| APPL-26-000003 - The macOS system must enforce session lock no more than five seconds after screen saver is started. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000009 - The macOS system must prevent AdminHostInfo from being available at LoginWindow. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000022 - The macOS system must limit consecutive failed login attempts to three. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000030 - The macOS system must configure audit log files to not contain access control lists (ACLs). | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-000054 - The macOS system must limit SSHD to FIPS-compliant connections. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE, SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-000057 - The macOS system must limit SSH to FIPS-compliant connections. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-000070 - The macOS system must enforce screen saver timeout. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000090 - The macOS system must disable login to other users' active and locked sessions. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-000110 - The macOS system must configure the SSH ServerAliveInterval to 900. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-000140 - The macOS system must set SSH Active Server Alive Maximum to 0. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-001013 - The macOS system must configure audit log folders to be owned by root. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001015 - The macOS system must configure the audit log folders group to wheel. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001031 - The macOS system must configure audit failure notification. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001044 - The macOS system must be configured to audit all authorization and authentication events. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| APPL-26-002003 - The macOS system must disable Network File System (NFS) service. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-002005 - The macOS system must disable Bonjour multicast. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002006 - The macOS system must disable Unix-to-Unix Copy Protocol (UUCP) service. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-002007 - The macOS system must disable Internet Sharing. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002009 - The macOS system must disable AirDrop. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-26-002012 - The macOS system must disable the iCloud Calendar services. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002016 - The macOS system must disable iCloud Notes. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002022 - The macOS system must disable Remote Apple Events. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-26-002023 - The macOS system must disable sending audio recordings and transcripts to Apple. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002036 - The macOS system must disable Privacy Setup services during Setup Assistant. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002041 - The macOS system must disable iCloud Document Sync. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002042 - The macOS system must disable iCloud Bookmarks. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002064 - The macOS system must enable gatekeeper. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002069 - The macOS system must require an administrator password to modify systemwide preferences. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-002100 - The macOS system must disable Media Sharing. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-002110 - The macOS system must disable Bluetooth Sharing. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-26-002170 - The macOS system must disable iCloud Private Relay. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002180 - The macOS system must disable Find My service. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002200 - The macOS system must disable Personalized Advertising. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002210 - The macOS system must disable sending Siri and Dictation information to Apple. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002220 - The macOS system must enforce On Device Dictation. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002260 - The macOS system must disable the Bluetooth System Settings pane. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002271 - The macOS system must disable iPhone Mirroring. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-26-003007 - The macOS system must require that passwords contain a minimum of one numeric character. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003014 - The macOS system must remove password hints from user accounts. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003080 - The macOS system must disable accounts after 35 days of inactivity. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-004001 - The macOS system must configure Apple System Log (ASL) files owned by root and group to wheel. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| APPL-26-004002 - The macOS system must configure Apple System Log (ASL) files to mode 640 or less permissive. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| APPL-26-004022 - The macOS system must require users to reauthenticate for privilege escalation when using the "sudo" command. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-004030 - The macOS system must configure system log files owned by root and group to wheel. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| APPL-26-005020 - The macOS system must enforce FileVault. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-005052 - The macOS system must configure the login window to prompt for username and password. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-005060 - The macOS system must disable proximity-based password sharing requests. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-005070 - The macOS system must enable Authenticated Root. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-005110 - The macOS system must enforce enrollment in Mobile Device Management (MDM). | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-005140 - The macOS system must disable Genmoji AI Creation. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |