Item Search

NameAudit NamePluginCategory
1.1 Ensure All Apple-provided Software Is CurrentCIS Apple macOS 13.0 Ventura Cloud-tailored v1.1.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1 Ensure All Apple-provided Software Is CurrentCIS Apple macOS 14.0 Sonoma Cloud-tailored v1.1.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.1 Ensure All Apple-provided Software Is CurrentCIS Apple macOS 15.0 Sequoia Cloud-tailored v1.0.0 L1Unix

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.1.1.2 Audit iCloud DriveCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.1.1.5 Audit Freeform Sync to iCloudCIS Apple macOS 15.0 Sequoia v2.1.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.3.2 Ensure Screen Saver Corners Are Secure - br-cornerCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

ACCESS CONTROL

2.3.3.11 Ensure Computer Name Does Not Contain PII or Protected Organizational InformationCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, PROGRAM MANAGEMENT

2.3.3.11 Ensure Computer Name Does Not Contain PII or Protected Organizational InformationCIS Apple macOS 15.0 Sequoia v2.1.0 L2Unix

CONFIGURATION MANAGEMENT, PROGRAM MANAGEMENT

2.3.4.1 Ensure Backup Automatically is Enabled If Time Machine Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONTINGENCY PLANNING

2.3.4.1 Ensure Backup Automatically is Enabled If Time Machine Is EnabledCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

CONTINGENCY PLANNING

2.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterAirWatch - CIS Apple iPadOS 18 v2.0.0 L1 End User OwnedMDM

IDENTIFICATION AND AUTHENTICATION

2.4.5 Disable Remote LoginCIS Apple macOS 10.12 L1 v1.2.0Unix

ACCESS CONTROL

2.4.5 Ensure Remote Login Is DisabledCIS Apple macOS 11.0 Big Sur v4.0.0 L1Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.4.6 Ensure 'Maximum number of failed attempts' is set to '6'MobileIron - CIS Apple iPadOS 17 v1.1.0 End User Owned L1MDM

ACCESS CONTROL

2.5.4 Audit Location Services AccessCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.1.1 Audit iCloud KeychainCIS Apple macOS 12.0 Monterey v4.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.1.2 Audit iCloud DriveCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.1.2 Audit iCloud DriveCIS Apple macOS 12.0 Monterey v4.0.0 L2Unix

ACCESS CONTROL, CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.1.2 Ensure 'Show Location Icon in Control Center when System Services Request Your Location' Is EnabledCIS Apple macOS 26 Tahoe v1.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.1.2 Ensure 'Show Location Icon in Control Center when System Services Request Your Location' Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.6.2 Audit App Store Password SettingsCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.8.3 Ensure the OS is not Activate When Resuming from Sleep - Apple DestroyFVKeyOnStandbyCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.8.3 Ensure the OS is not Activate When Resuming from Sleep - Intel DestroyFVKeyOnStandbyCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.9.1.2 Ensure Sleep and Display Sleep Is Enabled on Apple Silicon DevicesCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.10.1.1 Ensure the OS Is Not Active When Resuming from Standby (Intel)CIS Apple macOS 26 Tahoe v1.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

2.10.1.1 Ensure the OS Is Not Active When Resuming from Standby (Intel)CIS Apple macOS 15.0 Sequoia v2.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2 Ensure Security Auditing Flags For User-Attributable Events Are Configured Per Local Organizational RequirementsCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

3.2 Ensure Security Auditing Flags For User-Attributable Events Are Configured Per Local Organizational RequirementsCIS Apple macOS 12.0 Monterey v4.0.0 L2Unix

ACCESS CONTROL, AUDIT AND ACCOUNTABILITY

3.2.1.10 Ensure 'Force encrypted backups' is set to 'Enabled'MobileIron - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

CONTINGENCY PLANNING

3.2.1.22 Ensure 'Allow Handoff' is set to 'Disabled'AirWatch - CIS Apple iOS 14 and iPadOS 14 Institution Owned L1MDM

ACCESS CONTROL

3.4.3 Ensure 'Minimum passcode length' is set to a value of '6' or greaterMobileIron - CIS Apple iPadOS 26 v1.0.0 L1 Institutionally OwnedMDM

IDENTIFICATION AND AUTHENTICATION

3.7 Audit Software InventoryCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

CONFIGURATION MANAGEMENT, MAINTENANCE

5.1.7 Ensure No World Writable Folders Exist in the Library FolderCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

ACCESS CONTROL, MEDIA PROTECTION

5.1.7 Ensure No World Writable Folders Exist in the Library FolderCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

ACCESS CONTROL, MEDIA PROTECTION

5.2.3 Ensure Complex Password Must Contain Alphabetic Characters Is ConfiguredCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.4 Ensure Complex Password Must Contain Numeric Character Is ConfiguredCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.5 Ensure Complex Password Must Contain Special Character Is ConfiguredCIS Apple macOS 26 Tahoe v1.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.5 Ensure Complex Password Must Contain Special Character Is ConfiguredCIS Apple macOS 12.0 Monterey v4.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.5 Ensure Complex Password Must Contain Special Character Is ConfiguredCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.2.6 Ensure Complex Password Must Contain Uppercase and Lowercase Characters Is ConfiguredCIS Apple macOS 13.0 Ventura v4.0.0 L2Unix

IDENTIFICATION AND AUTHENTICATION

5.3.3 Audit Connected FAT32 and ExFAT DrivesCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.3.3 Audit Connected FAT32 and ExFAT DrivesCIS Apple macOS 15.0 Sequoia v2.1.0 L2Unix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.2.1 Ensure Protect Mail Activity in Mail Is EnabledCIS Apple macOS 14.0 Sonoma v3.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.2 Audit History and Remove History ItemsCIS Apple macOS 26 Tahoe v1.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

6.3.5 Audit Hide IP Address in Safari SettingCIS Apple macOS 26 Tahoe v1.1.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

7.2.2 Audit History and Remove History ItemsCIS Apple macOS 10.15 Catalina v3.0.0 L2Unix

CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION

AIOS-26-013300 - Apple iOS/iPadOS 26 must disable 'Allow USB drive access in Files app' if the authorizing official (AO) has not approved the use of DOD-approved USB storage drives with iOS/iPadOS devices - Allow USB drive access in Files app if the Authorizing Official (AO) has not approved the use of DoD-approved USB storage drives with iOS/iPadOS devices.MobileIron - DISA Apple iOS/iPadOS 26 v1r3MDM

SYSTEM AND COMMUNICATIONS PROTECTION

Big Sur - Enable Firmware PasswordNIST macOS Big Sur v1.4.0 - 800-53r5 ModerateUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Monterey - Enable Firmware PasswordNIST macOS Monterey v1.0.0 - 800-53r5 ModerateUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT

Monterey - Enable Firmware PasswordNIST macOS Monterey v1.0.0 - All ProfilesUnix

ACCESS CONTROL, CONFIGURATION MANAGEMENT