Item Search

NameAudit NamePluginCategory
APPL-26-000003 - The macOS system must enforce session lock no more than five seconds after screen saver is started.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-000009 - The macOS system must prevent AdminHostInfo from being available at LoginWindow.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-000022 - The macOS system must limit consecutive failed login attempts to three.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-000030 - The macOS system must configure audit log files to not contain access control lists (ACLs).DISA Apple macOS 26 Tahoe STIG v1r3Unix

AUDIT AND ACCOUNTABILITY

APPL-26-000054 - The macOS system must limit SSHD to FIPS-compliant connections.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-26-000057 - The macOS system must limit SSH to FIPS-compliant connections.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

APPL-26-000070 - The macOS system must enforce screen saver timeout.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-000090 - The macOS system must disable login to other users' active and locked sessions.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

APPL-26-000110 - The macOS system must configure the SSH ServerAliveInterval to 900.DISA Apple macOS 26 Tahoe STIG v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-26-000140 - The macOS system must set SSH Active Server Alive Maximum to 0.DISA Apple macOS 26 Tahoe STIG v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-26-001013 - The macOS system must configure audit log folders to be owned by root.DISA Apple macOS 26 Tahoe STIG v1r3Unix

AUDIT AND ACCOUNTABILITY

APPL-26-001015 - The macOS system must configure the audit log folders group to wheel.DISA Apple macOS 26 Tahoe STIG v1r3Unix

AUDIT AND ACCOUNTABILITY

APPL-26-001031 - The macOS system must configure audit failure notification.DISA Apple macOS 26 Tahoe STIG v1r3Unix

AUDIT AND ACCOUNTABILITY

APPL-26-001044 - The macOS system must be configured to audit all authorization and authentication events.DISA Apple macOS 26 Tahoe STIG v1r3Unix

AUDIT AND ACCOUNTABILITY, MAINTENANCE

APPL-26-002003 - The macOS system must disable Network File System (NFS) service.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-002005 - The macOS system must disable Bonjour multicast.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002006 - The macOS system must disable Unix-to-Unix Copy Protocol (UUCP) service.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-002007 - The macOS system must disable Internet Sharing.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002009 - The macOS system must disable AirDrop.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

APPL-26-002012 - The macOS system must disable the iCloud Calendar services.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002016 - The macOS system must disable iCloud Notes.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002022 - The macOS system must disable Remote Apple Events.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

APPL-26-002023 - The macOS system must disable sending audio recordings and transcripts to Apple.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002036 - The macOS system must disable Privacy Setup services during Setup Assistant.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002041 - The macOS system must disable iCloud Document Sync.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002042 - The macOS system must disable iCloud Bookmarks.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002064 - The macOS system must enable gatekeeper.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002069 - The macOS system must require an administrator password to modify systemwide preferences.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-002100 - The macOS system must disable Media Sharing.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-002110 - The macOS system must disable Bluetooth Sharing.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

APPL-26-002170 - The macOS system must disable iCloud Private Relay.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002180 - The macOS system must disable Find My service.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002200 - The macOS system must disable Personalized Advertising.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002210 - The macOS system must disable sending Siri and Dictation information to Apple.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002220 - The macOS system must enforce On Device Dictation.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002260 - The macOS system must disable the Bluetooth System Settings pane.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-002271 - The macOS system must disable iPhone Mirroring.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

APPL-26-003007 - The macOS system must require that passwords contain a minimum of one numeric character.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

APPL-26-003014 - The macOS system must remove password hints from user accounts.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

APPL-26-003080 - The macOS system must disable accounts after 35 days of inactivity.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-004001 - The macOS system must configure Apple System Log (ASL) files owned by root and group to wheel.DISA Apple macOS 26 Tahoe STIG v1r3Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-26-004002 - The macOS system must configure Apple System Log (ASL) files to mode 640 or less permissive.DISA Apple macOS 26 Tahoe STIG v1r3Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-26-004022 - The macOS system must require users to reauthenticate for privilege escalation when using the "sudo" command.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

APPL-26-004030 - The macOS system must configure system log files owned by root and group to wheel.DISA Apple macOS 26 Tahoe STIG v1r3Unix

SYSTEM AND INFORMATION INTEGRITY

APPL-26-005020 - The macOS system must enforce FileVault.DISA Apple macOS 26 Tahoe STIG v1r3Unix

SYSTEM AND COMMUNICATIONS PROTECTION

APPL-26-005052 - The macOS system must configure the login window to prompt for username and password.DISA Apple macOS 26 Tahoe STIG v1r3Unix

IDENTIFICATION AND AUTHENTICATION

APPL-26-005060 - The macOS system must disable proximity-based password sharing requests.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-005070 - The macOS system must enable Authenticated Root.DISA Apple macOS 26 Tahoe STIG v1r3Unix

ACCESS CONTROL

APPL-26-005110 - The macOS system must enforce enrollment in Mobile Device Management (MDM).DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT

APPL-26-005140 - The macOS system must disable Genmoji AI Creation.DISA Apple macOS 26 Tahoe STIG v1r3Unix

CONFIGURATION MANAGEMENT