| 1.77 APPL-26-002024 | CIS Apple macOS 26 Tahoe STIG v1.0.0 CAT II | Unix | CONFIGURATION MANAGEMENT |
| APPL-13-005058 - The macOS system must be configured to prevent activity continuation between Apple devices. | DISA STIG Apple macOS 13 v1r5 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-000001 - The macOS system must prevent Apple Watch from terminating a session lock. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000002 - The macOS system must enforce screen saver password. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000005 - The macOS system must configure user session lock when a smart token is removed. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000012 - The macOS system must automatically remove or disable temporary or emergency user accounts within 72 hours. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000023 - The macOS system must display a policy banner at remote login. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000024 - The macOS system must enforce SSH to display a policy banner. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000025 - The macOS system must display the Standard Mandatory DOD Notice and Consent Banner at the login window. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000052 - The macOS system must configure SSHD ClientAliveCountMax to 1. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-000053 - The macOS system must set login grace time to 30. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-000060 - The macOS system must set account lockout time to 15 minutes. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000120 - The macOS system must configure SSHD channel timeout to 900. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-000130 - The macOS system must configure SSHD unused connection timeout to 900. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-000180 - The macOS system must enable the time synchronization daemon. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001001 - The macOS system must be configured to audit all administrative action events. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| APPL-26-001017 - The macOS system must configure audit log folders to mode 700 or less permissive. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001020 - The macOS system must be configured to audit all deletions of object attributes. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| APPL-26-001023 - The macOS system must be configured to audit all failed write actions on the system. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| APPL-26-001024 - The macOS system must be configured to audit all failed program execution on the system. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001030 - The macOS system must configure audit capacity warning. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001130 - The macOS system must configure audit_control owner to mode 440 or less permissive. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001140 - The macOS system must configure audit_control to not contain access control lists (ACLs). | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001150 - The macOS system must disable password authentication for SSH. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION, MAINTENANCE |
| APPL-26-002004 - The macOS system must disable Location Services. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002008 - The macOS system must disable the built-in web server. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-002015 - The macOS system must disable iCloud Mail. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002037 - The macOS system must disable iCloud storage setup during Setup Assistant. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002038 - The macOS system must disable Trivial File Transfer Protocol (TFTP) service. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION |
| APPL-26-002039 - The macOS system must disable Siri Setup during Setup Assistant. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002050 - The macOS system must disable Screen Sharing and Apple Remote Desktop. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-002052 - The macOS system must disable the System Settings pane for Wallet and Apple Pay. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002053 - The macOS system must disable the system settings pane for Siri. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002063 - The macOS system must disable the guest account. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002150 - The macOS system must disable iCloud Desktop and Document folder sync. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002160 - The macOS system must disable iCloud Game Center. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002250 - The macOS system must disable Remote Management. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002270 - The macOS system must disable the iCloud Freeform services. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-003011 - The macOS system must require that passwords contain a minimum of one special character. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003012 - The macOS system must disable password hints. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003030 - The macOS system must allow smart card authentication. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003051 - The macOS system must enforce multifactor authentication for the su command. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003052 - The macOS system must enforce multifactor authentication for privilege escalation through the sudo command. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003060 - The macOS system must require that passwords contain a minimum of one lowercase character and one uppercase character. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-004060 - The macOS system must configure sudoers timestamp type. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-005090 - The macOS system must authorize USB devices before allowing connection. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-005120 - The macOS system must enable Recovery Lock. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-005130 - The macOS system must enforce installation of XProtect Remediator and Gatekeeper updates automatically. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-999999 - The macOS system must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs). | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| Catalina - Enforce Apple Mobile File Integrity | NIST macOS Catalina v1.5.0 - 800-53r5 High | Unix | SYSTEM AND INFORMATION INTEGRITY |