diff --git a/baselines/800-171.yaml b/baselines/800-171.yaml index 84d4383e..99dbfbd7 100644 --- a/baselines/800-171.yaml +++ b/baselines/800-171.yaml @@ -53,6 +53,9 @@ profile: - sysprefs_media_sharing_disabled - sysprefs_password_hints_disable - sysprefs_rae_disable + - sysprefs_screensaver_ask_for_password_delay_enforce + - sysprefs_screensaver_password_enforce + - sysprefs_screensaver_timeout_enforce - sysprefs_screen_sharing_disable - sysprefs_siri_disable - sysprefs_smbd_disable @@ -109,10 +112,7 @@ profile: - os_power_nap_disable - os_removable_media_disable - os_root_disable - - os_screensaver_ask_for_password_delay_enforce - os_screensaver_loginwindow_enforce - - os_screensaver_password_enforce - - os_screensaver_timeout_enforce - os_sip_enable - os_siri_prompt_disable - os_ssh_client_alive_count_max_configure diff --git a/baselines/800-53_high.yaml b/baselines/800-53_high.yaml index 7013b2f2..b377750f 100644 --- a/baselines/800-53_high.yaml +++ b/baselines/800-53_high.yaml @@ -56,6 +56,9 @@ profile: - sysprefs_loginwindow_prompt_username_password_enforce - sysprefs_password_hints_disable - sysprefs_rae_disable + - sysprefs_screensaver_ask_for_password_delay_enforce + - sysprefs_screensaver_password_enforce + - sysprefs_screensaver_timeout_enforce - sysprefs_screen_sharing_disable - sysprefs_siri_disable - sysprefs_smbd_disable @@ -112,10 +115,7 @@ profile: - os_policy_banner_ssh_enforce - os_power_nap_disable - os_removable_media_disable - - os_screensaver_ask_for_password_delay_enforce - os_screensaver_loginwindow_enforce - - os_screensaver_password_enforce - - os_screensaver_timeout_enforce - os_secure_boot_verify - os_siri_prompt_disable - os_ssh_client_alive_count_max_configure diff --git a/baselines/800-53_moderate.yaml b/baselines/800-53_moderate.yaml index bf7dcc5f..399d1fb1 100644 --- a/baselines/800-53_moderate.yaml +++ b/baselines/800-53_moderate.yaml @@ -54,6 +54,9 @@ profile: - sysprefs_loginwindow_prompt_username_password_enforce - sysprefs_password_hints_disable - sysprefs_rae_disable + - sysprefs_screensaver_ask_for_password_delay_enforce + - sysprefs_screensaver_password_enforce + - sysprefs_screensaver_timeout_enforce - sysprefs_screen_sharing_disable - sysprefs_siri_disable - sysprefs_smbd_disable @@ -110,10 +113,7 @@ profile: - os_removable_media_disable - os_root_disable - os_ssh_permit_root_login_configure - - os_screensaver_ask_for_password_delay_enforce - os_screensaver_loginwindow_enforce - - os_screensaver_password_enforce - - os_screensaver_timeout_enforce - os_siri_prompt_disable - os_ssh_client_alive_count_max_configure - os_ssh_client_alive_interval_configure diff --git a/baselines/all_rules.yaml b/baselines/all_rules.yaml index 2da27bd0..bcb2be34 100644 --- a/baselines/all_rules.yaml +++ b/baselines/all_rules.yaml @@ -58,6 +58,9 @@ profile: - sysprefs_media_sharing_disabled - sysprefs_password_hints_disable - sysprefs_rae_disable + - sysprefs_screensaver_ask_for_password_delay_enforce + - sysprefs_screensaver_password_enforce + - sysprefs_screensaver_timeout_enforce - sysprefs_screen_sharing_disable - sysprefs_siri_disable - sysprefs_smbd_disable @@ -117,10 +120,7 @@ profile: - os_privacy_setup_prompt_disable - os_removable_media_disable - os_root_disable - - os_screensaver_ask_for_password_delay_enforce - os_screensaver_loginwindow_enforce - - os_screensaver_password_enforce - - os_screensaver_timeout_enforce - os_secure_boot_verify - os_siri_prompt_disable - os_ssh_client_alive_count_max_configure diff --git a/baselines/cnssi-1253.yaml b/baselines/cnssi-1253.yaml index d1672a60..f0b5afcb 100644 --- a/baselines/cnssi-1253.yaml +++ b/baselines/cnssi-1253.yaml @@ -54,6 +54,9 @@ profile: - sysprefs_loginwindow_prompt_username_password_enforce - sysprefs_password_hints_disable - sysprefs_rae_disable + - sysprefs_screensaver_ask_for_password_delay_enforce + - sysprefs_screensaver_password_enforce + - sysprefs_screensaver_timeout_enforce - sysprefs_screen_sharing_disable - sysprefs_siri_disable - sysprefs_smbd_disable @@ -110,10 +113,7 @@ profile: - os_removable_media_disable - os_root_disable - os_ssh_permit_root_login_configure - - os_screensaver_ask_for_password_delay_enforce - os_screensaver_loginwindow_enforce - - os_screensaver_password_enforce - - os_screensaver_timeout_enforce - os_siri_prompt_disable - os_ssh_client_alive_count_max_configure - os_ssh_client_alive_interval_configure diff --git a/rules/os/os_screensaver_ask_for_password_delay_enforce.yaml b/rules/sysprefs/sysprefs_screensaver_ask_for_password_delay_enforce.yaml similarity index 93% rename from rules/os/os_screensaver_ask_for_password_delay_enforce.yaml rename to rules/sysprefs/sysprefs_screensaver_ask_for_password_delay_enforce.yaml index 9f0c7ac2..a32e4532 100644 --- a/rules/os/os_screensaver_ask_for_password_delay_enforce.yaml +++ b/rules/sysprefs/sysprefs_screensaver_ask_for_password_delay_enforce.yaml @@ -1,4 +1,4 @@ -id: os_screensaver_ask_for_password_delay_enforce +id: sysprefs_screensaver_ask_for_password_delay_enforce title: "Enforce Session Lock After Screen Saver is Started" discussion: | A screen saver _MUST_ be enabled and the system _MUST_ be configured to require a password to unlock once the screensaver has been on for a maximum of five seconds. diff --git a/rules/os/os_screensaver_password_enforce.yaml b/rules/sysprefs/sysprefs_screensaver_password_enforce.yaml similarity index 94% rename from rules/os/os_screensaver_password_enforce.yaml rename to rules/sysprefs/sysprefs_screensaver_password_enforce.yaml index f4965f63..91bef2c8 100644 --- a/rules/os/os_screensaver_password_enforce.yaml +++ b/rules/sysprefs/sysprefs_screensaver_password_enforce.yaml @@ -1,4 +1,4 @@ -id: os_screensaver_password_enforce +id: sysprefs_screensaver_password_enforce title: "Enforce Screen Saver Password" discussion: | Users _MUST_ authenticate when unlocking the screen saver. diff --git a/rules/os/os_screensaver_timeout_enforce.yaml b/rules/sysprefs/sysprefs_screensaver_timeout_enforce.yaml similarity index 94% rename from rules/os/os_screensaver_timeout_enforce.yaml rename to rules/sysprefs/sysprefs_screensaver_timeout_enforce.yaml index f264efd5..913fca3b 100644 --- a/rules/os/os_screensaver_timeout_enforce.yaml +++ b/rules/sysprefs/sysprefs_screensaver_timeout_enforce.yaml @@ -1,4 +1,4 @@ -id: os_screensaver_timeout_enforce +id: sysprefs_screensaver_timeout_enforce title: "Enforce Screen Saver Timeout" discussion: | The screen saver timeout _MUST_ be set to 15 minutes. diff --git a/templates/images/macOSSCP_Banner_3100x500.png b/templates/images/macOSSCP_Banner_3100x500.png new file mode 100644 index 00000000..170b599c Binary files /dev/null and b/templates/images/macOSSCP_Banner_3100x500.png differ diff --git a/templates/images/macOSSCP_Logo_x1024.PNG b/templates/images/macOSSCP_Logo_x1024.PNG new file mode 100644 index 00000000..9902b69c Binary files /dev/null and b/templates/images/macOSSCP_Logo_x1024.PNG differ