| APPL-26-000031 - The macOS system must configure the audit log folder to not contain access control lists (ACLs). | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-000033 - The macOS system must disable FileVault automatic login. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000051 - The macOS system must configure SSHD ClientAliveInterval to 900. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-000100 - The macOS system must disable root login. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| APPL-26-000160 - The macOS system must enforce auto logout after 86400 seconds of inactivity. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-000170 - The macOS system must be configured to use an authorized time server. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-000190 - The macOS system must configure sudo to log events. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001002 - The macOS system must be configured to audit all login and logout events. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| APPL-26-001003 - The macOS system must enable security auditing. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| APPL-26-001012 - The macOS system must configure audit log files to be owned by root. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001014 - The macOS system must configure the audit log files group to wheel. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001016 - The macOS system must configure audit log files to mode 440 or less permissive. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001021 - The macOS system must be configured to audit all changes of object attributes. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| APPL-26-001022 - The macOS system must be configured to audit all failed read actions on the system. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY, MAINTENANCE |
| APPL-26-001029 - The macOS system must configure audit retention to seven days. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001060 - The macOS system must set smart card certificate trust to moderate. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-001100 - The macOS system must disable root login for SSH. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-001110 - The macOS system must configure audit_control group to wheel. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-001120 - The macOS system must configure audit_control owner to root. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-002001 - The macOS system must disable Server Message Block (SMB) sharing. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-002010 - The macOS system must disable FaceTime.app. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002013 - The macOS system must disable iCloud Reminders. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002014 - The macOS system must disable iCloud Address Book. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002017 - The macOS system must disable the camera. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002020 - The macOS system must disable Siri. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002021 - The macOS system must disable sending diagnostic and usage data to Apple. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND INFORMATION INTEGRITY |
| APPL-26-002024 - The macOS system must disable sending search data from Spotlight to Apple. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002040 - The macOS system must disable iCloud Keychain Sync. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002043 - The macOS system must disable iCloud Photo Library. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002060 - The macOS system must apply gatekeeper settings to block applications from unidentified developers. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002062 - The macOS system must disable Bluetooth when no approved device is connected. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-002066 - The macOS system must disable unattended or automatic login to the system. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT, IDENTIFICATION AND AUTHENTICATION |
| APPL-26-002068 - The macOS system must secure users' home folders. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002080 - The macOS system must disable Airplay Receiver. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-26-002090 - The macOS system must disable TouchID for unlocking the device. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL |
| APPL-26-002120 - The macOS system must disable AppleID and internet Account Modification. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002140 - The macOS system must disable Content Caching service. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002230 - The macOS system must disable Dictation. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-002240 - The macOS system must disable Printer Sharing. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-003001 - The macOS system must issue or obtain public key certificates from an approved service provider. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND COMMUNICATIONS PROTECTION |
| APPL-26-003008 - The macOS system must restrict maximum password lifetime to 60 days. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003010 - The macOS system must require a minimum password length of 14 characters. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-003020 - The macOS system must enforce smart card authentication. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | IDENTIFICATION AND AUTHENTICATION |
| APPL-26-004050 - The macOS system must configure install.log retention to 365. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | AUDIT AND ACCOUNTABILITY |
| APPL-26-005050 - The macOS system must enable macOS Application Firewall. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-005054 - The macOS system must disable the TouchID prompt during Setup Assistant. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-005056 - The macOS system must disable Unlock with Apple Watch during Setup Assistant. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-005058 - The macOS system must disable Handoff. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | ACCESS CONTROL, CONFIGURATION MANAGEMENT |
| APPL-26-005080 - The macOS system must prohibit user installation of software into /users/. | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | CONFIGURATION MANAGEMENT |
| APPL-26-005100 - The macOS system must ensure Secure Boot level is set to "full". | DISA Apple macOS 26 Tahoe STIG v1r3 | Unix | SYSTEM AND INFORMATION INTEGRITY |