mirror of
https://github.com/usnistgov/macos_security.git
synced 2026-09-26 21:30:42 +01:00
Modified rule files
- Removed unncessary ----- at the top - Updated Siri and Dictation check for 26 to match 27 check - Updated discussion for iCloud and other rules to include "unless explicitly approved by the organization" language - Updated PCC fix to add a comment.
This commit is contained in:
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_acls_files_configure
|
||||
title: Configure Audit Log Files to Not Contain Access Control Lists
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_acls_folders_configure
|
||||
title: Configure Audit Log Folder to Not Contain Access Control Lists
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_alert_processing_fail
|
||||
title: Alert Audit Processing Failure
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_auditd_enabled
|
||||
title: Enable Security Auditing
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_configure_capacity_notify
|
||||
title: Configure Audit Capacity Warning
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_control_acls_configure
|
||||
title: Configure Audit_Control to Not Contain Access Control Lists
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_control_group_configure
|
||||
title: Configure Audit_Control Group to Wheel
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_control_mode_configure
|
||||
title: Configure Audit_Control Owner to Mode 440 or Less Permissive
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_control_owner_configure
|
||||
title: Configure Audit_Control Owner to Root
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_enforce_dual_auth
|
||||
title: Enforce Dual Authorization for Movement and Deletion of Audit Information
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_failure_halt
|
||||
title: Configure System to Shut Down Upon Audit Failure
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_files_group_configure
|
||||
title: Configure Audit Log Files Group to Wheel
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_files_mode_configure
|
||||
title: Configure Audit Log Files to Mode 440 or Less Permissive
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_files_owner_configure
|
||||
title: Configure Audit Log Files to be Owned by Root
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_aa_configure
|
||||
title: Configure System to Audit All Authorization and Authentication Events
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_ad_configure
|
||||
title: Configure System to Audit All Administrative Action Events
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_ex_configure
|
||||
title: Configure System to Audit All Failed Program Execution on the System
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_fd_configure
|
||||
title: Configure System to Audit All Deletions of Object Attributes
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_fm_configure
|
||||
title: Configure System to Audit All Changes of Object Attributes
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_fm_failed_configure
|
||||
title: Configure System to Audit All Failed Change of Object Attributes
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_fr_configure
|
||||
title: Configure System to Audit All Failed Read Actions on the System
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_fw_configure
|
||||
title: Configure System to Audit All Failed Write Actions on the System
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_flags_lo_configure
|
||||
title: Configure System to Audit All Log In and Log Out Events
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_folder_group_configure
|
||||
title: Configure Audit Log Folders Group to Wheel
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_folder_owner_configure
|
||||
title: Configure Audit Log Folders to be Owned by Root
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_folders_mode_configure
|
||||
title: Configure Audit Log Folders to Mode 700 or Less Permissive
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_off_load_records
|
||||
title: Off-Load Audit Records
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_record_reduction_report_generation
|
||||
title: Audit Record Reduction and Report Generation
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_records_processing
|
||||
title: Audit Record Reduction and Report Generation
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_retention_configure
|
||||
title: Configure Audit Retention to $ODV
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: audit_settings_failure_notify
|
||||
title: Configure Audit Failure Notification
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: auth_smartcard_allow
|
||||
title: Allow Smartcard Authentication
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: auth_smartcard_certificate_trust_enforce_high
|
||||
title: Set Smartcard Certificate Trust to High
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: auth_smartcard_certificate_trust_enforce_moderate
|
||||
title: Set Smartcard Certificate Trust to Moderate
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: auth_smartcard_enforce
|
||||
title: Enforce Smartcard Authentication
|
||||
discussion: |
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
id: icloud_addressbook_disable
|
||||
title: Disable iCloud Address Book
|
||||
discussion: |
|
||||
The macOS built-in Contacts.app connection to Apple's iCloud service _MUST_ be disabled.
|
||||
The macOS built-in Contacts.app connection to Apple's iCloud service _MUST_ be disabled if iCloud is not an authorized service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated contact synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -3,7 +3,7 @@ title: Disable the System Setting for Apple ID
|
||||
discussion: |
|
||||
The system setting for Apple ID _MUST_ be disabled.
|
||||
|
||||
Disabling the system setting prevents login to Apple ID and iCloud.
|
||||
Disabling the system setting prevents login to an Apple Account and synchronizing data to Apple's iCloud service.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,8 +1,11 @@
|
||||
---
|
||||
id: icloud_backup_disabled
|
||||
title: Ensure iCloud Backup is set to Disabled
|
||||
discussion: |
|
||||
iCloud backup _MUST_ be disabled.
|
||||
iCloud backup _MUST_ be disabled if iCloud is not an authorized service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated backup synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
id: icloud_bookmarks_disable
|
||||
title: Disable iCloud Bookmarks
|
||||
discussion: |
|
||||
The macOS built-in Safari.app bookmark synchronization via the iCloud service _MUST_ be disabled.
|
||||
The macOS built-in Safari.app bookmark synchronization via the iCloud service _MUST_ be disabled if iCloud is not an authorized service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated bookmark synchronization _MUST_ be controlled by an organization approved service.
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated bookmark synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
id: icloud_calendar_disable
|
||||
title: Disable the iCloud Calendar Services
|
||||
discussion: |
|
||||
The macOS built-in Calendar.app connection to Apple's iCloud service _MUST_ be disabled.
|
||||
The macOS built-in Calendar.app connection to Apple's iCloud service _MUST_ be disabled, if iCloud is not an authorized service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service.
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -3,7 +3,9 @@ title: Disable iCloud Document Sync
|
||||
discussion: |
|
||||
The macOS built-in iCloud document synchronization service _MUST_ be disabled to prevent organizational data from being synchronized to personal or non-approved storage.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated document synchronization _MUST_ be controlled by an organization approved service.
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated document synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,9 +1,11 @@
|
||||
id: icloud_enterprisebook_metadata_sync_disable
|
||||
title: Preventing synchronization of enterprise book meta data.
|
||||
discussion: |
|
||||
The iOS device _MUST_ be configured to prevent the synchronization of enterprise book meta data to Apple iCloud servers.
|
||||
The iOS device _MUST_ be configured to prevent the synchronization of enterprise book meta data to Apple iCloud servers, if iCloud is not an authorized service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service.
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
id: icloud_freeform_disable
|
||||
title: Disable the iCloud Freeform Services
|
||||
discussion: |
|
||||
The macOS built-in Freeform.app connection to Apple's iCloud service _MUST_ be disabled.
|
||||
The macOS built-in Freeform.app connection to Apple's iCloud service _MUST_ be disabled, if iCloud is not an authorized service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service.
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,9 +1,11 @@
|
||||
---
|
||||
id: icloud_game_center_disable
|
||||
title: Disable iCloud Game Center
|
||||
discussion: |
|
||||
This works only with supervised devices (MDM) and allows to disable Apple Game Center. The rationale is Game Center is using Apple ID and will shared data on AppleID based services, therefore, Game Center _MUST_ be disabled.
|
||||
This works only with supervised devices and allows to disable Apple Game Center. The rationale is Game Center is using Apple Account and will share data on iCloud based services, therefore, Game Center _MUST_ be disabled.
|
||||
|
||||
This setting also prohibits functionality of adding friends to Game Center.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,9 +1,11 @@
|
||||
id: icloud_keychain_disable
|
||||
title: Disable iCloud Keychain Sync
|
||||
discussion: |
|
||||
The system's ability to automatically synchronize a user's passwords to their iCloud account _MUST_ be disabled.
|
||||
The system's ability to automatically synchronize a user's passwords to their iCloud account _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved password management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
id: icloud_mail_disable
|
||||
title: Disable iCloud Mail
|
||||
discussion: |
|
||||
The macOS built-in Mail.app connection to Apple's iCloud service _MUST_ be disabled.
|
||||
The macOS built-in Mail.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved mail management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated mail synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,8 +1,11 @@
|
||||
---
|
||||
id: icloud_managed_apps_store_data_disabled
|
||||
title: Ensure Managed Apps Storing Data in iCloud is Set to Disabled
|
||||
discussion: |
|
||||
Managed Apps _MUST_ not store data in iCloud.
|
||||
Managed Apps _MUST_ not store data in iCloud, unless the organization has explicitly authorized the use of iCloud as a approved data management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
id: icloud_notes_disable
|
||||
title: Disable iCloud Notes
|
||||
discussion: |
|
||||
The macOS built-in Notes.app connection to Apple's iCloud service _MUST_ be disabled.
|
||||
The macOS built-in Notes.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved notes management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated Notes synchronization _MUST_ be controlled by an organization approved service.
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated notes synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,8 +1,11 @@
|
||||
---
|
||||
id: icloud_photo_stream_disable
|
||||
title: Ensure Photo Stream is set to Disabled
|
||||
discussion: |
|
||||
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DoD sensitive information.
|
||||
The built-in Photos.app's Photo Stream connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,9 +1,11 @@
|
||||
id: icloud_photos_disable
|
||||
title: Disable iCloud Photo Library
|
||||
discussion: |
|
||||
The built-in Photos.app's connection to Apple's iCloud service _MUST_ be disabled.
|
||||
The built-in Photos.app's connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service.
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: icloud_private_relay_disable
|
||||
title: Disable iCloud Private Relay
|
||||
discussion: |
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
id: icloud_reminders_disable
|
||||
title: Disable iCloud Reminders
|
||||
discussion: |
|
||||
The macOS built-in Reminders.app connection to Apple's iCloud service _MUST_ be disabled.
|
||||
The macOS built-in Reminders.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved reminder management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated reminders synchronization _MUST_ be controlled by an organization approved service.
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated reminders synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,8 +1,11 @@
|
||||
---
|
||||
id: icloud_shared_photo_stream_disable
|
||||
title: Ensure Shared Photo Stream is set to Disabled
|
||||
discussion: |
|
||||
If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DoD sensitive information.
|
||||
The built-in Photos.app's Photo Stream connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,10 +1,11 @@
|
||||
---
|
||||
id: icloud_sync_disable
|
||||
title: Disable iCloud Desktop and Document Folder Sync
|
||||
discussion: |
|
||||
The macOS system's ability to automatically synchronize a user's desktop and documents folder to their iCloud Drive _MUST_ be disabled.
|
||||
The macOS system's ability to automatically synchronize a user's desktop and documents folder to their iCloud Drive _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved file management service.
|
||||
|
||||
Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated file synchronization _MUST_ be controlled by an organization approved service.
|
||||
|
||||
This requirement helps ensure that organizational file data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_account_modification_disable
|
||||
title: Disable AppleID and Internet Account Modifications
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_airdrop_unmanaged_destination_enable
|
||||
title: Ensure Treat AirDrop as unmanaged destination is set to Enabled
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_airplay_incoming_password_require
|
||||
title: Require Passcode for Incoming Airplay Connection Requests
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_airprint_credential_storage_disable
|
||||
title: Disable Storage of AirPrint Credentials
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_airprint_disable
|
||||
title: Disable AirPrint
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_airprint_force_trusted_TLS
|
||||
title: Requires trusted certificates for TLS printing communication
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_allow_contacts_read_managed_sources_unmanaged_destinations_disable
|
||||
title: Ensure Managed Apps Cannot Read Unmanaged Contact Accounts
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_allow_contacts_write_managed_sources_unmanaged_destinations_disable
|
||||
title: Ensure Managed Apps Cannot Write to Unmanaged Contact Accounts
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_allow_documents_managed_sources_unmanaged_destinations_disable
|
||||
title: Ensure Allow documents from managed sources in unmanaged destinations is set to Disabled
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_allow_documents_unmanaged_sources_managed_destinations_disable
|
||||
title: Ensure Allow documents from unmanaged sources in managed destinations is set to Disabled
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_allow_info_passed
|
||||
title: Allow Information Transfer with Other Operating Systems
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_anti_virus_installed
|
||||
title: Must Use an Approved Antivirus Program
|
||||
discussion: |
|
||||
|
||||
@@ -1,8 +1,15 @@
|
||||
---
|
||||
id: os_apple_intelligence_pcc_disable
|
||||
title: Disable Apple Intelligence Private Cloud Compute
|
||||
discussion: |
|
||||
Apple Intelligence Private Cloud Compute sends data to off-device infrastructure that is not directly controlled by the organization. Therefore, Apple Intelligence features that rely on off-device processing MUST be disabled unless explicitly approved by the organization.
|
||||
Apple Intelligence Private Cloud Compute sends data to off-device infrastructure that is not directly controlled by the organization. Therefore, Apple Intelligence features that rely on off-device processing _MUST_ be disabled unless explicitly approved by the organization.
|
||||
|
||||
This requirement helps ensure that organizational data is managed in accordance with established security, privacy, access-control, and data governance requirements.
|
||||
|
||||
Data may be sent to Apple Intelligence Private Cloud Compute even when Apple's provided controls around Apple Intelligence are disabled. Therefore, organizations should ensure that Apple Intelligence Private Cloud Compute is disabled by blocking access to the following domains:
|
||||
- apple-relay.apple.com
|
||||
- apple-relay.fastly-edge.com
|
||||
- apple-relay.cloudflare.com
|
||||
- cp4.cloudflare.com
|
||||
references:
|
||||
nist:
|
||||
cce:
|
||||
@@ -52,9 +59,15 @@ platforms:
|
||||
result:
|
||||
integer: 4
|
||||
fix:
|
||||
shell: |-
|
||||
shell: |-
|
||||
note="### Apple Intelligence Private Cloud Compute is disabled by the organization (apple-relay, cp4.cloudflare.com, etc). Added by the mSCP ###"
|
||||
apple_intelligence_servers=("127.0.0.1 apple-relay.cloudflare.com" "127.0.0.1 apple-relay.fastly-edge.com" "127.0.0.1 cp4.cloudflare.com" "127.0.0.1 apple-relay.apple.com")
|
||||
|
||||
host_file=$(/bin/cat /etc/hosts)
|
||||
|
||||
if ! /usr/bin/grep -qxF "$note" "$hosts_file" 2>/dev/null; then
|
||||
echo "$note" >> "$hosts_file"
|
||||
fi
|
||||
for config in $apple_intelligence_servers; do
|
||||
if ! echo $host_file | /usr/bin/grep -q -i "^$config" 2>/dev/null; then
|
||||
/usr/bin/grep -qxF "^$config" "/etc/hosts" 2>/dev/null || echo "$config" >> "/etc/hosts"
|
||||
@@ -72,3 +85,4 @@ tags:
|
||||
- cmmc_lvl1
|
||||
- cnssi-1253_moderate
|
||||
- hicp_lp
|
||||
- new
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_apple_watch_pairing_disable
|
||||
title: Ensure Apple Watch Pairing is Disabled
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_apple_watch_wrist_detection_enable
|
||||
title: Ensure Force Apple Watch wrist detection is set to Enabled
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_appleid_prompt_disable
|
||||
title: Disable Apple ID Setup during Setup Assistant
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_application_allow_list
|
||||
title: Define Allowed Applications
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_application_deny_list
|
||||
title: Apps not allowed on the device
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_application_sandboxing
|
||||
title: Ensure Separate Execution Domain for Processes
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_asl_log_files_owner_group_configure
|
||||
title: Configure Apple System Log Files Owned by Root and Group to Wheel
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_asl_log_files_permissions_configure
|
||||
title: Configure Apple System Log Files To Mode 640 or Less Permissive
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_auth_peripherals
|
||||
title: Must Authenticate Before Establishing a Connection
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_authenticated_root_enable
|
||||
title: Enable Authenticated Root
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_authentication_password_autofill_enable
|
||||
title: Ensure Require Touch ID / Face ID authentication before AutoFill is set to Enabled
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_auto_correction_disable
|
||||
title: Disable Auto Correction
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_automatic_app_download_disable
|
||||
title: Disallow Automatic Downloads of Apps Purchased on other Apple Devices.
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_blank_bluray_disable
|
||||
title: Disable Blank Blu Ray
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_blank_cd_disable
|
||||
title: Disable Blank CD
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_blank_dvd_disable
|
||||
title: Disable Blank DVD
|
||||
discussion: |
|
||||
|
||||
@@ -62,6 +62,7 @@ tags:
|
||||
- cnssi-1253_moderate
|
||||
- cnssi-1253_low
|
||||
- cnssi-1253_high
|
||||
- new
|
||||
mobileconfig_info:
|
||||
- PayloadType: com.apple.applicationaccess
|
||||
PayloadContent:
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_bluray_read_only_enforce
|
||||
title: Enforce Blu Ray Read Only
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_bonjour_disable
|
||||
title: Disable Bonjour Multicast
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_burn_support_disable
|
||||
title: Disable Burn Support
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_camera_disable
|
||||
title: Disable Camera
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_cd_read_only_enforce
|
||||
title: Enforce CD Read Only
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_certificate_authority_trust
|
||||
title: Issue or Obtain Public Key Certificates from an Approved Service Provider
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_change_security_attributes
|
||||
title: Allow Administrators to Modify Security Settings and System Attributes
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_chat_disable
|
||||
title: Prevent the Usage of iMessage
|
||||
discussion: |
|
||||
|
||||
@@ -61,6 +61,7 @@ references:
|
||||
- 8.19.01
|
||||
platforms:
|
||||
macOS:
|
||||
'27.0': {}
|
||||
'26.0':
|
||||
benchmarks:
|
||||
- name: cis_lvl1
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_continuous_monitoring
|
||||
title: Configure Automated Flaw Remediation
|
||||
discussion: |-
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_default_browser_modification_disable
|
||||
title: Disable Modifying the Default Web Browser Application
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_default_calling_modification_disable
|
||||
title: Disable Modifying the Default Calling Application
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_default_messaging_modification_disable
|
||||
title: Disable Modifying the Default Messaging Application
|
||||
discussion: |
|
||||
|
||||
@@ -71,6 +71,7 @@ tags:
|
||||
- cnssi-1253_moderate
|
||||
- cnssi-1253_low
|
||||
- cnssi-1253_high
|
||||
- new
|
||||
mobileconfig_info:
|
||||
- PayloadType: com.apple.applicationaccess
|
||||
PayloadContent:
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_device_name_change_disable
|
||||
title: Disable Device Name Changes
|
||||
discussion: |
|
||||
|
||||
@@ -1,4 +1,3 @@
|
||||
---
|
||||
id: os_diagnostics_reports_modification_disable
|
||||
title: Disable changing Sending Diagnostic and Usage Data to Apple
|
||||
discussion: |
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user