Item Search

NameAudit NamePluginCategory
2.1.1 Ensure a 'Consent Message' has been 'Configured'AirWatch - CIS Apple iOS 17 Benchmark v1.1.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.1.1 Ensure a 'Consent Message' has been 'Configured'MobileIron - CIS Apple iOS 18 v1.0.0 L1 End User OwnedMDM

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.1.1 Ensure a 'Consent Message' has been 'Configured'MobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.2.2.1 Ensure 'Force fraud warning' is set to 'Enabled'AirWatch - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.2.1 Ensure 'Force fraud warning' is set to 'Enabled'MobileIron - CIS Apple iPadOS 18 v1.0.0 L1 End User OwnedMDM

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.2.2.1 Ensure 'Force fraud warning' is set to 'Enabled'MobileIron - CIS Apple iOS 18 v1.0.0 L1 End User OwnedMDM

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

2.3.2 Ensure Screen Saver Corners Are Secure - top left cornerCIS Apple macOS 10.14 v2.0.0 L2Unix

ACCESS CONTROL

2.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 v1.0.0 End User Owned L1MDM

CONFIGURATION MANAGEMENT

2.4.3 Ensure 'Maximum Auto-Lock' is set to '2 minutes' or lessMobileIron - CIS Apple iOS 13 and iPadOS 13 v1.0.0 End User Owned L1MDM

ACCESS CONTROL

2.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'MobileIron - CIS Apple iOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'MobileIron - CIS Apple iPadOS 18 v1.0.0 L1 End User OwnedMDM

ACCESS CONTROL

2.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'AirWatch - CIS Apple iOS 17 Benchmark v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'AirWatch - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'AirWatch - CIS Apple iPadOS 18 v1.0.0 L1 End User OwnedMDM

ACCESS CONTROL

2.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'MobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.5.7 Monitor Location Services AccessCIS Apple macOS 10.13 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

2.6.3 iCloud DriveCIS Apple macOS 10.13 L2 v1.1.0Unix

ACCESS CONTROL

3.2 Configure Security Auditing Flags per local organizational requirements - 'audit successful/failed file attribute modification events'CIS Apple macOS 10.13 L2 v1.1.0Unix

AUDIT AND ACCOUNTABILITY

3.2 Ensure Security Auditing Flags Are Configured Per Local Organizational Requirements - 'audit successful/failed administrative events'CIS Apple macOS 10.14 v2.0.0 L2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

3.2.1.5 Ensure 'Allow iCloud documents & data' is set to 'Disabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

ACCESS CONTROL

3.2.1.10 Ensure 'Force encrypted backups' is set to 'Enabled'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1.10 Ensure 'Force encrypted backups' is set to 'Enabled'MobileIron - CIS Apple iPadOS 17 Institutionally Owned L1MDM

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1.10 Ensure 'Force encrypted backups' is set to 'Enabled'MobileIron - CIS Apple iPadOS 18 v1.0.0 L1 Institutionally OwnedMDM

CONTINGENCY PLANNING, SYSTEM AND COMMUNICATIONS PROTECTION

3.2.1.14 Ensure 'Allow installing configuration profiles' is set to 'Disabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.2.1.15 Ensure 'Allow adding VPN configurations' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

3.2.1.15 Ensure 'Allow adding VPN configurations' is set to 'Disabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

SYSTEM AND INFORMATION INTEGRITY

3.2.1.24 Ensure 'Allow Handoff' is set to 'Disabled'AirWatch - CIS Apple iOS 18 v1.0.0 L1 Institution OwnedMDM

ACCESS CONTROL, MEDIA PROTECTION

3.2.1.24 Ensure 'Allow Handoff' is set to 'Disabled'AirWatch - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL, MEDIA PROTECTION

3.2.1.24 Ensure 'Allow Handoff' is set to 'Disabled'MobileIron - CIS Apple iOS 17 Institution Owned L1MDM

ACCESS CONTROL, MEDIA PROTECTION

3.2.1.24 Ensure 'Allow Handoff' is set to 'Disabled'AirWatch - CIS Apple iPadOS 18 v1.0.0 L1 Institutionally OwnedMDM

ACCESS CONTROL, MEDIA PROTECTION

3.2.2.1 Ensure 'Force fraud warning' is set to 'Enabled'MobileIron - CIS Apple iPadOS 17 Institutionally Owned L1MDM

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.2.1 Ensure 'Force fraud warning' is set to 'Enabled'MobileIron - CIS Apple iOS 18 v1.0.0 L1 Institution OwnedMDM

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iOS 12 v1.0.0 Institution Owned L1MDM

IDENTIFICATION AND AUTHENTICATION

3.4.1 Ensure 'Allow simple value' is set to 'Disabled'MobileIron - CIS Apple iOS 13 and iPadOS 13 Institution Owned L1MDM

CONFIGURATION MANAGEMENT

3.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'MobileIron - CIS Apple iPadOS 17 Institutionally Owned L1MDM

ACCESS CONTROL

3.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'AirWatch - CIS Apple iPadOS 17 Institutionally Owned L1MDM

ACCESS CONTROL

3.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'MobileIron - CIS Apple iOS 18 v1.0.0 L1 Institution OwnedMDM

ACCESS CONTROL

3.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'AirWatch - CIS Apple iPadOS 18 v1.0.0 L1 Institutionally OwnedMDM

ACCESS CONTROL

3.4.5 Ensure 'Maximum grace period for device lock' is set to 'Immediately'MobileIron - CIS Apple iPadOS 18 v1.0.0 L1 Institutionally OwnedMDM

ACCESS CONTROL

3.6.1 Ensure 'Allow user to move messages from this account' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

ACCESS CONTROL

4.1 Disable Bonjour advertising serviceCIS Apple macOS 10.13 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

4.3 Create network specific locationsCIS Apple macOS 10.13 L2 v1.1.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

5.2.6 Ensure Complex Password Must Contain Uppercase and Lowercase Characters Is ConfiguredCIS Apple macOS 10.14 v2.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.9 Ensure system is set to hibernate - standbydelaylowCIS Apple macOS 10.14 v2.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

5.14 Create a Login window bannerCIS Apple macOS 10.13 L2 v1.1.0Unix

ACCESS CONTROL

5.16 Disable Fast User SwitchingCIS Apple macOS 10.13 L2 v1.1.0Unix

ACCESS CONTROL

7.8 Extensible Firmware Interface (EFI) passwordCIS Apple macOS 10.13 L2 v1.1.0Unix

CONFIGURATION MANAGEMENT

Big Sur - Ensure the System Implements Malicious Code Protection MechanismsNIST macOS Big Sur v1.4.0 - 800-53r5 ModerateUnix

SYSTEM AND INFORMATION INTEGRITY

Monterey - Ensure the System Implements Malicious Code Protection MechanismsNIST macOS Monterey v1.0.0 - 800-53r5 LowUnix

SYSTEM AND INFORMATION INTEGRITY

Monterey - Ensure the System Implements Malicious Code Protection MechanismsNIST macOS Monterey v1.0.0 - All ProfilesUnix

SYSTEM AND INFORMATION INTEGRITY