Modified rule files

- Removed unncessary ----- at the top
- Updated Siri and Dictation check for 26 to match 27 check
- Updated discussion for iCloud and other rules to include "unless explicitly approved by the organization" language
- Updated PCC fix to add a comment.
This commit is contained in:
Bob Gendler
2026-07-31 22:19:17 -04:00
parent 0bc65f86e8
commit 78f2fcc9cc
190 changed files with 133 additions and 287 deletions

View File

@@ -1,4 +1,3 @@
---
id: audit_acls_files_configure
title: Configure Audit Log Files to Not Contain Access Control Lists
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_acls_folders_configure
title: Configure Audit Log Folder to Not Contain Access Control Lists
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_alert_processing_fail
title: Alert Audit Processing Failure
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: audit_auditd_enabled
title: Enable Security Auditing
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_configure_capacity_notify
title: Configure Audit Capacity Warning
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_control_acls_configure
title: Configure Audit_Control to Not Contain Access Control Lists
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_control_group_configure
title: Configure Audit_Control Group to Wheel
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_control_mode_configure
title: Configure Audit_Control Owner to Mode 440 or Less Permissive
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_control_owner_configure
title: Configure Audit_Control Owner to Root
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_enforce_dual_auth
title: Enforce Dual Authorization for Movement and Deletion of Audit Information
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: audit_failure_halt
title: Configure System to Shut Down Upon Audit Failure
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_files_group_configure
title: Configure Audit Log Files Group to Wheel
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_files_mode_configure
title: Configure Audit Log Files to Mode 440 or Less Permissive
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_files_owner_configure
title: Configure Audit Log Files to be Owned by Root
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_aa_configure
title: Configure System to Audit All Authorization and Authentication Events
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_ad_configure
title: Configure System to Audit All Administrative Action Events
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_ex_configure
title: Configure System to Audit All Failed Program Execution on the System
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_fd_configure
title: Configure System to Audit All Deletions of Object Attributes
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_fm_configure
title: Configure System to Audit All Changes of Object Attributes
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_fm_failed_configure
title: Configure System to Audit All Failed Change of Object Attributes
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_fr_configure
title: Configure System to Audit All Failed Read Actions on the System
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_fw_configure
title: Configure System to Audit All Failed Write Actions on the System
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_flags_lo_configure
title: Configure System to Audit All Log In and Log Out Events
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_folder_group_configure
title: Configure Audit Log Folders Group to Wheel
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_folder_owner_configure
title: Configure Audit Log Folders to be Owned by Root
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_folders_mode_configure
title: Configure Audit Log Folders to Mode 700 or Less Permissive
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_off_load_records
title: Off-Load Audit Records
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: audit_record_reduction_report_generation
title: Audit Record Reduction and Report Generation
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: audit_records_processing
title: Audit Record Reduction and Report Generation
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: audit_retention_configure
title: Configure Audit Retention to $ODV
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: audit_settings_failure_notify
title: Configure Audit Failure Notification
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: auth_smartcard_allow
title: Allow Smartcard Authentication
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: auth_smartcard_certificate_trust_enforce_high
title: Set Smartcard Certificate Trust to High
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: auth_smartcard_certificate_trust_enforce_moderate
title: Set Smartcard Certificate Trust to Moderate
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: auth_smartcard_enforce
title: Enforce Smartcard Authentication
discussion: |

View File

@@ -1,10 +1,11 @@
---
id: icloud_addressbook_disable
title: Disable iCloud Address Book
discussion: |
The macOS built-in Contacts.app connection to Apple's iCloud service _MUST_ be disabled.
The macOS built-in Contacts.app connection to Apple's iCloud service _MUST_ be disabled if iCloud is not an authorized service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated contact synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -3,7 +3,7 @@ title: Disable the System Setting for Apple ID
discussion: |
The system setting for Apple ID _MUST_ be disabled.
Disabling the system setting prevents login to Apple ID and iCloud.
Disabling the system setting prevents login to an Apple Account and synchronizing data to Apple's iCloud service.
references:
nist:
cce:

View File

@@ -1,8 +1,11 @@
---
id: icloud_backup_disabled
title: Ensure iCloud Backup is set to Disabled
discussion: |
iCloud backup _MUST_ be disabled.
iCloud backup _MUST_ be disabled if iCloud is not an authorized service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated backup synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,10 +1,11 @@
---
id: icloud_bookmarks_disable
title: Disable iCloud Bookmarks
discussion: |
The macOS built-in Safari.app bookmark synchronization via the iCloud service _MUST_ be disabled.
The macOS built-in Safari.app bookmark synchronization via the iCloud service _MUST_ be disabled if iCloud is not an authorized service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated bookmark synchronization _MUST_ be controlled by an organization approved service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated bookmark synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,10 +1,11 @@
---
id: icloud_calendar_disable
title: Disable the iCloud Calendar Services
discussion: |
The macOS built-in Calendar.app connection to Apple's iCloud service _MUST_ be disabled.
The macOS built-in Calendar.app connection to Apple's iCloud service _MUST_ be disabled, if iCloud is not an authorized service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -3,7 +3,9 @@ title: Disable iCloud Document Sync
discussion: |
The macOS built-in iCloud document synchronization service _MUST_ be disabled to prevent organizational data from being synchronized to personal or non-approved storage.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated document synchronization _MUST_ be controlled by an organization approved service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated document synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,9 +1,11 @@
id: icloud_enterprisebook_metadata_sync_disable
title: Preventing synchronization of enterprise book meta data.
discussion: |
The iOS device _MUST_ be configured to prevent the synchronization of enterprise book meta data to Apple iCloud servers.
The iOS device _MUST_ be configured to prevent the synchronization of enterprise book meta data to Apple iCloud servers, if iCloud is not an authorized service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,10 +1,11 @@
---
id: icloud_freeform_disable
title: Disable the iCloud Freeform Services
discussion: |
The macOS built-in Freeform.app connection to Apple's iCloud service _MUST_ be disabled.
The macOS built-in Freeform.app connection to Apple's iCloud service _MUST_ be disabled, if iCloud is not an authorized service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,9 +1,11 @@
---
id: icloud_game_center_disable
title: Disable iCloud Game Center
discussion: |
This works only with supervised devices (MDM) and allows to disable Apple Game Center. The rationale is Game Center is using Apple ID and will shared data on AppleID based services, therefore, Game Center _MUST_ be disabled.
This works only with supervised devices and allows to disable Apple Game Center. The rationale is Game Center is using Apple Account and will share data on iCloud based services, therefore, Game Center _MUST_ be disabled.
This setting also prohibits functionality of adding friends to Game Center.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,9 +1,11 @@
id: icloud_keychain_disable
title: Disable iCloud Keychain Sync
discussion: |
The system's ability to automatically synchronize a user's passwords to their iCloud account _MUST_ be disabled.
The system's ability to automatically synchronize a user's passwords to their iCloud account _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved password management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,10 +1,11 @@
---
id: icloud_mail_disable
title: Disable iCloud Mail
discussion: |
The macOS built-in Mail.app connection to Apple's iCloud service _MUST_ be disabled.
The macOS built-in Mail.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved mail management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated mail synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,8 +1,11 @@
---
id: icloud_managed_apps_store_data_disabled
title: Ensure Managed Apps Storing Data in iCloud is Set to Disabled
discussion: |
Managed Apps _MUST_ not store data in iCloud.
Managed Apps _MUST_ not store data in iCloud, unless the organization has explicitly authorized the use of iCloud as a approved data management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,10 +1,11 @@
---
id: icloud_notes_disable
title: Disable iCloud Notes
discussion: |
The macOS built-in Notes.app connection to Apple's iCloud service _MUST_ be disabled.
The macOS built-in Notes.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved notes management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated Notes synchronization _MUST_ be controlled by an organization approved service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated notes synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,8 +1,11 @@
---
id: icloud_photo_stream_disable
title: Ensure Photo Stream is set to Disabled
discussion: |
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DoD sensitive information.
The built-in Photos.app's Photo Stream connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,9 +1,11 @@
id: icloud_photos_disable
title: Disable iCloud Photo Library
discussion: |
The built-in Photos.app's connection to Apple's iCloud service _MUST_ be disabled.
The built-in Photos.app's connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,4 +1,3 @@
---
id: icloud_private_relay_disable
title: Disable iCloud Private Relay
discussion: |

View File

@@ -1,10 +1,11 @@
---
id: icloud_reminders_disable
title: Disable iCloud Reminders
discussion: |
The macOS built-in Reminders.app connection to Apple's iCloud service _MUST_ be disabled.
The macOS built-in Reminders.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved reminder management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated reminders synchronization _MUST_ be controlled by an organization approved service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated reminders synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,8 +1,11 @@
---
id: icloud_shared_photo_stream_disable
title: Ensure Shared Photo Stream is set to Disabled
discussion: |
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DoD sensitive information.
The built-in Photos.app's Photo Stream connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,10 +1,11 @@
---
id: icloud_sync_disable
title: Disable iCloud Desktop and Document Folder Sync
discussion: |
The macOS system's ability to automatically synchronize a user's desktop and documents folder to their iCloud Drive _MUST_ be disabled.
The macOS system's ability to automatically synchronize a user's desktop and documents folder to their iCloud Drive _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved file management service.
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated file synchronization _MUST_ be controlled by an organization approved service.
This requirement helps ensure that organizational file data is managed in accordance with established security, privacy, access-control, and data governance requirements.
references:
nist:
cce:

View File

@@ -1,4 +1,3 @@
---
id: os_account_modification_disable
title: Disable AppleID and Internet Account Modifications
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_airdrop_unmanaged_destination_enable
title: Ensure Treat AirDrop as unmanaged destination is set to Enabled
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_airplay_incoming_password_require
title: Require Passcode for Incoming Airplay Connection Requests
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_airprint_credential_storage_disable
title: Disable Storage of AirPrint Credentials
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_airprint_disable
title: Disable AirPrint
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_airprint_force_trusted_TLS
title: Requires trusted certificates for TLS printing communication
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_allow_contacts_read_managed_sources_unmanaged_destinations_disable
title: Ensure Managed Apps Cannot Read Unmanaged Contact Accounts
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_allow_contacts_write_managed_sources_unmanaged_destinations_disable
title: Ensure Managed Apps Cannot Write to Unmanaged Contact Accounts
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_allow_documents_managed_sources_unmanaged_destinations_disable
title: Ensure Allow documents from managed sources in unmanaged destinations is set to Disabled
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_allow_documents_unmanaged_sources_managed_destinations_disable
title: Ensure Allow documents from unmanaged sources in managed destinations is set to Disabled
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_allow_info_passed
title: Allow Information Transfer with Other Operating Systems
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: os_anti_virus_installed
title: Must Use an Approved Antivirus Program
discussion: |

View File

@@ -1,8 +1,15 @@
---
id: os_apple_intelligence_pcc_disable
title: Disable Apple Intelligence Private Cloud Compute
discussion: |
Apple Intelligence Private Cloud Compute sends data to off-device infrastructure that is not directly controlled by the organization. Therefore, Apple Intelligence features that rely on off-device processing MUST be disabled unless explicitly approved by the organization.
Apple Intelligence Private Cloud Compute sends data to off-device infrastructure that is not directly controlled by the organization. Therefore, Apple Intelligence features that rely on off-device processing _MUST_ be disabled unless explicitly approved by the organization.
This requirement helps ensure that organizational data is managed in accordance with established security, privacy, access-control, and data governance requirements.
Data may be sent to Apple Intelligence Private Cloud Compute even when Apple's provided controls around Apple Intelligence are disabled. Therefore, organizations should ensure that Apple Intelligence Private Cloud Compute is disabled by blocking access to the following domains:
- apple-relay.apple.com
- apple-relay.fastly-edge.com
- apple-relay.cloudflare.com
- cp4.cloudflare.com
references:
nist:
cce:
@@ -52,9 +59,15 @@ platforms:
result:
integer: 4
fix:
shell: |-
shell: |-
note="### Apple Intelligence Private Cloud Compute is disabled by the organization (apple-relay, cp4.cloudflare.com, etc). Added by the mSCP ###"
apple_intelligence_servers=("127.0.0.1 apple-relay.cloudflare.com" "127.0.0.1 apple-relay.fastly-edge.com" "127.0.0.1 cp4.cloudflare.com" "127.0.0.1 apple-relay.apple.com")
host_file=$(/bin/cat /etc/hosts)
if ! /usr/bin/grep -qxF "$note" "$hosts_file" 2>/dev/null; then
echo "$note" >> "$hosts_file"
fi
for config in $apple_intelligence_servers; do
if ! echo $host_file | /usr/bin/grep -q -i "^$config" 2>/dev/null; then
/usr/bin/grep -qxF "^$config" "/etc/hosts" 2>/dev/null || echo "$config" >> "/etc/hosts"
@@ -72,3 +85,4 @@ tags:
- cmmc_lvl1
- cnssi-1253_moderate
- hicp_lp
- new

View File

@@ -1,4 +1,3 @@
---
id: os_apple_watch_pairing_disable
title: Ensure Apple Watch Pairing is Disabled
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_apple_watch_wrist_detection_enable
title: Ensure Force Apple Watch wrist detection is set to Enabled
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_appleid_prompt_disable
title: Disable Apple ID Setup during Setup Assistant
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_application_allow_list
title: Define Allowed Applications
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_application_deny_list
title: Apps not allowed on the device
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_application_sandboxing
title: Ensure Separate Execution Domain for Processes
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: os_asl_log_files_owner_group_configure
title: Configure Apple System Log Files Owned by Root and Group to Wheel
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_asl_log_files_permissions_configure
title: Configure Apple System Log Files To Mode 640 or Less Permissive
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_auth_peripherals
title: Must Authenticate Before Establishing a Connection
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: os_authenticated_root_enable
title: Enable Authenticated Root
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_authentication_password_autofill_enable
title: Ensure Require Touch ID / Face ID authentication before AutoFill is set to Enabled
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_auto_correction_disable
title: Disable Auto Correction
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_automatic_app_download_disable
title: Disallow Automatic Downloads of Apps Purchased on other Apple Devices.
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_blank_bluray_disable
title: Disable Blank Blu Ray
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_blank_cd_disable
title: Disable Blank CD
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_blank_dvd_disable
title: Disable Blank DVD
discussion: |

View File

@@ -62,6 +62,7 @@ tags:
- cnssi-1253_moderate
- cnssi-1253_low
- cnssi-1253_high
- new
mobileconfig_info:
- PayloadType: com.apple.applicationaccess
PayloadContent:

View File

@@ -1,4 +1,3 @@
---
id: os_bluray_read_only_enforce
title: Enforce Blu Ray Read Only
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_bonjour_disable
title: Disable Bonjour Multicast
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_burn_support_disable
title: Disable Burn Support
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_camera_disable
title: Disable Camera
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_cd_read_only_enforce
title: Enforce CD Read Only
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_certificate_authority_trust
title: Issue or Obtain Public Key Certificates from an Approved Service Provider
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_change_security_attributes
title: Allow Administrators to Modify Security Settings and System Attributes
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: os_chat_disable
title: Prevent the Usage of iMessage
discussion: |

View File

@@ -61,6 +61,7 @@ references:
- 8.19.01
platforms:
macOS:
'27.0': {}
'26.0':
benchmarks:
- name: cis_lvl1

View File

@@ -1,4 +1,3 @@
---
id: os_continuous_monitoring
title: Configure Automated Flaw Remediation
discussion: |-

View File

@@ -1,4 +1,3 @@
---
id: os_default_browser_modification_disable
title: Disable Modifying the Default Web Browser Application
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_default_calling_modification_disable
title: Disable Modifying the Default Calling Application
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_default_messaging_modification_disable
title: Disable Modifying the Default Messaging Application
discussion: |

View File

@@ -71,6 +71,7 @@ tags:
- cnssi-1253_moderate
- cnssi-1253_low
- cnssi-1253_high
- new
mobileconfig_info:
- PayloadType: com.apple.applicationaccess
PayloadContent:

View File

@@ -1,4 +1,3 @@
---
id: os_device_name_change_disable
title: Disable Device Name Changes
discussion: |

View File

@@ -1,4 +1,3 @@
---
id: os_diagnostics_reports_modification_disable
title: Disable changing Sending Diagnostic and Usage Data to Apple
discussion: |

Some files were not shown because too many files have changed in this diff Show More