diff --git a/src/mscp/data/rules/audit/audit_acls_files_configure.yaml b/src/mscp/data/rules/audit/audit_acls_files_configure.yaml index c92746c1..9b67d591 100644 --- a/src/mscp/data/rules/audit/audit_acls_files_configure.yaml +++ b/src/mscp/data/rules/audit/audit_acls_files_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_acls_files_configure title: Configure Audit Log Files to Not Contain Access Control Lists discussion: | diff --git a/src/mscp/data/rules/audit/audit_acls_folders_configure.yaml b/src/mscp/data/rules/audit/audit_acls_folders_configure.yaml index 9c970cd0..d815bfda 100644 --- a/src/mscp/data/rules/audit/audit_acls_folders_configure.yaml +++ b/src/mscp/data/rules/audit/audit_acls_folders_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_acls_folders_configure title: Configure Audit Log Folder to Not Contain Access Control Lists discussion: | diff --git a/src/mscp/data/rules/audit/audit_alert_processing_fail.yaml b/src/mscp/data/rules/audit/audit_alert_processing_fail.yaml index 045717da..060089a5 100644 --- a/src/mscp/data/rules/audit/audit_alert_processing_fail.yaml +++ b/src/mscp/data/rules/audit/audit_alert_processing_fail.yaml @@ -1,4 +1,3 @@ ---- id: audit_alert_processing_fail title: Alert Audit Processing Failure discussion: |- diff --git a/src/mscp/data/rules/audit/audit_auditd_enabled.yaml b/src/mscp/data/rules/audit/audit_auditd_enabled.yaml index 15c8d054..e32c7df5 100644 --- a/src/mscp/data/rules/audit/audit_auditd_enabled.yaml +++ b/src/mscp/data/rules/audit/audit_auditd_enabled.yaml @@ -1,4 +1,3 @@ ---- id: audit_auditd_enabled title: Enable Security Auditing discussion: | diff --git a/src/mscp/data/rules/audit/audit_configure_capacity_notify.yaml b/src/mscp/data/rules/audit/audit_configure_capacity_notify.yaml index ccfd6417..4e9ef261 100644 --- a/src/mscp/data/rules/audit/audit_configure_capacity_notify.yaml +++ b/src/mscp/data/rules/audit/audit_configure_capacity_notify.yaml @@ -1,4 +1,3 @@ ---- id: audit_configure_capacity_notify title: Configure Audit Capacity Warning discussion: | diff --git a/src/mscp/data/rules/audit/audit_control_acls_configure.yaml b/src/mscp/data/rules/audit/audit_control_acls_configure.yaml index 46543b70..1d5a8b97 100644 --- a/src/mscp/data/rules/audit/audit_control_acls_configure.yaml +++ b/src/mscp/data/rules/audit/audit_control_acls_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_control_acls_configure title: Configure Audit_Control to Not Contain Access Control Lists discussion: | diff --git a/src/mscp/data/rules/audit/audit_control_group_configure.yaml b/src/mscp/data/rules/audit/audit_control_group_configure.yaml index 73fc8960..17bedd2f 100644 --- a/src/mscp/data/rules/audit/audit_control_group_configure.yaml +++ b/src/mscp/data/rules/audit/audit_control_group_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_control_group_configure title: Configure Audit_Control Group to Wheel discussion: | diff --git a/src/mscp/data/rules/audit/audit_control_mode_configure.yaml b/src/mscp/data/rules/audit/audit_control_mode_configure.yaml index 9d540bcd..e36c6058 100644 --- a/src/mscp/data/rules/audit/audit_control_mode_configure.yaml +++ b/src/mscp/data/rules/audit/audit_control_mode_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_control_mode_configure title: Configure Audit_Control Owner to Mode 440 or Less Permissive discussion: | diff --git a/src/mscp/data/rules/audit/audit_control_owner_configure.yaml b/src/mscp/data/rules/audit/audit_control_owner_configure.yaml index 94125908..822d3c91 100644 --- a/src/mscp/data/rules/audit/audit_control_owner_configure.yaml +++ b/src/mscp/data/rules/audit/audit_control_owner_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_control_owner_configure title: Configure Audit_Control Owner to Root discussion: | diff --git a/src/mscp/data/rules/audit/audit_enforce_dual_auth.yaml b/src/mscp/data/rules/audit/audit_enforce_dual_auth.yaml index 0e7aedbe..26d3c515 100644 --- a/src/mscp/data/rules/audit/audit_enforce_dual_auth.yaml +++ b/src/mscp/data/rules/audit/audit_enforce_dual_auth.yaml @@ -1,4 +1,3 @@ ---- id: audit_enforce_dual_auth title: Enforce Dual Authorization for Movement and Deletion of Audit Information discussion: |- diff --git a/src/mscp/data/rules/audit/audit_failure_halt.yaml b/src/mscp/data/rules/audit/audit_failure_halt.yaml index 9166feaf..efef08c8 100644 --- a/src/mscp/data/rules/audit/audit_failure_halt.yaml +++ b/src/mscp/data/rules/audit/audit_failure_halt.yaml @@ -1,4 +1,3 @@ ---- id: audit_failure_halt title: Configure System to Shut Down Upon Audit Failure discussion: | diff --git a/src/mscp/data/rules/audit/audit_files_group_configure.yaml b/src/mscp/data/rules/audit/audit_files_group_configure.yaml index b8d1b5a5..e5a39f71 100644 --- a/src/mscp/data/rules/audit/audit_files_group_configure.yaml +++ b/src/mscp/data/rules/audit/audit_files_group_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_files_group_configure title: Configure Audit Log Files Group to Wheel discussion: | diff --git a/src/mscp/data/rules/audit/audit_files_mode_configure.yaml b/src/mscp/data/rules/audit/audit_files_mode_configure.yaml index 8f6b28ed..99ed0df8 100644 --- a/src/mscp/data/rules/audit/audit_files_mode_configure.yaml +++ b/src/mscp/data/rules/audit/audit_files_mode_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_files_mode_configure title: Configure Audit Log Files to Mode 440 or Less Permissive discussion: | diff --git a/src/mscp/data/rules/audit/audit_files_owner_configure.yaml b/src/mscp/data/rules/audit/audit_files_owner_configure.yaml index 842325b0..1108c721 100644 --- a/src/mscp/data/rules/audit/audit_files_owner_configure.yaml +++ b/src/mscp/data/rules/audit/audit_files_owner_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_files_owner_configure title: Configure Audit Log Files to be Owned by Root discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_aa_configure.yaml b/src/mscp/data/rules/audit/audit_flags_aa_configure.yaml index 6e76e043..a0df7896 100644 --- a/src/mscp/data/rules/audit/audit_flags_aa_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_aa_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_aa_configure title: Configure System to Audit All Authorization and Authentication Events discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_ad_configure.yaml b/src/mscp/data/rules/audit/audit_flags_ad_configure.yaml index 24b0fe2f..4fc2d61a 100644 --- a/src/mscp/data/rules/audit/audit_flags_ad_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_ad_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_ad_configure title: Configure System to Audit All Administrative Action Events discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_ex_configure.yaml b/src/mscp/data/rules/audit/audit_flags_ex_configure.yaml index ce3a012d..8a472a03 100644 --- a/src/mscp/data/rules/audit/audit_flags_ex_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_ex_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_ex_configure title: Configure System to Audit All Failed Program Execution on the System discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_fd_configure.yaml b/src/mscp/data/rules/audit/audit_flags_fd_configure.yaml index 19a7806f..8db01a48 100644 --- a/src/mscp/data/rules/audit/audit_flags_fd_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_fd_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_fd_configure title: Configure System to Audit All Deletions of Object Attributes discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_fm_configure.yaml b/src/mscp/data/rules/audit/audit_flags_fm_configure.yaml index 591071a2..1fcd307e 100644 --- a/src/mscp/data/rules/audit/audit_flags_fm_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_fm_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_fm_configure title: Configure System to Audit All Changes of Object Attributes discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_fm_failed_configure.yaml b/src/mscp/data/rules/audit/audit_flags_fm_failed_configure.yaml index 7d39170c..c232282e 100644 --- a/src/mscp/data/rules/audit/audit_flags_fm_failed_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_fm_failed_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_fm_failed_configure title: Configure System to Audit All Failed Change of Object Attributes discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_fr_configure.yaml b/src/mscp/data/rules/audit/audit_flags_fr_configure.yaml index 184c040f..c447a721 100644 --- a/src/mscp/data/rules/audit/audit_flags_fr_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_fr_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_fr_configure title: Configure System to Audit All Failed Read Actions on the System discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_fw_configure.yaml b/src/mscp/data/rules/audit/audit_flags_fw_configure.yaml index 7ba0dd0b..aa5a3920 100644 --- a/src/mscp/data/rules/audit/audit_flags_fw_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_fw_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_fw_configure title: Configure System to Audit All Failed Write Actions on the System discussion: | diff --git a/src/mscp/data/rules/audit/audit_flags_lo_configure.yaml b/src/mscp/data/rules/audit/audit_flags_lo_configure.yaml index 1859f125..ed055d71 100644 --- a/src/mscp/data/rules/audit/audit_flags_lo_configure.yaml +++ b/src/mscp/data/rules/audit/audit_flags_lo_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_flags_lo_configure title: Configure System to Audit All Log In and Log Out Events discussion: | diff --git a/src/mscp/data/rules/audit/audit_folder_group_configure.yaml b/src/mscp/data/rules/audit/audit_folder_group_configure.yaml index 7846c757..dba6cae8 100644 --- a/src/mscp/data/rules/audit/audit_folder_group_configure.yaml +++ b/src/mscp/data/rules/audit/audit_folder_group_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_folder_group_configure title: Configure Audit Log Folders Group to Wheel discussion: | diff --git a/src/mscp/data/rules/audit/audit_folder_owner_configure.yaml b/src/mscp/data/rules/audit/audit_folder_owner_configure.yaml index 8ea58c35..e988381d 100644 --- a/src/mscp/data/rules/audit/audit_folder_owner_configure.yaml +++ b/src/mscp/data/rules/audit/audit_folder_owner_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_folder_owner_configure title: Configure Audit Log Folders to be Owned by Root discussion: | diff --git a/src/mscp/data/rules/audit/audit_folders_mode_configure.yaml b/src/mscp/data/rules/audit/audit_folders_mode_configure.yaml index 4bcd8a69..f3249fbd 100644 --- a/src/mscp/data/rules/audit/audit_folders_mode_configure.yaml +++ b/src/mscp/data/rules/audit/audit_folders_mode_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_folders_mode_configure title: Configure Audit Log Folders to Mode 700 or Less Permissive discussion: | diff --git a/src/mscp/data/rules/audit/audit_off_load_records.yaml b/src/mscp/data/rules/audit/audit_off_load_records.yaml index 29576d10..2ab3f8aa 100644 --- a/src/mscp/data/rules/audit/audit_off_load_records.yaml +++ b/src/mscp/data/rules/audit/audit_off_load_records.yaml @@ -1,4 +1,3 @@ ---- id: audit_off_load_records title: Off-Load Audit Records discussion: |- diff --git a/src/mscp/data/rules/audit/audit_record_reduction_report_generation.yaml b/src/mscp/data/rules/audit/audit_record_reduction_report_generation.yaml index c5fd6c16..0ecf2b1e 100644 --- a/src/mscp/data/rules/audit/audit_record_reduction_report_generation.yaml +++ b/src/mscp/data/rules/audit/audit_record_reduction_report_generation.yaml @@ -1,4 +1,3 @@ ---- id: audit_record_reduction_report_generation title: Audit Record Reduction and Report Generation discussion: |- diff --git a/src/mscp/data/rules/audit/audit_records_processing.yaml b/src/mscp/data/rules/audit/audit_records_processing.yaml index d5e59bc7..2ce43a76 100644 --- a/src/mscp/data/rules/audit/audit_records_processing.yaml +++ b/src/mscp/data/rules/audit/audit_records_processing.yaml @@ -1,4 +1,3 @@ ---- id: audit_records_processing title: Audit Record Reduction and Report Generation discussion: |- diff --git a/src/mscp/data/rules/audit/audit_retention_configure.yaml b/src/mscp/data/rules/audit/audit_retention_configure.yaml index 13b1100c..f3e2d778 100644 --- a/src/mscp/data/rules/audit/audit_retention_configure.yaml +++ b/src/mscp/data/rules/audit/audit_retention_configure.yaml @@ -1,4 +1,3 @@ ---- id: audit_retention_configure title: Configure Audit Retention to $ODV discussion: | diff --git a/src/mscp/data/rules/audit/audit_settings_failure_notify.yaml b/src/mscp/data/rules/audit/audit_settings_failure_notify.yaml index f0308dd7..8c857e65 100644 --- a/src/mscp/data/rules/audit/audit_settings_failure_notify.yaml +++ b/src/mscp/data/rules/audit/audit_settings_failure_notify.yaml @@ -1,4 +1,3 @@ ---- id: audit_settings_failure_notify title: Configure Audit Failure Notification discussion: | diff --git a/src/mscp/data/rules/auth/auth_smartcard_allow.yaml b/src/mscp/data/rules/auth/auth_smartcard_allow.yaml index d9fc5ef0..3db4a12d 100644 --- a/src/mscp/data/rules/auth/auth_smartcard_allow.yaml +++ b/src/mscp/data/rules/auth/auth_smartcard_allow.yaml @@ -1,4 +1,3 @@ ---- id: auth_smartcard_allow title: Allow Smartcard Authentication discussion: | diff --git a/src/mscp/data/rules/auth/auth_smartcard_certificate_trust_enforce_high.yaml b/src/mscp/data/rules/auth/auth_smartcard_certificate_trust_enforce_high.yaml index 6ee3d70b..e6aec4df 100644 --- a/src/mscp/data/rules/auth/auth_smartcard_certificate_trust_enforce_high.yaml +++ b/src/mscp/data/rules/auth/auth_smartcard_certificate_trust_enforce_high.yaml @@ -1,4 +1,3 @@ ---- id: auth_smartcard_certificate_trust_enforce_high title: Set Smartcard Certificate Trust to High discussion: | diff --git a/src/mscp/data/rules/auth/auth_smartcard_certificate_trust_enforce_moderate.yaml b/src/mscp/data/rules/auth/auth_smartcard_certificate_trust_enforce_moderate.yaml index 84f7ba3b..1e542f29 100644 --- a/src/mscp/data/rules/auth/auth_smartcard_certificate_trust_enforce_moderate.yaml +++ b/src/mscp/data/rules/auth/auth_smartcard_certificate_trust_enforce_moderate.yaml @@ -1,4 +1,3 @@ ---- id: auth_smartcard_certificate_trust_enforce_moderate title: Set Smartcard Certificate Trust to Moderate discussion: | diff --git a/src/mscp/data/rules/auth/auth_smartcard_enforce.yaml b/src/mscp/data/rules/auth/auth_smartcard_enforce.yaml index 057c1f41..6f2d63d3 100644 --- a/src/mscp/data/rules/auth/auth_smartcard_enforce.yaml +++ b/src/mscp/data/rules/auth/auth_smartcard_enforce.yaml @@ -1,4 +1,3 @@ ---- id: auth_smartcard_enforce title: Enforce Smartcard Authentication discussion: | diff --git a/src/mscp/data/rules/icloud/icloud_addressbook_disable.yaml b/src/mscp/data/rules/icloud/icloud_addressbook_disable.yaml index f817eae8..b9217270 100644 --- a/src/mscp/data/rules/icloud/icloud_addressbook_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_addressbook_disable.yaml @@ -1,10 +1,11 @@ ---- id: icloud_addressbook_disable title: Disable iCloud Address Book discussion: | - The macOS built-in Contacts.app connection to Apple's iCloud service _MUST_ be disabled. + The macOS built-in Contacts.app connection to Apple's iCloud service _MUST_ be disabled if iCloud is not an authorized service. Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated contact synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_appleid_system_settings_disable.yaml b/src/mscp/data/rules/icloud/icloud_appleid_system_settings_disable.yaml index caf256d9..6fcab83c 100644 --- a/src/mscp/data/rules/icloud/icloud_appleid_system_settings_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_appleid_system_settings_disable.yaml @@ -3,7 +3,7 @@ title: Disable the System Setting for Apple ID discussion: | The system setting for Apple ID _MUST_ be disabled. - Disabling the system setting prevents login to Apple ID and iCloud. + Disabling the system setting prevents login to an Apple Account and synchronizing data to Apple's iCloud service. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_backup_disabled.yaml b/src/mscp/data/rules/icloud/icloud_backup_disabled.yaml index 2261f686..f83ba24a 100644 --- a/src/mscp/data/rules/icloud/icloud_backup_disabled.yaml +++ b/src/mscp/data/rules/icloud/icloud_backup_disabled.yaml @@ -1,8 +1,11 @@ ---- id: icloud_backup_disabled title: Ensure iCloud Backup is set to Disabled discussion: | - iCloud backup _MUST_ be disabled. + iCloud backup _MUST_ be disabled if iCloud is not an authorized service. + + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated backup synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_bookmarks_disable.yaml b/src/mscp/data/rules/icloud/icloud_bookmarks_disable.yaml index a7134325..7dd825c7 100644 --- a/src/mscp/data/rules/icloud/icloud_bookmarks_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_bookmarks_disable.yaml @@ -1,10 +1,11 @@ ---- id: icloud_bookmarks_disable title: Disable iCloud Bookmarks discussion: | - The macOS built-in Safari.app bookmark synchronization via the iCloud service _MUST_ be disabled. + The macOS built-in Safari.app bookmark synchronization via the iCloud service _MUST_ be disabled if iCloud is not an authorized service. - Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated bookmark synchronization _MUST_ be controlled by an organization approved service. + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated bookmark synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_calendar_disable.yaml b/src/mscp/data/rules/icloud/icloud_calendar_disable.yaml index dc81b911..6f8088f9 100644 --- a/src/mscp/data/rules/icloud/icloud_calendar_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_calendar_disable.yaml @@ -1,10 +1,11 @@ ---- id: icloud_calendar_disable title: Disable the iCloud Calendar Services discussion: | - The macOS built-in Calendar.app connection to Apple's iCloud service _MUST_ be disabled. + The macOS built-in Calendar.app connection to Apple's iCloud service _MUST_ be disabled, if iCloud is not an authorized service. - Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service. + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_drive_disable.yaml b/src/mscp/data/rules/icloud/icloud_drive_disable.yaml index da67e76f..94b68c0d 100644 --- a/src/mscp/data/rules/icloud/icloud_drive_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_drive_disable.yaml @@ -3,7 +3,9 @@ title: Disable iCloud Document Sync discussion: | The macOS built-in iCloud document synchronization service _MUST_ be disabled to prevent organizational data from being synchronized to personal or non-approved storage. - Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated document synchronization _MUST_ be controlled by an organization approved service. + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated document synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_enterprisebook_metadata_sync_disable.yaml b/src/mscp/data/rules/icloud/icloud_enterprisebook_metadata_sync_disable.yaml index a13d5642..e7520c98 100644 --- a/src/mscp/data/rules/icloud/icloud_enterprisebook_metadata_sync_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_enterprisebook_metadata_sync_disable.yaml @@ -1,9 +1,11 @@ id: icloud_enterprisebook_metadata_sync_disable title: Preventing synchronization of enterprise book meta data. discussion: | - The iOS device _MUST_ be configured to prevent the synchronization of enterprise book meta data to Apple iCloud servers. + The iOS device _MUST_ be configured to prevent the synchronization of enterprise book meta data to Apple iCloud servers, if iCloud is not an authorized service. - Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service. + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_freeform_disable.yaml b/src/mscp/data/rules/icloud/icloud_freeform_disable.yaml index f7cd5f4b..7ae96edf 100644 --- a/src/mscp/data/rules/icloud/icloud_freeform_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_freeform_disable.yaml @@ -1,10 +1,11 @@ ---- id: icloud_freeform_disable title: Disable the iCloud Freeform Services discussion: | - The macOS built-in Freeform.app connection to Apple's iCloud service _MUST_ be disabled. + The macOS built-in Freeform.app connection to Apple's iCloud service _MUST_ be disabled, if iCloud is not an authorized service. - Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated calendar synchronization _MUST_ be controlled by an organization approved service. + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_game_center_disable.yaml b/src/mscp/data/rules/icloud/icloud_game_center_disable.yaml index 15ec5f84..945f78d0 100644 --- a/src/mscp/data/rules/icloud/icloud_game_center_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_game_center_disable.yaml @@ -1,9 +1,11 @@ ---- id: icloud_game_center_disable title: Disable iCloud Game Center discussion: | - This works only with supervised devices (MDM) and allows to disable Apple Game Center. The rationale is Game Center is using Apple ID and will shared data on AppleID based services, therefore, Game Center _MUST_ be disabled. + This works only with supervised devices and allows to disable Apple Game Center. The rationale is Game Center is using Apple Account and will share data on iCloud based services, therefore, Game Center _MUST_ be disabled. + This setting also prohibits functionality of adding friends to Game Center. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_keychain_disable.yaml b/src/mscp/data/rules/icloud/icloud_keychain_disable.yaml index a96bc593..33dc98b1 100644 --- a/src/mscp/data/rules/icloud/icloud_keychain_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_keychain_disable.yaml @@ -1,9 +1,11 @@ id: icloud_keychain_disable title: Disable iCloud Keychain Sync discussion: | - The system's ability to automatically synchronize a user's passwords to their iCloud account _MUST_ be disabled. + The system's ability to automatically synchronize a user's passwords to their iCloud account _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved password management service. Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, password management and synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_mail_disable.yaml b/src/mscp/data/rules/icloud/icloud_mail_disable.yaml index 7624241c..073365ee 100644 --- a/src/mscp/data/rules/icloud/icloud_mail_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_mail_disable.yaml @@ -1,10 +1,11 @@ ---- id: icloud_mail_disable title: Disable iCloud Mail discussion: | - The macOS built-in Mail.app connection to Apple's iCloud service _MUST_ be disabled. + The macOS built-in Mail.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved mail management service. Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated mail synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_managed_apps_store_data_disabled.yaml b/src/mscp/data/rules/icloud/icloud_managed_apps_store_data_disabled.yaml index a8a50c0e..a9b67bab 100644 --- a/src/mscp/data/rules/icloud/icloud_managed_apps_store_data_disabled.yaml +++ b/src/mscp/data/rules/icloud/icloud_managed_apps_store_data_disabled.yaml @@ -1,8 +1,11 @@ ---- id: icloud_managed_apps_store_data_disabled title: Ensure Managed Apps Storing Data in iCloud is Set to Disabled discussion: | - Managed Apps _MUST_ not store data in iCloud. + Managed Apps _MUST_ not store data in iCloud, unless the organization has explicitly authorized the use of iCloud as a approved data management service. + + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_notes_disable.yaml b/src/mscp/data/rules/icloud/icloud_notes_disable.yaml index 81ef28bc..cfc264dc 100644 --- a/src/mscp/data/rules/icloud/icloud_notes_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_notes_disable.yaml @@ -1,10 +1,11 @@ ---- id: icloud_notes_disable title: Disable iCloud Notes discussion: | - The macOS built-in Notes.app connection to Apple's iCloud service _MUST_ be disabled. + The macOS built-in Notes.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved notes management service. - Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated Notes synchronization _MUST_ be controlled by an organization approved service. + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated notes synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational contact data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_photo_stream_disable.yaml b/src/mscp/data/rules/icloud/icloud_photo_stream_disable.yaml index 816a4344..6178e1bf 100644 --- a/src/mscp/data/rules/icloud/icloud_photo_stream_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_photo_stream_disable.yaml @@ -1,8 +1,11 @@ ---- id: icloud_photo_stream_disable title: Ensure Photo Stream is set to Disabled discussion: | - If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DoD sensitive information. + The built-in Photos.app's Photo Stream connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service. + + Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_photos_disable.yaml b/src/mscp/data/rules/icloud/icloud_photos_disable.yaml index baf5bfb0..15f37775 100644 --- a/src/mscp/data/rules/icloud/icloud_photos_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_photos_disable.yaml @@ -1,9 +1,11 @@ id: icloud_photos_disable title: Disable iCloud Photo Library discussion: | - The built-in Photos.app's connection to Apple's iCloud service _MUST_ be disabled. + The built-in Photos.app's connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service. - Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service. + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_private_relay_disable.yaml b/src/mscp/data/rules/icloud/icloud_private_relay_disable.yaml index d68ae927..32abed14 100644 --- a/src/mscp/data/rules/icloud/icloud_private_relay_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_private_relay_disable.yaml @@ -1,4 +1,3 @@ ---- id: icloud_private_relay_disable title: Disable iCloud Private Relay discussion: | diff --git a/src/mscp/data/rules/icloud/icloud_reminders_disable.yaml b/src/mscp/data/rules/icloud/icloud_reminders_disable.yaml index 46211ca1..e8856572 100644 --- a/src/mscp/data/rules/icloud/icloud_reminders_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_reminders_disable.yaml @@ -1,10 +1,11 @@ ---- id: icloud_reminders_disable title: Disable iCloud Reminders discussion: | - The macOS built-in Reminders.app connection to Apple's iCloud service _MUST_ be disabled. + The macOS built-in Reminders.app connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved reminder management service. - Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated reminders synchronization _MUST_ be controlled by an organization approved service. + Apple's iCloud service does not provide an organization with enough control over the storage and access of data, and, therefore, automated reminders synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_shared_photo_stream_disable.yaml b/src/mscp/data/rules/icloud/icloud_shared_photo_stream_disable.yaml index 87074fb0..917592c9 100644 --- a/src/mscp/data/rules/icloud/icloud_shared_photo_stream_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_shared_photo_stream_disable.yaml @@ -1,8 +1,11 @@ ---- id: icloud_shared_photo_stream_disable title: Ensure Shared Photo Stream is set to Disabled discussion: | - If a user is able to configure the security setting, the user could inadvertently or maliciously set it to a value that poses unacceptable risk to DoD information systems. An adversary could exploit vulnerabilities created by the weaker configuration to compromise DoD sensitive information. + The built-in Photos.app's Photo Stream connection to Apple's iCloud service _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved photo management service. + + Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated photo synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational photo data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/icloud/icloud_sync_disable.yaml b/src/mscp/data/rules/icloud/icloud_sync_disable.yaml index 3d6db23d..66192a77 100644 --- a/src/mscp/data/rules/icloud/icloud_sync_disable.yaml +++ b/src/mscp/data/rules/icloud/icloud_sync_disable.yaml @@ -1,10 +1,11 @@ ---- id: icloud_sync_disable title: Disable iCloud Desktop and Document Folder Sync discussion: | - The macOS system's ability to automatically synchronize a user's desktop and documents folder to their iCloud Drive _MUST_ be disabled. + The macOS system's ability to automatically synchronize a user's desktop and documents folder to their iCloud Drive _MUST_ be disabled, unless the organization has explicitly authorized the use of iCloud as a approved file management service. Apple's iCloud service does not provide an organization with enough control over the storage and access of data and, therefore, automated file synchronization _MUST_ be controlled by an organization approved service. + + This requirement helps ensure that organizational file data is managed in accordance with established security, privacy, access-control, and data governance requirements. references: nist: cce: diff --git a/src/mscp/data/rules/os/os_account_modification_disable.yaml b/src/mscp/data/rules/os/os_account_modification_disable.yaml index dc7c212d..f94ae482 100644 --- a/src/mscp/data/rules/os/os_account_modification_disable.yaml +++ b/src/mscp/data/rules/os/os_account_modification_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_account_modification_disable title: Disable AppleID and Internet Account Modifications discussion: | diff --git a/src/mscp/data/rules/os/os_airdrop_unmanaged_destination_enable.yaml b/src/mscp/data/rules/os/os_airdrop_unmanaged_destination_enable.yaml index 644dd53a..125b0da2 100644 --- a/src/mscp/data/rules/os/os_airdrop_unmanaged_destination_enable.yaml +++ b/src/mscp/data/rules/os/os_airdrop_unmanaged_destination_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_airdrop_unmanaged_destination_enable title: Ensure Treat AirDrop as unmanaged destination is set to Enabled discussion: | diff --git a/src/mscp/data/rules/os/os_airplay_incoming_password_require.yaml b/src/mscp/data/rules/os/os_airplay_incoming_password_require.yaml index bf894041..7517bfb8 100644 --- a/src/mscp/data/rules/os/os_airplay_incoming_password_require.yaml +++ b/src/mscp/data/rules/os/os_airplay_incoming_password_require.yaml @@ -1,4 +1,3 @@ ---- id: os_airplay_incoming_password_require title: Require Passcode for Incoming Airplay Connection Requests discussion: | diff --git a/src/mscp/data/rules/os/os_airprint_credential_storage_disable.yaml b/src/mscp/data/rules/os/os_airprint_credential_storage_disable.yaml index 34594399..c553029e 100644 --- a/src/mscp/data/rules/os/os_airprint_credential_storage_disable.yaml +++ b/src/mscp/data/rules/os/os_airprint_credential_storage_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_airprint_credential_storage_disable title: Disable Storage of AirPrint Credentials discussion: | diff --git a/src/mscp/data/rules/os/os_airprint_disable.yaml b/src/mscp/data/rules/os/os_airprint_disable.yaml index 392bdfef..c79e801e 100644 --- a/src/mscp/data/rules/os/os_airprint_disable.yaml +++ b/src/mscp/data/rules/os/os_airprint_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_airprint_disable title: Disable AirPrint discussion: | diff --git a/src/mscp/data/rules/os/os_airprint_force_trusted_TLS.yaml b/src/mscp/data/rules/os/os_airprint_force_trusted_TLS.yaml index 10adcc84..2ca5b28d 100644 --- a/src/mscp/data/rules/os/os_airprint_force_trusted_TLS.yaml +++ b/src/mscp/data/rules/os/os_airprint_force_trusted_TLS.yaml @@ -1,4 +1,3 @@ ---- id: os_airprint_force_trusted_TLS title: Requires trusted certificates for TLS printing communication discussion: | diff --git a/src/mscp/data/rules/os/os_allow_contacts_read_managed_sources_unmanaged_destinations_disable.yaml b/src/mscp/data/rules/os/os_allow_contacts_read_managed_sources_unmanaged_destinations_disable.yaml index 28c03c70..c7de7d21 100644 --- a/src/mscp/data/rules/os/os_allow_contacts_read_managed_sources_unmanaged_destinations_disable.yaml +++ b/src/mscp/data/rules/os/os_allow_contacts_read_managed_sources_unmanaged_destinations_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_allow_contacts_read_managed_sources_unmanaged_destinations_disable title: Ensure Managed Apps Cannot Read Unmanaged Contact Accounts discussion: | diff --git a/src/mscp/data/rules/os/os_allow_contacts_write_managed_sources_unmanaged_destinations_disable.yaml b/src/mscp/data/rules/os/os_allow_contacts_write_managed_sources_unmanaged_destinations_disable.yaml index 7ad3bd62..e5556734 100644 --- a/src/mscp/data/rules/os/os_allow_contacts_write_managed_sources_unmanaged_destinations_disable.yaml +++ b/src/mscp/data/rules/os/os_allow_contacts_write_managed_sources_unmanaged_destinations_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_allow_contacts_write_managed_sources_unmanaged_destinations_disable title: Ensure Managed Apps Cannot Write to Unmanaged Contact Accounts discussion: | diff --git a/src/mscp/data/rules/os/os_allow_documents_managed_sources_unmanaged_destinations_disable.yaml b/src/mscp/data/rules/os/os_allow_documents_managed_sources_unmanaged_destinations_disable.yaml index d2a727b6..b527d7f6 100644 --- a/src/mscp/data/rules/os/os_allow_documents_managed_sources_unmanaged_destinations_disable.yaml +++ b/src/mscp/data/rules/os/os_allow_documents_managed_sources_unmanaged_destinations_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_allow_documents_managed_sources_unmanaged_destinations_disable title: Ensure Allow documents from managed sources in unmanaged destinations is set to Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_allow_documents_unmanaged_sources_managed_destinations_disable.yaml b/src/mscp/data/rules/os/os_allow_documents_unmanaged_sources_managed_destinations_disable.yaml index db85f0b8..e81aaf2f 100644 --- a/src/mscp/data/rules/os/os_allow_documents_unmanaged_sources_managed_destinations_disable.yaml +++ b/src/mscp/data/rules/os/os_allow_documents_unmanaged_sources_managed_destinations_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_allow_documents_unmanaged_sources_managed_destinations_disable title: Ensure Allow documents from unmanaged sources in managed destinations is set to Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_allow_info_passed.yaml b/src/mscp/data/rules/os/os_allow_info_passed.yaml index 0e9f1612..2eeee5f9 100644 --- a/src/mscp/data/rules/os/os_allow_info_passed.yaml +++ b/src/mscp/data/rules/os/os_allow_info_passed.yaml @@ -1,4 +1,3 @@ ---- id: os_allow_info_passed title: Allow Information Transfer with Other Operating Systems discussion: |- diff --git a/src/mscp/data/rules/os/os_anti_virus_installed.yaml b/src/mscp/data/rules/os/os_anti_virus_installed.yaml index 82130229..86c48932 100644 --- a/src/mscp/data/rules/os/os_anti_virus_installed.yaml +++ b/src/mscp/data/rules/os/os_anti_virus_installed.yaml @@ -1,4 +1,3 @@ ---- id: os_anti_virus_installed title: Must Use an Approved Antivirus Program discussion: | diff --git a/src/mscp/data/rules/os/os_apple_intelligence_pcc_disable.yaml b/src/mscp/data/rules/os/os_apple_intelligence_pcc_disable.yaml index 51de3f43..da05df2c 100644 --- a/src/mscp/data/rules/os/os_apple_intelligence_pcc_disable.yaml +++ b/src/mscp/data/rules/os/os_apple_intelligence_pcc_disable.yaml @@ -1,8 +1,15 @@ ---- id: os_apple_intelligence_pcc_disable title: Disable Apple Intelligence Private Cloud Compute discussion: | - Apple Intelligence Private Cloud Compute sends data to off-device infrastructure that is not directly controlled by the organization. Therefore, Apple Intelligence features that rely on off-device processing MUST be disabled unless explicitly approved by the organization. + Apple Intelligence Private Cloud Compute sends data to off-device infrastructure that is not directly controlled by the organization. Therefore, Apple Intelligence features that rely on off-device processing _MUST_ be disabled unless explicitly approved by the organization. + + This requirement helps ensure that organizational data is managed in accordance with established security, privacy, access-control, and data governance requirements. + + Data may be sent to Apple Intelligence Private Cloud Compute even when Apple's provided controls around Apple Intelligence are disabled. Therefore, organizations should ensure that Apple Intelligence Private Cloud Compute is disabled by blocking access to the following domains: + - apple-relay.apple.com + - apple-relay.fastly-edge.com + - apple-relay.cloudflare.com + - cp4.cloudflare.com references: nist: cce: @@ -52,9 +59,15 @@ platforms: result: integer: 4 fix: - shell: |- + shell: |- + note="### Apple Intelligence Private Cloud Compute is disabled by the organization (apple-relay, cp4.cloudflare.com, etc). Added by the mSCP ###" apple_intelligence_servers=("127.0.0.1 apple-relay.cloudflare.com" "127.0.0.1 apple-relay.fastly-edge.com" "127.0.0.1 cp4.cloudflare.com" "127.0.0.1 apple-relay.apple.com") + host_file=$(/bin/cat /etc/hosts) + + if ! /usr/bin/grep -qxF "$note" "$hosts_file" 2>/dev/null; then + echo "$note" >> "$hosts_file" + fi for config in $apple_intelligence_servers; do if ! echo $host_file | /usr/bin/grep -q -i "^$config" 2>/dev/null; then /usr/bin/grep -qxF "^$config" "/etc/hosts" 2>/dev/null || echo "$config" >> "/etc/hosts" @@ -72,3 +85,4 @@ tags: - cmmc_lvl1 - cnssi-1253_moderate - hicp_lp + - new \ No newline at end of file diff --git a/src/mscp/data/rules/os/os_apple_watch_pairing_disable.yaml b/src/mscp/data/rules/os/os_apple_watch_pairing_disable.yaml index cbb5bd53..037a888b 100644 --- a/src/mscp/data/rules/os/os_apple_watch_pairing_disable.yaml +++ b/src/mscp/data/rules/os/os_apple_watch_pairing_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_apple_watch_pairing_disable title: Ensure Apple Watch Pairing is Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_apple_watch_wrist_detection_enable.yaml b/src/mscp/data/rules/os/os_apple_watch_wrist_detection_enable.yaml index 03c9da3a..c484c2dd 100644 --- a/src/mscp/data/rules/os/os_apple_watch_wrist_detection_enable.yaml +++ b/src/mscp/data/rules/os/os_apple_watch_wrist_detection_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_apple_watch_wrist_detection_enable title: Ensure Force Apple Watch wrist detection is set to Enabled discussion: | diff --git a/src/mscp/data/rules/os/os_appleid_prompt_disable.yaml b/src/mscp/data/rules/os/os_appleid_prompt_disable.yaml index 1609f724..92f07a8c 100644 --- a/src/mscp/data/rules/os/os_appleid_prompt_disable.yaml +++ b/src/mscp/data/rules/os/os_appleid_prompt_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_appleid_prompt_disable title: Disable Apple ID Setup during Setup Assistant discussion: | diff --git a/src/mscp/data/rules/os/os_application_allow_list.yaml b/src/mscp/data/rules/os/os_application_allow_list.yaml index 29109f1f..df7cdb21 100644 --- a/src/mscp/data/rules/os/os_application_allow_list.yaml +++ b/src/mscp/data/rules/os/os_application_allow_list.yaml @@ -1,4 +1,3 @@ ---- id: os_application_allow_list title: Define Allowed Applications discussion: | diff --git a/src/mscp/data/rules/os/os_application_deny_list.yaml b/src/mscp/data/rules/os/os_application_deny_list.yaml index d8167a1a..2318b80f 100644 --- a/src/mscp/data/rules/os/os_application_deny_list.yaml +++ b/src/mscp/data/rules/os/os_application_deny_list.yaml @@ -1,4 +1,3 @@ ---- id: os_application_deny_list title: Apps not allowed on the device discussion: | diff --git a/src/mscp/data/rules/os/os_application_sandboxing.yaml b/src/mscp/data/rules/os/os_application_sandboxing.yaml index 987949de..75eeb780 100644 --- a/src/mscp/data/rules/os/os_application_sandboxing.yaml +++ b/src/mscp/data/rules/os/os_application_sandboxing.yaml @@ -1,4 +1,3 @@ ---- id: os_application_sandboxing title: Ensure Separate Execution Domain for Processes discussion: |- diff --git a/src/mscp/data/rules/os/os_asl_log_files_owner_group_configure.yaml b/src/mscp/data/rules/os/os_asl_log_files_owner_group_configure.yaml index 37764ad1..07957e88 100644 --- a/src/mscp/data/rules/os/os_asl_log_files_owner_group_configure.yaml +++ b/src/mscp/data/rules/os/os_asl_log_files_owner_group_configure.yaml @@ -1,4 +1,3 @@ ---- id: os_asl_log_files_owner_group_configure title: Configure Apple System Log Files Owned by Root and Group to Wheel discussion: | diff --git a/src/mscp/data/rules/os/os_asl_log_files_permissions_configure.yaml b/src/mscp/data/rules/os/os_asl_log_files_permissions_configure.yaml index 8de9cd1a..a4cee386 100644 --- a/src/mscp/data/rules/os/os_asl_log_files_permissions_configure.yaml +++ b/src/mscp/data/rules/os/os_asl_log_files_permissions_configure.yaml @@ -1,4 +1,3 @@ ---- id: os_asl_log_files_permissions_configure title: Configure Apple System Log Files To Mode 640 or Less Permissive discussion: | diff --git a/src/mscp/data/rules/os/os_auth_peripherals.yaml b/src/mscp/data/rules/os/os_auth_peripherals.yaml index a4592131..635a7f34 100644 --- a/src/mscp/data/rules/os/os_auth_peripherals.yaml +++ b/src/mscp/data/rules/os/os_auth_peripherals.yaml @@ -1,4 +1,3 @@ ---- id: os_auth_peripherals title: Must Authenticate Before Establishing a Connection discussion: |- diff --git a/src/mscp/data/rules/os/os_authenticated_root_enable.yaml b/src/mscp/data/rules/os/os_authenticated_root_enable.yaml index 11f9e209..cfac57b5 100644 --- a/src/mscp/data/rules/os/os_authenticated_root_enable.yaml +++ b/src/mscp/data/rules/os/os_authenticated_root_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_authenticated_root_enable title: Enable Authenticated Root discussion: | diff --git a/src/mscp/data/rules/os/os_authentication_password_autofill_enable.yaml b/src/mscp/data/rules/os/os_authentication_password_autofill_enable.yaml index 399504d2..1724fac9 100644 --- a/src/mscp/data/rules/os/os_authentication_password_autofill_enable.yaml +++ b/src/mscp/data/rules/os/os_authentication_password_autofill_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_authentication_password_autofill_enable title: Ensure Require Touch ID / Face ID authentication before AutoFill is set to Enabled discussion: | diff --git a/src/mscp/data/rules/os/os_auto_correction_disable.yaml b/src/mscp/data/rules/os/os_auto_correction_disable.yaml index 328adb22..adb9b287 100644 --- a/src/mscp/data/rules/os/os_auto_correction_disable.yaml +++ b/src/mscp/data/rules/os/os_auto_correction_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_auto_correction_disable title: Disable Auto Correction discussion: | diff --git a/src/mscp/data/rules/os/os_automatic_app_download_disable.yaml b/src/mscp/data/rules/os/os_automatic_app_download_disable.yaml index 98df0f55..fbc78616 100644 --- a/src/mscp/data/rules/os/os_automatic_app_download_disable.yaml +++ b/src/mscp/data/rules/os/os_automatic_app_download_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_automatic_app_download_disable title: Disallow Automatic Downloads of Apps Purchased on other Apple Devices. discussion: | diff --git a/src/mscp/data/rules/os/os_blank_bluray_disable.yaml b/src/mscp/data/rules/os/os_blank_bluray_disable.yaml index 138a9338..131f497b 100644 --- a/src/mscp/data/rules/os/os_blank_bluray_disable.yaml +++ b/src/mscp/data/rules/os/os_blank_bluray_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_blank_bluray_disable title: Disable Blank Blu Ray discussion: | diff --git a/src/mscp/data/rules/os/os_blank_cd_disable.yaml b/src/mscp/data/rules/os/os_blank_cd_disable.yaml index 628544e9..9d00df89 100644 --- a/src/mscp/data/rules/os/os_blank_cd_disable.yaml +++ b/src/mscp/data/rules/os/os_blank_cd_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_blank_cd_disable title: Disable Blank CD discussion: | diff --git a/src/mscp/data/rules/os/os_blank_dvd_disable.yaml b/src/mscp/data/rules/os/os_blank_dvd_disable.yaml index 8159aba4..633a4525 100644 --- a/src/mscp/data/rules/os/os_blank_dvd_disable.yaml +++ b/src/mscp/data/rules/os/os_blank_dvd_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_blank_dvd_disable title: Disable Blank DVD discussion: | diff --git a/src/mscp/data/rules/os/os_bluetooth_modification_disable.yaml b/src/mscp/data/rules/os/os_bluetooth_modification_disable.yaml index 372b091d..3028d084 100644 --- a/src/mscp/data/rules/os/os_bluetooth_modification_disable.yaml +++ b/src/mscp/data/rules/os/os_bluetooth_modification_disable.yaml @@ -62,6 +62,7 @@ tags: - cnssi-1253_moderate - cnssi-1253_low - cnssi-1253_high + - new mobileconfig_info: - PayloadType: com.apple.applicationaccess PayloadContent: diff --git a/src/mscp/data/rules/os/os_bluray_read_only_enforce.yaml b/src/mscp/data/rules/os/os_bluray_read_only_enforce.yaml index 1f17db49..54f5f32e 100644 --- a/src/mscp/data/rules/os/os_bluray_read_only_enforce.yaml +++ b/src/mscp/data/rules/os/os_bluray_read_only_enforce.yaml @@ -1,4 +1,3 @@ ---- id: os_bluray_read_only_enforce title: Enforce Blu Ray Read Only discussion: | diff --git a/src/mscp/data/rules/os/os_bonjour_disable.yaml b/src/mscp/data/rules/os/os_bonjour_disable.yaml index 057815f0..cfcf66d2 100644 --- a/src/mscp/data/rules/os/os_bonjour_disable.yaml +++ b/src/mscp/data/rules/os/os_bonjour_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_bonjour_disable title: Disable Bonjour Multicast discussion: | diff --git a/src/mscp/data/rules/os/os_burn_support_disable.yaml b/src/mscp/data/rules/os/os_burn_support_disable.yaml index 018fed11..7701715d 100644 --- a/src/mscp/data/rules/os/os_burn_support_disable.yaml +++ b/src/mscp/data/rules/os/os_burn_support_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_burn_support_disable title: Disable Burn Support discussion: | diff --git a/src/mscp/data/rules/os/os_camera_disable.yaml b/src/mscp/data/rules/os/os_camera_disable.yaml index ab93872c..800f2afb 100644 --- a/src/mscp/data/rules/os/os_camera_disable.yaml +++ b/src/mscp/data/rules/os/os_camera_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_camera_disable title: Disable Camera discussion: | diff --git a/src/mscp/data/rules/os/os_cd_read_only_enforce.yaml b/src/mscp/data/rules/os/os_cd_read_only_enforce.yaml index 698de94f..7058bb61 100644 --- a/src/mscp/data/rules/os/os_cd_read_only_enforce.yaml +++ b/src/mscp/data/rules/os/os_cd_read_only_enforce.yaml @@ -1,4 +1,3 @@ ---- id: os_cd_read_only_enforce title: Enforce CD Read Only discussion: | diff --git a/src/mscp/data/rules/os/os_certificate_authority_trust.yaml b/src/mscp/data/rules/os/os_certificate_authority_trust.yaml index 33aa8ff0..0446ffb0 100644 --- a/src/mscp/data/rules/os/os_certificate_authority_trust.yaml +++ b/src/mscp/data/rules/os/os_certificate_authority_trust.yaml @@ -1,4 +1,3 @@ ---- id: os_certificate_authority_trust title: Issue or Obtain Public Key Certificates from an Approved Service Provider discussion: | diff --git a/src/mscp/data/rules/os/os_change_security_attributes.yaml b/src/mscp/data/rules/os/os_change_security_attributes.yaml index 82d28699..71ed3584 100644 --- a/src/mscp/data/rules/os/os_change_security_attributes.yaml +++ b/src/mscp/data/rules/os/os_change_security_attributes.yaml @@ -1,4 +1,3 @@ ---- id: os_change_security_attributes title: Allow Administrators to Modify Security Settings and System Attributes discussion: |- diff --git a/src/mscp/data/rules/os/os_chat_disable.yaml b/src/mscp/data/rules/os/os_chat_disable.yaml index af43354c..d2b855f5 100644 --- a/src/mscp/data/rules/os/os_chat_disable.yaml +++ b/src/mscp/data/rules/os/os_chat_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_chat_disable title: Prevent the Usage of iMessage discussion: | diff --git a/src/mscp/data/rules/os/os_config_data_install_enforce.yaml b/src/mscp/data/rules/os/os_config_data_install_enforce.yaml index ddb6338f..57857642 100644 --- a/src/mscp/data/rules/os/os_config_data_install_enforce.yaml +++ b/src/mscp/data/rules/os/os_config_data_install_enforce.yaml @@ -61,6 +61,7 @@ references: - 8.19.01 platforms: macOS: + '27.0': {} '26.0': benchmarks: - name: cis_lvl1 diff --git a/src/mscp/data/rules/os/os_continuous_monitoring.yaml b/src/mscp/data/rules/os/os_continuous_monitoring.yaml index 6dcc6296..b863180d 100644 --- a/src/mscp/data/rules/os/os_continuous_monitoring.yaml +++ b/src/mscp/data/rules/os/os_continuous_monitoring.yaml @@ -1,4 +1,3 @@ ---- id: os_continuous_monitoring title: Configure Automated Flaw Remediation discussion: |- diff --git a/src/mscp/data/rules/os/os_default_browser_modification_disable.yaml b/src/mscp/data/rules/os/os_default_browser_modification_disable.yaml index 101c9bc3..9af2cd3f 100644 --- a/src/mscp/data/rules/os/os_default_browser_modification_disable.yaml +++ b/src/mscp/data/rules/os/os_default_browser_modification_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_default_browser_modification_disable title: Disable Modifying the Default Web Browser Application discussion: | diff --git a/src/mscp/data/rules/os/os_default_calling_modification_disable.yaml b/src/mscp/data/rules/os/os_default_calling_modification_disable.yaml index 9b196787..08f3a98b 100644 --- a/src/mscp/data/rules/os/os_default_calling_modification_disable.yaml +++ b/src/mscp/data/rules/os/os_default_calling_modification_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_default_calling_modification_disable title: Disable Modifying the Default Calling Application discussion: | diff --git a/src/mscp/data/rules/os/os_default_messaging_modification_disable.yaml b/src/mscp/data/rules/os/os_default_messaging_modification_disable.yaml index 9b2a6973..a89834c1 100644 --- a/src/mscp/data/rules/os/os_default_messaging_modification_disable.yaml +++ b/src/mscp/data/rules/os/os_default_messaging_modification_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_default_messaging_modification_disable title: Disable Modifying the Default Messaging Application discussion: | diff --git a/src/mscp/data/rules/os/os_definition_lookup_disable.yaml b/src/mscp/data/rules/os/os_definition_lookup_disable.yaml index cc06468c..b2e70e03 100644 --- a/src/mscp/data/rules/os/os_definition_lookup_disable.yaml +++ b/src/mscp/data/rules/os/os_definition_lookup_disable.yaml @@ -71,6 +71,7 @@ tags: - cnssi-1253_moderate - cnssi-1253_low - cnssi-1253_high + - new mobileconfig_info: - PayloadType: com.apple.applicationaccess PayloadContent: diff --git a/src/mscp/data/rules/os/os_device_name_change_disable.yaml b/src/mscp/data/rules/os/os_device_name_change_disable.yaml index 541cc8ca..7544fb32 100644 --- a/src/mscp/data/rules/os/os_device_name_change_disable.yaml +++ b/src/mscp/data/rules/os/os_device_name_change_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_device_name_change_disable title: Disable Device Name Changes discussion: | diff --git a/src/mscp/data/rules/os/os_diagnostics_reports_modification_disable.yaml b/src/mscp/data/rules/os/os_diagnostics_reports_modification_disable.yaml index 6b1c7b46..9150457b 100644 --- a/src/mscp/data/rules/os/os_diagnostics_reports_modification_disable.yaml +++ b/src/mscp/data/rules/os/os_diagnostics_reports_modification_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_diagnostics_reports_modification_disable title: Disable changing Sending Diagnostic and Usage Data to Apple discussion: | diff --git a/src/mscp/data/rules/os/os_dictation_disable.yaml b/src/mscp/data/rules/os/os_dictation_disable.yaml index 84a39191..1da105d5 100644 --- a/src/mscp/data/rules/os/os_dictation_disable.yaml +++ b/src/mscp/data/rules/os/os_dictation_disable.yaml @@ -69,19 +69,6 @@ platforms: benchmarks: - name: disa_stig severity: medium - enforcement_info: - check: - shell: |- - /usr/bin/osascript -l JavaScript << EOS - $.NSUserDefaults.alloc.initWithSuiteName('com.apple.applicationaccess')\ - .objectForKey('allowDictation').js - EOS - result: - string: 'false' - mobileconfig_info: - - PayloadType: com.apple.applicationaccess - PayloadContent: - - allowDictation: false '15.0': benchmarks: - name: disa_stig diff --git a/src/mscp/data/rules/os/os_directory_services_configured.yaml b/src/mscp/data/rules/os/os_directory_services_configured.yaml index 1f62a745..7fee8578 100644 --- a/src/mscp/data/rules/os/os_directory_services_configured.yaml +++ b/src/mscp/data/rules/os/os_directory_services_configured.yaml @@ -1,4 +1,3 @@ ---- id: os_directory_services_configured title: Integrate System into a Directory Services Infrastructure discussion: | diff --git a/src/mscp/data/rules/os/os_disk_image_disable.yaml b/src/mscp/data/rules/os/os_disk_image_disable.yaml index fa0c68fe..03fb185d 100644 --- a/src/mscp/data/rules/os/os_disk_image_disable.yaml +++ b/src/mscp/data/rules/os/os_disk_image_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_disk_image_disable title: Disable Disk Images discussion: | diff --git a/src/mscp/data/rules/os/os_dvdram_disable.yaml b/src/mscp/data/rules/os/os_dvdram_disable.yaml index f29176f3..b9e3758a 100644 --- a/src/mscp/data/rules/os/os_dvdram_disable.yaml +++ b/src/mscp/data/rules/os/os_dvdram_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_dvdram_disable title: Disable DVD-RAM discussion: | diff --git a/src/mscp/data/rules/os/os_enforce_access_restrictions.yaml b/src/mscp/data/rules/os/os_enforce_access_restrictions.yaml index 3411adea..78759e72 100644 --- a/src/mscp/data/rules/os/os_enforce_access_restrictions.yaml +++ b/src/mscp/data/rules/os/os_enforce_access_restrictions.yaml @@ -1,4 +1,3 @@ ---- id: os_enforce_access_restrictions title: Enforce Access Restrictions discussion: |- diff --git a/src/mscp/data/rules/os/os_enterprise_books_disable.yaml b/src/mscp/data/rules/os/os_enterprise_books_disable.yaml index 4d7f5683..ee3159c2 100644 --- a/src/mscp/data/rules/os/os_enterprise_books_disable.yaml +++ b/src/mscp/data/rules/os/os_enterprise_books_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_enterprise_books_disable title: Ensure Backup of Enterprise Books is set to Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_erase_contents_and_settings_disable.yaml b/src/mscp/data/rules/os/os_erase_contents_and_settings_disable.yaml index 963f46fe..f9503e03 100644 --- a/src/mscp/data/rules/os/os_erase_contents_and_settings_disable.yaml +++ b/src/mscp/data/rules/os/os_erase_contents_and_settings_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_erase_contents_and_settings_disable title: Ensure Allow Erase All Content and Settings is set to Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_error_message.yaml b/src/mscp/data/rules/os/os_error_message.yaml index 62dfe4fa..d409a32f 100644 --- a/src/mscp/data/rules/os/os_error_message.yaml +++ b/src/mscp/data/rules/os/os_error_message.yaml @@ -1,4 +1,3 @@ ---- id: os_error_message title: Generate Error Messages without Exploitable Information discussion: |- diff --git a/src/mscp/data/rules/os/os_esim_delete.yaml b/src/mscp/data/rules/os/os_esim_delete.yaml index af66c0a5..66629734 100644 --- a/src/mscp/data/rules/os/os_esim_delete.yaml +++ b/src/mscp/data/rules/os/os_esim_delete.yaml @@ -1,4 +1,3 @@ ---- id: os_esim_delete title: Ensure the eSIM Contents are Deleted When Device is Erased discussion: | diff --git a/src/mscp/data/rules/os/os_esim_transfers_disable.yaml b/src/mscp/data/rules/os/os_esim_transfers_disable.yaml index 8a3b0ab1..662dec4b 100644 --- a/src/mscp/data/rules/os/os_esim_transfers_disable.yaml +++ b/src/mscp/data/rules/os/os_esim_transfers_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_esim_transfers_disable title: Ensure the ability to transfer an eSIM is set to Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_SMIME_encryption_certificate_overwrite_disable.yaml b/src/mscp/data/rules/os/os_exchange_SMIME_encryption_certificate_overwrite_disable.yaml index 0c39c301..bcf91d6f 100644 --- a/src/mscp/data/rules/os/os_exchange_SMIME_encryption_certificate_overwrite_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_SMIME_encryption_certificate_overwrite_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_SMIME_encryption_certificate_overwrite_disable title: Disable changing the S/MIME encryption settings. discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_SMIME_encryption_default_certificate_overwrite_enable.yaml b/src/mscp/data/rules/os/os_exchange_SMIME_encryption_default_certificate_overwrite_enable.yaml index 48950609..06e86f92 100644 --- a/src/mscp/data/rules/os/os_exchange_SMIME_encryption_default_certificate_overwrite_enable.yaml +++ b/src/mscp/data/rules/os/os_exchange_SMIME_encryption_default_certificate_overwrite_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_SMIME_encryption_default_certificate_overwrite_enable title: Enable selecting the appropriate S/MIME encryption certificate. discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_SMIME_encryption_enforce.yaml b/src/mscp/data/rules/os/os_exchange_SMIME_encryption_enforce.yaml index 16f9e591..322985e9 100644 --- a/src/mscp/data/rules/os/os_exchange_SMIME_encryption_enforce.yaml +++ b/src/mscp/data/rules/os/os_exchange_SMIME_encryption_enforce.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_SMIME_encryption_enforce title: Setting S/MIME Encryption as Default discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_SMIME_encryption_per_message_disable.yaml b/src/mscp/data/rules/os/os_exchange_SMIME_encryption_per_message_disable.yaml index ecb2946c..b20c3ec1 100644 --- a/src/mscp/data/rules/os/os_exchange_SMIME_encryption_per_message_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_SMIME_encryption_per_message_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_SMIME_encryption_per_message_disable title: Disable Encryption Selection Option per Mail Message discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_SMIME_signing_certificate_overwrite_disable.yaml b/src/mscp/data/rules/os/os_exchange_SMIME_signing_certificate_overwrite_disable.yaml index 3e42b160..6eff0b0d 100644 --- a/src/mscp/data/rules/os/os_exchange_SMIME_signing_certificate_overwrite_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_SMIME_signing_certificate_overwrite_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_SMIME_signing_certificate_overwrite_disable title: Disable changing the S/MIME signing settings discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_SMIME_signing_enabled.yaml b/src/mscp/data/rules/os/os_exchange_SMIME_signing_enabled.yaml index c41fbeed..330e30e8 100644 --- a/src/mscp/data/rules/os/os_exchange_SMIME_signing_enabled.yaml +++ b/src/mscp/data/rules/os/os_exchange_SMIME_signing_enabled.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_SMIME_signing_enabled title: Enable S/MIME Signing discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_SMIME_signing_overwrite_disable.yaml b/src/mscp/data/rules/os/os_exchange_SMIME_signing_overwrite_disable.yaml index 7bb8df53..4e0e3fc9 100644 --- a/src/mscp/data/rules/os/os_exchange_SMIME_signing_overwrite_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_SMIME_signing_overwrite_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_SMIME_signing_overwrite_disable title: Disable Modifying the S/MIME Signing Settings discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_mail_recents_sync_disable.yaml b/src/mscp/data/rules/os/os_exchange_mail_recents_sync_disable.yaml index aa1bbc92..a3e28efc 100644 --- a/src/mscp/data/rules/os/os_exchange_mail_recents_sync_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_mail_recents_sync_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_mail_recents_sync_disable title: Prevent synching of recent recipients. discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_notes_disable.yaml b/src/mscp/data/rules/os/os_exchange_notes_disable.yaml index e83ca950..dc5ab0c1 100644 --- a/src/mscp/data/rules/os/os_exchange_notes_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_notes_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_notes_disable title: Ensure Notes service is disabled for Exchange ActiveSync discussion: 'Exchange ActiveSync Notes service can be disabled for an account. Note: The user can reenable the Notes service unless the setting EnableNotesUserOverridable is set to false.' diff --git a/src/mscp/data/rules/os/os_exchange_notes_user_override_disable.yaml b/src/mscp/data/rules/os/os_exchange_notes_user_override_disable.yaml index c6d5a2f9..7ee2783d 100644 --- a/src/mscp/data/rules/os/os_exchange_notes_user_override_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_notes_user_override_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_notes_user_override_disable title: Ensure Notes service override is disabled for Exchange ActiveSync discussion: Exchange ActiveSync Notes service can be disabled for a user. Setting EnableNotesUserOverridable to false prevents the user from altering the service status. diff --git a/src/mscp/data/rules/os/os_exchange_peraccountVPN.yaml b/src/mscp/data/rules/os/os_exchange_peraccountVPN.yaml index a8ca6594..78a150a1 100644 --- a/src/mscp/data/rules/os/os_exchange_peraccountVPN.yaml +++ b/src/mscp/data/rules/os/os_exchange_peraccountVPN.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_peraccountVPN title: Enforce per account VPN for managed Mail accounts. discussion: | diff --git a/src/mscp/data/rules/os/os_exchange_reminders_disable.yaml b/src/mscp/data/rules/os/os_exchange_reminders_disable.yaml index 3f8c566e..86fa37ba 100644 --- a/src/mscp/data/rules/os/os_exchange_reminders_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_reminders_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_reminders_disable title: Ensure Reminders service is disabled for Exchange ActiveSync discussion: 'Exchange ActiveSync system can disable the Reminders service for an account. Note: The user can reenable the Notes service unless the setting ''EnableRemindersUserOverridable'' is set to false.' diff --git a/src/mscp/data/rules/os/os_exchange_reminders_user_override_disable.yaml b/src/mscp/data/rules/os/os_exchange_reminders_user_override_disable.yaml index bda84180..701a349f 100644 --- a/src/mscp/data/rules/os/os_exchange_reminders_user_override_disable.yaml +++ b/src/mscp/data/rules/os/os_exchange_reminders_user_override_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_exchange_reminders_user_override_disable title: Ensure Reminders service override is disabled for Exchange ActiveSync discussion: Exchange ActiveSync system can disable the Reminders service for an account, but it can be reenabled by the user. The Reminders service is completely disabled when the 'EnableRemindersUserOverridable' setting is set to 'false'. diff --git a/src/mscp/data/rules/os/os_external_storage_access_defined.yaml b/src/mscp/data/rules/os/os_external_storage_access_defined.yaml index 96b68cd9..9e6c6182 100644 --- a/src/mscp/data/rules/os/os_external_storage_access_defined.yaml +++ b/src/mscp/data/rules/os/os_external_storage_access_defined.yaml @@ -1,4 +1,3 @@ ---- id: os_external_storage_access_defined title: Access to External Storage Must Be Defined discussion: |- diff --git a/src/mscp/data/rules/os/os_facetime_app_disable.yaml b/src/mscp/data/rules/os/os_facetime_app_disable.yaml index a9834b09..31cfaacb 100644 --- a/src/mscp/data/rules/os/os_facetime_app_disable.yaml +++ b/src/mscp/data/rules/os/os_facetime_app_disable.yaml @@ -1,8 +1,7 @@ ---- id: os_facetime_app_disable title: Disable FaceTime.app discussion: | - The macOS built-in FaceTime.app _MUST_ be disabled. + The macOS built-in FaceTime.app _MUST_ be disabled, unless FaceTime is an approved collaboration tool. The FaceTime.app establishes a connection to Apple's iCloud service, even when security controls have been put in place to disable iCloud access. @@ -10,6 +9,10 @@ discussion: | ==== Apple has deprecated the use of link:https://github.com/apple/device-management/blob/eb51fb0cb9626cac4717858556912c257a734ce0/mdm/profiles/com.apple.applicationaccess.new.yaml#L67-L70[application restriction controls], using these controls may not work as expected. Third party software may be required to fulfill the compliance requirements. ==== + + [IMPORTANT] + ==== + macOS 27 Golden Gate uses Declarative Device Management (DDM) to manage application restrictions. The DDM key for this control is `Allowed` with the value of `DeniedBinaries` containing the signing ID of the application to be disabled. The signing ID for FaceTime.app is `com.apple.FaceTime`. references: nist: cce: diff --git a/src/mscp/data/rules/os/os_facetime_disable.yaml b/src/mscp/data/rules/os/os_facetime_disable.yaml index 30bc4558..5144be7c 100644 --- a/src/mscp/data/rules/os/os_facetime_disable.yaml +++ b/src/mscp/data/rules/os/os_facetime_disable.yaml @@ -1,8 +1,9 @@ ---- id: os_facetime_disable title: Disable FaceTime App discussion: | - FaceTime _MUST_ be disabled. + The built-in FaceTime.app _MUST_ be disabled, unless FaceTime is an approved collaboration tool. + + The FaceTime.app establishes a connection to Apple's iCloud service, even when security controls have been put in place to disable iCloud access. references: nist: cce: diff --git a/src/mscp/data/rules/os/os_fail_secure_state.yaml b/src/mscp/data/rules/os/os_fail_secure_state.yaml index 2536c426..a040f4b1 100644 --- a/src/mscp/data/rules/os/os_fail_secure_state.yaml +++ b/src/mscp/data/rules/os/os_fail_secure_state.yaml @@ -1,4 +1,3 @@ ---- id: os_fail_secure_state title: Configure System to Fail to a Known Safe State if System Initialization, Shutdown, or Abort Fails discussion: |- diff --git a/src/mscp/data/rules/os/os_files_network_drive_access_disable.yaml b/src/mscp/data/rules/os/os_files_network_drive_access_disable.yaml index c25765d9..462a02e3 100644 --- a/src/mscp/data/rules/os/os_files_network_drive_access_disable.yaml +++ b/src/mscp/data/rules/os/os_files_network_drive_access_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_files_network_drive_access_disable title: Ensure Allow Network Drive Access in Files App is Set to Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_files_usb_drive_access_disable.yaml b/src/mscp/data/rules/os/os_files_usb_drive_access_disable.yaml index 30fbdada..d8933868 100644 --- a/src/mscp/data/rules/os/os_files_usb_drive_access_disable.yaml +++ b/src/mscp/data/rules/os/os_files_usb_drive_access_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_files_usb_drive_access_disable title: Ensure Allow USB Drive Access in Files App is Set to Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_filevault_authorized_users.yaml b/src/mscp/data/rules/os/os_filevault_authorized_users.yaml index 747a45ab..fddb72f9 100644 --- a/src/mscp/data/rules/os/os_filevault_authorized_users.yaml +++ b/src/mscp/data/rules/os/os_filevault_authorized_users.yaml @@ -1,4 +1,3 @@ ---- id: os_filevault_authorized_users title: FileVault Authorized Users discussion: | diff --git a/src/mscp/data/rules/os/os_filevault_autologin_disable.yaml b/src/mscp/data/rules/os/os_filevault_autologin_disable.yaml index 672d4500..b8674ade 100644 --- a/src/mscp/data/rules/os/os_filevault_autologin_disable.yaml +++ b/src/mscp/data/rules/os/os_filevault_autologin_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_filevault_autologin_disable title: Disable FileVault Automatic Login discussion: | diff --git a/src/mscp/data/rules/os/os_firewall_default_deny_require.yaml b/src/mscp/data/rules/os/os_firewall_default_deny_require.yaml index e302dd82..59e69f6d 100644 --- a/src/mscp/data/rules/os/os_firewall_default_deny_require.yaml +++ b/src/mscp/data/rules/os/os_firewall_default_deny_require.yaml @@ -1,4 +1,3 @@ ---- id: os_firewall_default_deny_require title: Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall Policy discussion: | diff --git a/src/mscp/data/rules/os/os_firewall_log_enable.yaml b/src/mscp/data/rules/os/os_firewall_log_enable.yaml index b7ac8abf..32c486fe 100644 --- a/src/mscp/data/rules/os/os_firewall_log_enable.yaml +++ b/src/mscp/data/rules/os/os_firewall_log_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_firewall_log_enable title: Enable Firewall Logging discussion: | diff --git a/src/mscp/data/rules/os/os_firmware_password_require.yaml b/src/mscp/data/rules/os/os_firmware_password_require.yaml index 81af761c..926958c8 100644 --- a/src/mscp/data/rules/os/os_firmware_password_require.yaml +++ b/src/mscp/data/rules/os/os_firmware_password_require.yaml @@ -1,4 +1,3 @@ ---- id: os_firmware_password_require title: Enable Firmware Password discussion: | @@ -9,10 +8,8 @@ discussion: | To set a firmware passcode use the following command: [source,bash] - ---- - /usr/sbin/firmwarepasswd -setpasswd - ---- - + - /usr/sbin/firmwarepasswd -setpasswd + - NOTE: If firmware password or passcode is forgotten, the only way to reset the forgotten password is through the use of a machine specific binary generated and provided by Apple. Schedule a support call, and provide proof of purchase before the firmware binary will be generated. NOTE: Firmware passwords are not supported on Apple Silicon devices. This rule is only applicable to Intel devices. diff --git a/src/mscp/data/rules/os/os_force_encrypted_backups_enable.yaml b/src/mscp/data/rules/os/os_force_encrypted_backups_enable.yaml index e2c05160..41c9576d 100644 --- a/src/mscp/data/rules/os/os_force_encrypted_backups_enable.yaml +++ b/src/mscp/data/rules/os/os_force_encrypted_backups_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_force_encrypted_backups_enable title: Ensure Force Encrypted Backups is Enabled discussion: | diff --git a/src/mscp/data/rules/os/os_gatekeeper_rearm.yaml b/src/mscp/data/rules/os/os_gatekeeper_rearm.yaml index 9ad51c54..c1119bb3 100644 --- a/src/mscp/data/rules/os/os_gatekeeper_rearm.yaml +++ b/src/mscp/data/rules/os/os_gatekeeper_rearm.yaml @@ -1,4 +1,3 @@ ---- id: os_gatekeeper_rearm title: Enforce Gatekeeper 30 Day Automatic Rearm discussion: | diff --git a/src/mscp/data/rules/os/os_genmoji_disable.yaml b/src/mscp/data/rules/os/os_genmoji_disable.yaml index 68c67475..d15f1133 100644 --- a/src/mscp/data/rules/os/os_genmoji_disable.yaml +++ b/src/mscp/data/rules/os/os_genmoji_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_genmoji_disable title: Disable Genmoji AI Creation discussion: | diff --git a/src/mscp/data/rules/os/os_grant_privs.yaml b/src/mscp/data/rules/os/os_grant_privs.yaml index 62479063..8f9cbe87 100644 --- a/src/mscp/data/rules/os/os_grant_privs.yaml +++ b/src/mscp/data/rules/os/os_grant_privs.yaml @@ -1,4 +1,3 @@ ---- id: os_grant_privs title: Allow Administrators to Promote Other Users to Administrator Status discussion: |- diff --git a/src/mscp/data/rules/os/os_guest_folder_removed.yaml b/src/mscp/data/rules/os/os_guest_folder_removed.yaml index fe7c1ba8..b389e00b 100644 --- a/src/mscp/data/rules/os/os_guest_folder_removed.yaml +++ b/src/mscp/data/rules/os/os_guest_folder_removed.yaml @@ -1,4 +1,3 @@ ---- id: os_guest_folder_removed title: Remove Guest Folder if Present discussion: | diff --git a/src/mscp/data/rules/os/os_handoff_disable.yaml b/src/mscp/data/rules/os/os_handoff_disable.yaml index 4fa641c9..4c1782a1 100644 --- a/src/mscp/data/rules/os/os_handoff_disable.yaml +++ b/src/mscp/data/rules/os/os_handoff_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_handoff_disable title: Disable Handoff discussion: | diff --git a/src/mscp/data/rules/os/os_hibernate_mode_destroyfvkeyonstandby_enable.yaml b/src/mscp/data/rules/os/os_hibernate_mode_destroyfvkeyonstandby_enable.yaml index b3f83980..0a293ac9 100644 --- a/src/mscp/data/rules/os/os_hibernate_mode_destroyfvkeyonstandby_enable.yaml +++ b/src/mscp/data/rules/os/os_hibernate_mode_destroyfvkeyonstandby_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_hibernate_mode_destroyfvkeyonstandby_enable title: Enable DestroyFVKeyOnStandby on Hibernate discussion: | diff --git a/src/mscp/data/rules/os/os_home_folders_default.yaml b/src/mscp/data/rules/os/os_home_folders_default.yaml index 3ac3bf0b..01bcfaf5 100644 --- a/src/mscp/data/rules/os/os_home_folders_default.yaml +++ b/src/mscp/data/rules/os/os_home_folders_default.yaml @@ -1,4 +1,3 @@ ---- id: os_home_folders_default title: Configure User's Home Folders to Apple's Default discussion: | diff --git a/src/mscp/data/rules/os/os_icloud_storage_prompt_disable.yaml b/src/mscp/data/rules/os/os_icloud_storage_prompt_disable.yaml index c4b0b38e..bb6018df 100644 --- a/src/mscp/data/rules/os/os_icloud_storage_prompt_disable.yaml +++ b/src/mscp/data/rules/os/os_icloud_storage_prompt_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_icloud_storage_prompt_disable title: Disable iCloud Storage Setup during Setup Assistant discussion: | diff --git a/src/mscp/data/rules/os/os_identify_non-org_users.yaml b/src/mscp/data/rules/os/os_identify_non-org_users.yaml index 9898ab42..7ac55022 100644 --- a/src/mscp/data/rules/os/os_identify_non-org_users.yaml +++ b/src/mscp/data/rules/os/os_identify_non-org_users.yaml @@ -1,4 +1,3 @@ ---- id: os_identify_non-org_users title: Configure the System to Uniquely Identify and Authenticate Non-Organizational Users discussion: |- diff --git a/src/mscp/data/rules/os/os_image_wand_disable.yaml b/src/mscp/data/rules/os/os_image_wand_disable.yaml index 393dadc1..d3c45cd2 100644 --- a/src/mscp/data/rules/os/os_image_wand_disable.yaml +++ b/src/mscp/data/rules/os/os_image_wand_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_image_wand_disable title: Disable Apple Intelligence ImageWand discussion: | diff --git a/src/mscp/data/rules/os/os_implement_cryptography.yaml b/src/mscp/data/rules/os/os_implement_cryptography.yaml index f3bca6f2..6e4605ee 100644 --- a/src/mscp/data/rules/os/os_implement_cryptography.yaml +++ b/src/mscp/data/rules/os/os_implement_cryptography.yaml @@ -1,4 +1,3 @@ ---- id: os_implement_cryptography title: Configure the System to Implement Approved Cryptography to Protect Information discussion: |- diff --git a/src/mscp/data/rules/os/os_implement_memory_protection.yaml b/src/mscp/data/rules/os/os_implement_memory_protection.yaml index f3c563c0..405f8429 100644 --- a/src/mscp/data/rules/os/os_implement_memory_protection.yaml +++ b/src/mscp/data/rules/os/os_implement_memory_protection.yaml @@ -1,4 +1,3 @@ ---- id: os_implement_memory_protection title: Configure the System to Protect Memory from Unauthorized Code Execution discussion: |- diff --git a/src/mscp/data/rules/os/os_information_validation.yaml b/src/mscp/data/rules/os/os_information_validation.yaml index 9d4d5fd9..ea564d49 100644 --- a/src/mscp/data/rules/os/os_information_validation.yaml +++ b/src/mscp/data/rules/os/os_information_validation.yaml @@ -1,4 +1,3 @@ ---- id: os_information_validation title: Information Input Validation discussion: |- diff --git a/src/mscp/data/rules/os/os_install_log_retention_configure.yaml b/src/mscp/data/rules/os/os_install_log_retention_configure.yaml index ffafe57f..deaf2e17 100644 --- a/src/mscp/data/rules/os/os_install_log_retention_configure.yaml +++ b/src/mscp/data/rules/os/os_install_log_retention_configure.yaml @@ -1,4 +1,3 @@ ---- id: os_install_log_retention_configure title: Configure Install.log Retention to $ODV discussion: | diff --git a/src/mscp/data/rules/os/os_install_vpn_configuration_disable.yaml b/src/mscp/data/rules/os/os_install_vpn_configuration_disable.yaml index 61df00f4..10849a3d 100644 --- a/src/mscp/data/rules/os/os_install_vpn_configuration_disable.yaml +++ b/src/mscp/data/rules/os/os_install_vpn_configuration_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_install_vpn_configuration_disable title: Ensure Allow Adding VPN Configurations is Set to Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_internal_apfs_volumes_encrypted.yaml b/src/mscp/data/rules/os/os_internal_apfs_volumes_encrypted.yaml index cc78c400..d0a311f8 100644 --- a/src/mscp/data/rules/os/os_internal_apfs_volumes_encrypted.yaml +++ b/src/mscp/data/rules/os/os_internal_apfs_volumes_encrypted.yaml @@ -1,4 +1,3 @@ ---- id: os_internal_apfs_volumes_encrypted title: Ensure All Internal User Storage APFS Volumes Are Encrypted discussion: | @@ -8,6 +7,8 @@ discussion: | references: nist: cce: + macos_27: + - CCE-XXXXX-X macos_26: - CCE-96725-7 cis: @@ -21,6 +22,7 @@ references: - 14.8 platforms: macOS: + '27.0': {} '26.0': benchmarks: - name: cis_lvl1 diff --git a/src/mscp/data/rules/os/os_iphone_mirroring_disable.yaml b/src/mscp/data/rules/os/os_iphone_mirroring_disable.yaml index 1cdfe234..0db01c56 100644 --- a/src/mscp/data/rules/os/os_iphone_mirroring_disable.yaml +++ b/src/mscp/data/rules/os/os_iphone_mirroring_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_iphone_mirroring_disable title: Disable iPhone Mirroring discussion: | diff --git a/src/mscp/data/rules/os/os_ir_support_disable.yaml b/src/mscp/data/rules/os/os_ir_support_disable.yaml index eedd5a3d..2860926a 100644 --- a/src/mscp/data/rules/os/os_ir_support_disable.yaml +++ b/src/mscp/data/rules/os/os_ir_support_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_ir_support_disable title: Disable Infrared (IR) support discussion: | diff --git a/src/mscp/data/rules/os/os_isolate_security_functions.yaml b/src/mscp/data/rules/os/os_isolate_security_functions.yaml index 800f4033..57b6a133 100644 --- a/src/mscp/data/rules/os/os_isolate_security_functions.yaml +++ b/src/mscp/data/rules/os/os_isolate_security_functions.yaml @@ -1,4 +1,3 @@ ---- id: os_isolate_security_functions title: Configure the System to Separate User and System Functionality discussion: |- diff --git a/src/mscp/data/rules/os/os_library_validation_enabled.yaml b/src/mscp/data/rules/os/os_library_validation_enabled.yaml index 61e4a9ac..99113573 100644 --- a/src/mscp/data/rules/os/os_library_validation_enabled.yaml +++ b/src/mscp/data/rules/os/os_library_validation_enabled.yaml @@ -1,4 +1,3 @@ ---- id: os_library_validation_enabled title: Enable Library Validation discussion: Library validation _MUST_ be enabled. diff --git a/src/mscp/data/rules/os/os_loginwindow_adminhostinfo_undefined.yaml b/src/mscp/data/rules/os/os_loginwindow_adminhostinfo_undefined.yaml index 83010945..7510c489 100644 --- a/src/mscp/data/rules/os/os_loginwindow_adminhostinfo_undefined.yaml +++ b/src/mscp/data/rules/os/os_loginwindow_adminhostinfo_undefined.yaml @@ -1,4 +1,3 @@ ---- id: os_loginwindow_adminhostinfo_undefined title: Prevent AdminHostInfo from Being Available at LoginWindow discussion: | diff --git a/src/mscp/data/rules/os/os_mail_app_disable.yaml b/src/mscp/data/rules/os/os_mail_app_disable.yaml index 65eaeeb9..7ae61ab1 100644 --- a/src/mscp/data/rules/os/os_mail_app_disable.yaml +++ b/src/mscp/data/rules/os/os_mail_app_disable.yaml @@ -1,9 +1,7 @@ id: os_mail_app_disable title: Disable Mail App discussion: | - The macOS built-in Mail.app _MUST_ be disabled. - - The Mail.app contains functionality that can establish connections to Apple's iCloud, even when security controls to disable iCloud access have been put in place. + The macOS built-in Mail.app _MUST_ be disabled, unless Mail is an approved emailtool. [IMPORTANT] ==== @@ -17,8 +15,6 @@ discussion: | references: nist: cce: - macos_27: - - CCE-XXXXX-X macos_26: - CCE-95221-8 macos_15: @@ -48,7 +44,6 @@ references: - 4.8 platforms: macOS: - '27.0': {} '26.0': {} '15.0': {} enforcement_info: @@ -81,8 +76,4 @@ mobileconfig_info: PayloadContent: - familyControlsEnabled: true - pathBlackList: - - /Applications/Mail.app -ddm_info: - declarationtype: com.apple.configuration.app.settings - ddm_key: Allowed - ddm_value: { 'DeniedBinaries': [ { "SigningID": "com.apple.Messages" } ] } \ No newline at end of file + - /Applications/Mail.app \ No newline at end of file diff --git a/src/mscp/data/rules/os/os_newsyslog_files_owner_group_configure.yaml b/src/mscp/data/rules/os/os_newsyslog_files_owner_group_configure.yaml index e5245ebe..234f21ab 100644 --- a/src/mscp/data/rules/os/os_newsyslog_files_owner_group_configure.yaml +++ b/src/mscp/data/rules/os/os_newsyslog_files_owner_group_configure.yaml @@ -1,4 +1,3 @@ ---- id: os_newsyslog_files_owner_group_configure title: Configure System Log Files Owned by Root and Group to Wheel discussion: | diff --git a/src/mscp/data/rules/os/os_newsyslog_files_permissions_configure.yaml b/src/mscp/data/rules/os/os_newsyslog_files_permissions_configure.yaml index 2a0aa8a4..0c5839b4 100644 --- a/src/mscp/data/rules/os/os_newsyslog_files_permissions_configure.yaml +++ b/src/mscp/data/rules/os/os_newsyslog_files_permissions_configure.yaml @@ -1,4 +1,3 @@ ---- id: os_newsyslog_files_permissions_configure title: Configure System Log Files to Mode 640 or Less Permissive discussion: | diff --git a/src/mscp/data/rules/os/os_notify_account_removal.yaml b/src/mscp/data/rules/os/os_notify_account_removal.yaml index 752ba93e..95cca9b9 100644 --- a/src/mscp/data/rules/os/os_notify_account_removal.yaml +++ b/src/mscp/data/rules/os/os_notify_account_removal.yaml @@ -1,4 +1,3 @@ ---- id: os_notify_account_removal title: Configure the System to Notify upon Account Removed Actions discussion: |- diff --git a/src/mscp/data/rules/os/os_notify_unauthorized_baseline_change.yaml b/src/mscp/data/rules/os/os_notify_unauthorized_baseline_change.yaml index 2da966cb..8165bd66 100644 --- a/src/mscp/data/rules/os/os_notify_unauthorized_baseline_change.yaml +++ b/src/mscp/data/rules/os/os_notify_unauthorized_baseline_change.yaml @@ -1,4 +1,3 @@ ---- id: os_notify_unauthorized_baseline_change title: Configure the System to Notify upon Baseline Configuration Changes discussion: |- diff --git a/src/mscp/data/rules/os/os_obscure_password.yaml b/src/mscp/data/rules/os/os_obscure_password.yaml index 551229d7..1fb5481f 100644 --- a/src/mscp/data/rules/os/os_obscure_password.yaml +++ b/src/mscp/data/rules/os/os_obscure_password.yaml @@ -1,4 +1,3 @@ ---- id: os_obscure_password title: Obscure Passwords discussion: |- diff --git a/src/mscp/data/rules/os/os_parental_controls_enable.yaml b/src/mscp/data/rules/os/os_parental_controls_enable.yaml index 6274de7a..2e40ab92 100644 --- a/src/mscp/data/rules/os/os_parental_controls_enable.yaml +++ b/src/mscp/data/rules/os/os_parental_controls_enable.yaml @@ -1,4 +1,3 @@ ---- id: os_parental_controls_enable title: Enable Parental Controls discussion: | diff --git a/src/mscp/data/rules/os/os_policy_banner_ssh_configure.yaml b/src/mscp/data/rules/os/os_policy_banner_ssh_configure.yaml index 96961edc..03b3a24f 100644 --- a/src/mscp/data/rules/os/os_policy_banner_ssh_configure.yaml +++ b/src/mscp/data/rules/os/os_policy_banner_ssh_configure.yaml @@ -1,4 +1,3 @@ ---- id: os_policy_banner_ssh_configure title: Display Policy Banner at Remote Login discussion: | diff --git a/src/mscp/data/rules/os/os_policy_banner_ssh_enforce.yaml b/src/mscp/data/rules/os/os_policy_banner_ssh_enforce.yaml index 5bec6122..e62bf0d4 100644 --- a/src/mscp/data/rules/os/os_policy_banner_ssh_enforce.yaml +++ b/src/mscp/data/rules/os/os_policy_banner_ssh_enforce.yaml @@ -1,4 +1,3 @@ ---- id: os_policy_banner_ssh_enforce title: Enforce SSH to Display Policy Banner discussion: | diff --git a/src/mscp/data/rules/os/os_prevent_priv_functions.yaml b/src/mscp/data/rules/os/os_prevent_priv_functions.yaml index 1488f273..8382c851 100644 --- a/src/mscp/data/rules/os/os_prevent_priv_functions.yaml +++ b/src/mscp/data/rules/os/os_prevent_priv_functions.yaml @@ -1,4 +1,3 @@ ---- id: os_prevent_priv_functions title: Configure the System to Block Non-Privileged Users from Executing Privileged Functions discussion: |- diff --git a/src/mscp/data/rules/os/os_removable_media_disable.yaml b/src/mscp/data/rules/os/os_removable_media_disable.yaml index 71a596bd..d0e90d0e 100644 --- a/src/mscp/data/rules/os/os_removable_media_disable.yaml +++ b/src/mscp/data/rules/os/os_removable_media_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_removable_media_disable title: Disable Removable Storage Devices discussion: | diff --git a/src/mscp/data/rules/os/os_remove_software_components_after_updates.yaml b/src/mscp/data/rules/os/os_remove_software_components_after_updates.yaml index 7ec8fd01..ead5561f 100644 --- a/src/mscp/data/rules/os/os_remove_software_components_after_updates.yaml +++ b/src/mscp/data/rules/os/os_remove_software_components_after_updates.yaml @@ -1,4 +1,3 @@ ---- id: os_remove_software_components_after_updates title: Must remove all software components after updated versions installed discussion: |- diff --git a/src/mscp/data/rules/os/os_require_managed_pasteboard_enforce.yaml b/src/mscp/data/rules/os/os_require_managed_pasteboard_enforce.yaml index d35db2df..395c46b5 100644 --- a/src/mscp/data/rules/os/os_require_managed_pasteboard_enforce.yaml +++ b/src/mscp/data/rules/os/os_require_managed_pasteboard_enforce.yaml @@ -1,4 +1,3 @@ ---- id: os_require_managed_pasteboard_enforce title: Ensure Copy/Paste of Data from Managed to Unmanaged Applications is Disabled discussion: | diff --git a/src/mscp/data/rules/os/os_required_crypto_module.yaml b/src/mscp/data/rules/os/os_required_crypto_module.yaml index 73d11fa2..24331466 100644 --- a/src/mscp/data/rules/os/os_required_crypto_module.yaml +++ b/src/mscp/data/rules/os/os_required_crypto_module.yaml @@ -1,4 +1,3 @@ ---- id: os_required_crypto_module title: Ensure all Federal Laws, Executive Orders, Directives, Policies, Regulations, Standards, and Guidance for Authentication to a Cryptographic Module are Met discussion: |- diff --git a/src/mscp/data/rules/os/os_safari_open_safe_downloads_disable.yaml b/src/mscp/data/rules/os/os_safari_open_safe_downloads_disable.yaml index 7b203d84..60667601 100644 --- a/src/mscp/data/rules/os/os_safari_open_safe_downloads_disable.yaml +++ b/src/mscp/data/rules/os/os_safari_open_safe_downloads_disable.yaml @@ -1,4 +1,3 @@ ---- id: os_safari_open_safe_downloads_disable title: Disable Automatic Opening of Safe Files in Safari discussion: | diff --git a/src/mscp/data/rules/os/os_screenshots_disable.yaml b/src/mscp/data/rules/os/os_screenshots_disable.yaml index 0472150c..ddef9942 100644 --- a/src/mscp/data/rules/os/os_screenshots_disable.yaml +++ b/src/mscp/data/rules/os/os_screenshots_disable.yaml @@ -107,6 +107,7 @@ tags: - cnssi-1253_moderate - cnssi-1253_low - cnssi-1253_high + - new mobileconfig_info: - PayloadType: com.apple.applicationaccess PayloadContent: diff --git a/src/mscp/data/rules/os/os_show_filename_extensions_enable.yaml b/src/mscp/data/rules/os/os_show_filename_extensions_enable.yaml index 9f9168da..361cb341 100644 --- a/src/mscp/data/rules/os/os_show_filename_extensions_enable.yaml +++ b/src/mscp/data/rules/os/os_show_filename_extensions_enable.yaml @@ -7,10 +7,8 @@ discussion: | ==== The check and fix are for the currently logged in user. To get the currently logged in user, run the following. [source,bash] - ---- - CURRENT_USER=$( /usr/bin/defaults read /Library/Preferences/com.apple.loginwindow lastUserName ) - ---- - ==== + - CURRENT_USER=$( /usr/bin/defaults read /Library/Preferences/com.apple.loginwindow lastUserName ) + - ==== references: nist: cce: diff --git a/src/mscp/data/rules/os/os_ssh_server_alive_interval_configure.yaml b/src/mscp/data/rules/os/os_ssh_server_alive_interval_configure.yaml index 39b3063b..7368b952 100644 --- a/src/mscp/data/rules/os/os_ssh_server_alive_interval_configure.yaml +++ b/src/mscp/data/rules/os/os_ssh_server_alive_interval_configure.yaml @@ -1,4 +1,3 @@ ---- id: os_ssh_server_alive_interval_configure title: Configure SSH ServerAliveInterval option set to $ODV discussion: | diff --git a/src/mscp/data/rules/os/os_visual_intelligence_summary.yaml b/src/mscp/data/rules/os/os_visual_intelligence_summary.yaml index 25c908ed..fdb91a1d 100644 --- a/src/mscp/data/rules/os/os_visual_intelligence_summary.yaml +++ b/src/mscp/data/rules/os/os_visual_intelligence_summary.yaml @@ -1,4 +1,3 @@ ---- id: os_visual_intelligence_summary title: Disable Apple Intelligence Visual Intelligence Summary discussion: | diff --git a/src/mscp/data/rules/os/os_voice_dialing_when_locked_disabled.yaml b/src/mscp/data/rules/os/os_voice_dialing_when_locked_disabled.yaml index 7b360043..b320460f 100644 --- a/src/mscp/data/rules/os/os_voice_dialing_when_locked_disabled.yaml +++ b/src/mscp/data/rules/os/os_voice_dialing_when_locked_disabled.yaml @@ -1,4 +1,3 @@ ---- id: os_voice_dialing_when_locked_disabled title: Ensure Allow Voice Dialing While Device is Locked is Set to Disabled discussion: | diff --git a/src/mscp/data/rules/pwpolicy/pwpolicy_account_inactivity_enforce.yaml b/src/mscp/data/rules/pwpolicy/pwpolicy_account_inactivity_enforce.yaml index 61cc4995..3763089a 100644 --- a/src/mscp/data/rules/pwpolicy/pwpolicy_account_inactivity_enforce.yaml +++ b/src/mscp/data/rules/pwpolicy/pwpolicy_account_inactivity_enforce.yaml @@ -62,8 +62,7 @@ platforms: To set local policy to disable an inactive user after $ODV days, edit the current password policy to contain the following within the "policyCategoryAuthentication": [source,xml] - ---- - + - policyContent policyAttributeLastAuthenticationTime > policyAttributeCurrentTime - (policyAttributeInactiveDays * 24 * 60 * 60) policyIdentifier @@ -74,14 +73,11 @@ platforms: $ODV - ---- - After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file". + - After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file". [source,bash] - ---- - /usr/bin/pwpolicy setaccountpolicies $pwpolicy_file - ---- - NOTE: See the password policy supplemental on more information on how to implement password policies on macOS. + - /usr/bin/pwpolicy setaccountpolicies $pwpolicy_file + - NOTE: See the password policy supplemental on more information on how to implement password policies on macOS. odv: hint: datatype: number diff --git a/src/mscp/data/rules/pwpolicy/pwpolicy_force_password_change.yaml b/src/mscp/data/rules/pwpolicy/pwpolicy_force_password_change.yaml index f9bb730b..257ac983 100644 --- a/src/mscp/data/rules/pwpolicy/pwpolicy_force_password_change.yaml +++ b/src/mscp/data/rules/pwpolicy/pwpolicy_force_password_change.yaml @@ -7,10 +7,8 @@ discussion: |- For a user to change their password at next logon, run the following command: [source,bash] - ---- - /usr/bin/pwpolicy -u [USER] -setpolicy "newPasswordRequired=1" - ---- - NOTE: Replace [USER] with the username that must change the password at next logon + - /usr/bin/pwpolicy -u [USER] -setpolicy "newPasswordRequired=1" + - NOTE: Replace [USER] with the username that must change the password at next logon NOTE: The technology supports this requirement and cannot be configured to be out of compliance. The technology inherently meets this requirement. references: diff --git a/src/mscp/data/rules/pwpolicy/pwpolicy_lower_case_character_enforce.yaml b/src/mscp/data/rules/pwpolicy/pwpolicy_lower_case_character_enforce.yaml index 2e75c681..afc0c56b 100644 --- a/src/mscp/data/rules/pwpolicy/pwpolicy_lower_case_character_enforce.yaml +++ b/src/mscp/data/rules/pwpolicy/pwpolicy_lower_case_character_enforce.yaml @@ -52,8 +52,7 @@ platforms: To set local policy to require at least $ODV lowercase letter, edit the current password policy to contain the following within the "policyCategoryPasswordContent": [source,xml] - ---- - + - policyContent policyAttributePassword matches '(.*[a-z].*){$ODV,}+' policyIdentifier @@ -64,14 +63,11 @@ platforms: $ODV - ---- - After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file". + - After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file". [source,bash] - ---- - /usr/bin/pwpolicy setaccountpolicies $pwpolicy_file - ---- - NOTE: See the password policy supplemental on more information on how to implement password policies on macOS. + - /usr/bin/pwpolicy setaccountpolicies $pwpolicy_file + - NOTE: See the password policy supplemental on more information on how to implement password policies on macOS. odv: hint: datatype: number diff --git a/src/mscp/data/rules/pwpolicy/pwpolicy_minimum_lifetime_enforce.yaml b/src/mscp/data/rules/pwpolicy/pwpolicy_minimum_lifetime_enforce.yaml index ac78c193..f80fb112 100644 --- a/src/mscp/data/rules/pwpolicy/pwpolicy_minimum_lifetime_enforce.yaml +++ b/src/mscp/data/rules/pwpolicy/pwpolicy_minimum_lifetime_enforce.yaml @@ -67,8 +67,7 @@ platforms: To set local policy to require a minimum password lifetime, edit the current password policy to contain the following within the "policyCategoryPasswordContent": [source,xml] - ---- - + - policyContent policyAttributeLastPasswordChangeTime < policyAttributeCurrentTime - (policyAttributeMinimumLifetimeHours * 60 * 60) policyIdentifier @@ -79,14 +78,11 @@ platforms: $ODV - ---- - After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file". + - After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file". [source,bash] - ---- - /usr/bin/pwpolicy setaccountpolicies $pwpolicy_file - ---- - NOTE: See the password policy supplemental on more information on how to implement password policies on macOS. + - /usr/bin/pwpolicy setaccountpolicies $pwpolicy_file + - NOTE: See the password policy supplemental on more information on how to implement password policies on macOS. odv: hint: datatype: number diff --git a/src/mscp/data/rules/pwpolicy/pwpolicy_upper_case_character_enforce.yaml b/src/mscp/data/rules/pwpolicy/pwpolicy_upper_case_character_enforce.yaml index 452a2b60..8f329864 100644 --- a/src/mscp/data/rules/pwpolicy/pwpolicy_upper_case_character_enforce.yaml +++ b/src/mscp/data/rules/pwpolicy/pwpolicy_upper_case_character_enforce.yaml @@ -52,8 +52,7 @@ platforms: To set local policy to require at least $ODV lowercase letter, edit the current password policy to contain the following within the "policyCategoryPasswordContent": [source,xml] - ---- - + - policyContent policyAttributePassword matches '(.*[A-Z].*){$ODV,}+' policyIdentifier @@ -64,14 +63,11 @@ platforms: $ODV - ---- - After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file". + - After saving the file and exiting to the command prompt, run the following command to load the new policy file, substituting the path to the file in place of "$pwpolicy_file". [source,bash] - ---- - /usr/bin/pwpolicy setaccountpolicies $pwpolicy_file - ---- - NOTE: See the password policy supplemental on more information on how to implement password policies on macOS. + - /usr/bin/pwpolicy setaccountpolicies $pwpolicy_file + - NOTE: See the password policy supplemental on more information on how to implement password policies on macOS. odv: hint: datatype: number diff --git a/src/mscp/data/rules/system_settings/system_settings_apple_watch_unlock_disable.yaml b/src/mscp/data/rules/system_settings/system_settings_apple_watch_unlock_disable.yaml index 8bbdf47c..ef09cb0f 100644 --- a/src/mscp/data/rules/system_settings/system_settings_apple_watch_unlock_disable.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_apple_watch_unlock_disable.yaml @@ -1,4 +1,3 @@ ---- id: system_settings_apple_watch_unlock_disable title: Prevent Apple Watch from Terminating a Session Lock discussion: | diff --git a/src/mscp/data/rules/system_settings/system_settings_bluetooth_sharing_disable.yaml b/src/mscp/data/rules/system_settings/system_settings_bluetooth_sharing_disable.yaml index 888e843d..f1132583 100644 --- a/src/mscp/data/rules/system_settings/system_settings_bluetooth_sharing_disable.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_bluetooth_sharing_disable.yaml @@ -9,10 +9,8 @@ discussion: | ==== The check and fix are for the last logged in user. To get the last logged in user, run the following. [source,bash] - ---- - CURRENT_USER=$( /usr/bin/defaults read /Library/Preferences/com.apple.loginwindow lastUserName ) - ---- - ==== + - CURRENT_USER=$( /usr/bin/defaults read /Library/Preferences/com.apple.loginwindow lastUserName ) + - ==== references: nist: cce: diff --git a/src/mscp/data/rules/system_settings/system_settings_hot_corners_secure.yaml b/src/mscp/data/rules/system_settings/system_settings_hot_corners_secure.yaml index 8b227add..342cc6a6 100644 --- a/src/mscp/data/rules/system_settings/system_settings_hot_corners_secure.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_hot_corners_secure.yaml @@ -9,10 +9,8 @@ discussion: | ==== The check and fix are for the last logged in user. To get the last logged in user, run the following. [source,bash] - ---- - CURRENT_USER=$( /usr/bin/defaults read /Library/Preferences/com.apple.loginwindow lastUserName ) - ---- - ==== + - CURRENT_USER=$( /usr/bin/defaults read /Library/Preferences/com.apple.loginwindow lastUserName ) + - ==== references: nist: cce: diff --git a/src/mscp/data/rules/system_settings/system_settings_printer_sharing_disable.yaml b/src/mscp/data/rules/system_settings/system_settings_printer_sharing_disable.yaml index 4fee34c0..706e7b2e 100644 --- a/src/mscp/data/rules/system_settings/system_settings_printer_sharing_disable.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_printer_sharing_disable.yaml @@ -1,4 +1,3 @@ ---- id: system_settings_printer_sharing_disable title: Disable Printer Sharing discussion: | diff --git a/src/mscp/data/rules/system_settings/system_settings_siri_AI_disable.yaml b/src/mscp/data/rules/system_settings/system_settings_siri_AI_disable.yaml index a21213fc..39b203f0 100644 --- a/src/mscp/data/rules/system_settings/system_settings_siri_AI_disable.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_siri_AI_disable.yaml @@ -40,6 +40,8 @@ references: hhs: hicp: - 2.L.A + - 4.L.A + - 4.L.B" cis: controls_v8: - 4.1 @@ -76,6 +78,7 @@ tags: - cmmc_lvl1 - cnssi-1253_moderate - hicp_lp + - new ddm_info: declarationtype: com.apple.configuration.siri.settings ddm_key: AllowSiriAI diff --git a/src/mscp/data/rules/system_settings/system_settings_siri_disable.yaml b/src/mscp/data/rules/system_settings/system_settings_siri_disable.yaml index 5b92f3d2..f43ef8d2 100644 --- a/src/mscp/data/rules/system_settings/system_settings_siri_disable.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_siri_disable.yaml @@ -94,19 +94,6 @@ platforms: - name: cis_lvl2 - name: disa_stig severity: medium - enforcement_info: - check: - shell: |- - /usr/bin/osascript -l JavaScript << EOS - $.NSUserDefaults.alloc.initWithSuiteName('com.apple.applicationaccess')\ - .objectForKey('allowAssistant').js - EOS - result: - string: 'false' - mobileconfig_info: - - PayloadType: com.apple.applicationaccess - PayloadContent: - - allowAssistant: false '15.0': benchmarks: - name: cis_lvl1 diff --git a/src/mscp/data/rules/system_settings/system_settings_siri_listen_disable.yaml b/src/mscp/data/rules/system_settings/system_settings_siri_listen_disable.yaml index 49811ac4..f73b7d1a 100644 --- a/src/mscp/data/rules/system_settings/system_settings_siri_listen_disable.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_siri_listen_disable.yaml @@ -1,4 +1,3 @@ ---- id: system_settings_siri_listen_disable title: Ensure Siri Listen For is Disabled discussion: | diff --git a/src/mscp/data/rules/system_settings/system_settings_time_machine_auto_backup_enable.yaml b/src/mscp/data/rules/system_settings/system_settings_time_machine_auto_backup_enable.yaml index 0239723d..42ce0dab 100644 --- a/src/mscp/data/rules/system_settings/system_settings_time_machine_auto_backup_enable.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_time_machine_auto_backup_enable.yaml @@ -47,4 +47,4 @@ tags: mobileconfig_info: - PayloadType: com.apple.TimeMachine PayloadContent: - - AutoBackup: true + - AutoBackup: true \ No newline at end of file diff --git a/src/mscp/data/rules/system_settings/system_settings_time_machine_encrypted_configure.yaml b/src/mscp/data/rules/system_settings/system_settings_time_machine_encrypted_configure.yaml index c6d0cb4f..3efe8ca7 100644 --- a/src/mscp/data/rules/system_settings/system_settings_time_machine_encrypted_configure.yaml +++ b/src/mscp/data/rules/system_settings/system_settings_time_machine_encrypted_configure.yaml @@ -44,7 +44,7 @@ platforms: - name: nlmapgov_plus enforcement_info: check: - shell: /usr/bin/sudo /usr/bin/defaults read /Library/Preferences/com.apple.TimeMachine.plist | grep -c NotEncrypted + shell: /usr/bin/defaults read /Library/Preferences/com.apple.TimeMachine.plist | /usr/bin/grep -c NotEncrypted result: integer: 0 fix: