.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000024 - The macOS system must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the system via SSH.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL

APPL-12-000052 - The macOS system must be configured with the SSH daemon ClientAliveCountMax option set to 1.DISA STIG Apple macOS 12 v1r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-000053 - The macOS system must be configured with the SSH daemon LoginGraceTime set to 30 or less.DISA STIG Apple macOS 12 v1r9Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-000056 - The macOS system must implement approved Key Exchange Algorithms within the SSH server configuration.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-000057 - The macOS system must implement approved ciphers within the SSH client configuration to protect the confidentiality of SSH connections.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-000058 - The macOS system must implement approved Message Authentication Codes (MACs) within the SSH client configuration.DISA STIG Apple macOS 12 v1r9Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE

APPL-12-001016 - The macOS system must be configured with audit log files set to mode 440 or less permissive.DISA STIG Apple macOS 12 v1r9Unix

AUDIT AND ACCOUNTABILITY

APPL-12-001017 - The macOS system must be configured with audit log folders set to mode 700 or less permissive.DISA STIG Apple macOS 12 v1r9Unix

AUDIT AND ACCOUNTABILITY

APPL-12-002003 - The macOS system must be configured to disable the Network File System (NFS) daemon unless it is required.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002004 - The macOS system must be configured to disable Location Services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002009 - The macOS system must be configured to disable AirDrop.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002013 - The macOS system must be configured to disable the iCloud Reminders services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002014 - The macOS system must be configured to disable iCloud Address Book services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002016 - The macOS system must be configured to disable the iCloud Notes services.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002064 - The macOS system must have the security assessment policy subsystem enabled.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002066 - The macOS system must not allow an unattended or automatic logon to the system.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-002068 - The macOS system must set permissions on user home directories to prevent users from having access to read or modify another user's files.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-003001 - The macOS system must issue or obtain public key certificates under an appropriate certificate policy from an approved service provider.DISA STIG Apple macOS 12 v1r9Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-12-003052 - The macOS system must be configured so that the sudo command requires smart card authentication.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-12-004002 - The macOS system must be configured with system log files set to mode 640 or less permissive.DISA STIG Apple macOS 12 v1r9Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-12-005051 - The macOS system must restrict the ability to utilize external writeable media devices.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION

APPL-12-005060 - The macOS system must be configured to prevent password proximity sharing requests from nearby Apple Devices.DISA STIG Apple macOS 12 v1r9Unix

CONFIGURATION MANAGEMENT

APPL-15-005150 - The macOS system must disable Apple Intelligence Image Generation.DISA Apple macOS 15 Sequoia STIG v1r7Unix

CONFIGURATION MANAGEMENT

APPL-15-005160 - The macOS system must disable Apple Intelligence Writing Tools.DISA Apple macOS 15 Sequoia STIG v1r7Unix

CONFIGURATION MANAGEMENT

APPL-26-005150 - The macOS system must disable Apple Intelligence Image Playground.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

Big Sur - Disable Apple ID Setup during Setup AssistantNIST macOS Big Sur v1.4.0 - 800-53r4 HighUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Big Sur - Disable Apple ID Setup during Setup AssistantNIST macOS Big Sur v1.4.0 - 800-53r4 LowUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Big Sur - Disable Apple ID Setup during Setup AssistantNIST macOS Big Sur v1.4.0 - 800-53r4 ModerateUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Big Sur - Disable Apple ID Setup during Setup AssistantNIST macOS Big Sur v1.4.0 - 800-53r5 ModerateUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Big Sur - Disable Apple ID Setup during Setup AssistantNIST macOS Big Sur v1.4.0 - All ProfilesUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Big Sur - Disable Apple ID Setup during Setup AssistantNIST macOS Big Sur v1.4.0 - CNSSI 1253Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Catalina - Disable Apple ID Setup during Setup AssistantNIST macOS Catalina v1.5.0 - 800-53r5 HighUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Monterey - Disable Apple ID Setup during Setup AssistantNIST macOS Monterey v1.0.0 - 800-53r4 HighUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Monterey - Disable Apple ID Setup during Setup AssistantNIST macOS Monterey v1.0.0 - 800-53r4 LowUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Monterey - Disable Apple ID Setup during Setup AssistantNIST macOS Monterey v1.0.0 - 800-53r4 ModerateUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Monterey - Disable Apple ID Setup during Setup AssistantNIST macOS Monterey v1.0.0 - 800-53r5 LowUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT