918 Commits

Author SHA1 Message Date
Allen Golbig
be5491f565 sync check/fix from tahoe
Some checks failed
Spell Check / spellcheck (push) Has been cancelled
2026-01-29 11:52:11 -05:00
Bob Gendler
fe09001686 updates for DISA STIG
Signed-off-by: Bob Gendler <robert.gendler@nist.gov>
2025-12-17 15:36:35 -05:00
Dan Brodjieski
6d9731b6e5 fix[rule]: align check with CIS methodology
update the check to better detect hardware for applicability
2025-12-17 11:21:53 -05:00
Dan Brodjieski
e5876d5cbe Merge branch 'sequoia' into dev_sequoia_bio 2025-11-21 16:30:10 -05:00
Allen Golbig
5c8ca93754 fixed path 2025-11-07 08:09:42 -05:00
Allen Golbig
aaf2097869 add note 2025-11-06 12:05:08 -05:00
Dan Brodjieski
59e627543a fix: adjusted specific OS references 2025-09-15 11:04:49 -04:00
Dan Brodjieski
647f8b83ec refactor: fix typos and spelling 2025-09-15 10:55:09 -04:00
Dan Brodjieski
306655ff44 fix[rule]: correct typo in fix text 2025-09-12 10:43:44 -04:00
Jordy Witteman
1cf55be5d0 Update system_settings_time_server_configure.yaml 2025-09-09 21:43:22 +02:00
Dan Brodjieski
a12e6a7eba fix: adjust logic in pwpolicy rules
checks allow for settings that fall within the limits of the rule instead of having to be exact

standardized result strings

issue #541
2025-09-09 10:56:52 -04:00
Dan Brodjieski
5b527bcc8a fix{rule]: add note about FileVault implementation
Issue #540
2025-09-08 12:13:35 -04:00
Dan Brodjieski
43de18fd8a docs: add warning about allowPasscodeModification
password policy supplemental updated with warning for restriction on passcode modification

issue #539
2025-09-08 12:09:39 -04:00
Dan Brodjieski
4e9c3613ac fix[rule]: update check for time machine encryption
Verified
1a6a8df
changing to CIS method

Issue #538
2025-09-08 12:03:19 -04:00
Jordy Witteman
64dba1e8d4 Merge branch 'dev_sequoia_nlmapgov' into sequoia 2025-09-05 20:39:45 +02:00
mahlmanj
2df2d68ea1 Merge branch 'sequoia' into dev_sequoia_cmmc 2025-09-03 10:17:43 -04:00
mahlmanj
f459b693be Remove cmmc references from os_anti_virus_installed 2025-09-03 10:11:43 -04:00
Bob Gendler
e435364874 refactor[rules] Added stderr redirect
Issue #522
Added stderr redirect for mdmclient for
- os_authenticated_root_enable
- os_recovery_lock_enable
- os_secure_boot_verify
- system_settings_remote_management_disable
2025-08-26 15:04:57 -04:00
Bob Gendler
450d0e351d refactor[rules] updated check
Updated check for os_network_storage_restriction

Issue #529
2025-08-26 15:00:57 -04:00
Bob Gendler
843a5c9f49 refactor[rules] updated script and fix text
Issue #529

Fixed script check for os_external_storage_access_defined
Updated fix text for os_external_storage_access_defined and os_network_storage_restriction
2025-08-26 14:50:03 -04:00
Bob Gendler
9564143a5d Pr #530 2025-08-26 14:44:52 -04:00
Bob Gendler
79adf45029 Merge pull request #506 from usnistgov/dev_sequoia_issue364
Dev sequoia issue364
2025-08-26 13:10:28 -04:00
Bob Gendler
795cf9f7d5 Issue #531 - fixed uppercase result string 2025-08-25 12:40:35 -04:00
Allen Golbig
e614f4ccb4 update rule to support psso 2025-08-20 11:17:47 -04:00
Bob Gendler
740c35b2c8 removed unncessary STIG tag 2025-08-19 14:04:20 -04:00
mahlmanj
1460f2082f Updating rules to add CMMC tags and removing tags from one. Update baselines. 2025-08-18 14:55:41 -04:00
Bob Gendler
0f2d750451 removed unncessary stig tag 2025-08-18 13:46:29 -04:00
Allen Golbig
15a6501477 Merge pull request #523 from root3nl/nlmapgov
Initial development version of NLMAPGOV
2025-08-14 09:12:56 -04:00
Jordy Witteman
4647021a12 Update os_safari_open_safe_downloads_disable.yaml 2025-08-07 17:29:29 +02:00
Jordy Witteman
0e85b93535 Updates and mapping
- Updates to some rules
- Mapping added for `nlmapgov_plus` to the BIO rules
2025-08-07 17:22:41 +02:00
Allen Golbig
798d95ed62 adding profile to rule to fix user experience 2025-07-30 18:05:50 -04:00
Jordy Witteman
d7be09a4de NLMAPGOV updates
- Added additional audit rules to `nlmapgov_base`
- Added first draft of `nlmapgov_plus`, designed as a complete package with rules from best practices from the field and other baselines. Still requires evaluation and altering by organizations.
2025-07-24 17:12:32 +02:00
Allen Golbig
121dc6e44f updated rule to match CIS 2025-07-15 15:02:39 -04:00
Jordy Witteman
e569753014 Merge branch 'usnistgov:main' into nlmapgov 2025-07-10 17:02:03 +02:00
Bob Gendler
30193a9ccf Added missing cis_lvl1 2025-07-02 09:45:31 -04:00
akegerreis
eab528ae5e Update os_iphone_mirroring_disable.yaml (#504)
added stig tag
2025-07-02 09:10:29 -04:00
Bob Gendler
252852d3d2 Release 2025-07-01 14:43:21 -04:00
Bob Gendler
0e49fac1ff Added missing CCE 2025-06-30 11:11:59 -04:00
Bob Gendler
8a6f58844d refactor[rule] Added warning
Added warning about using os_unlock_active_user_session_disable with platformSSO.
2025-06-26 11:42:03 -04:00
Bob Gendler
dbb7f7f38d refactor[rules/baseline]
Added missing baseline tags to system_settings_ssh_disable
Added rule to baseline files
2025-06-26 11:32:09 -04:00
Bob Gendler
892e06ad18 refactor[rules] Modified CIS information
Moved CIS benchmark numbers
2025-06-18 09:48:22 -04:00
Jordy Witteman
d11a2bbcff Added BIO guidance mapping
Added BIO guidance mapping
2025-06-05 14:48:15 +02:00
Jordy Witteman
f702efa237 Merge branch 'sequoia' of https://github.com/usnistgov/macos_security into usnistgov-sequoia 2025-05-26 15:49:41 +02:00
Bob Gendler
9fa05af111 refactor[rules] CIS updates
Updates to CIS rule IDs
2025-05-21 10:23:04 -04:00
Jordy Witteman
8f8ddc1a68 Update audit_retention_configure.yaml 2025-05-15 16:50:06 +02:00
Bob Gendler
3ef330effb refactor[rules] Changed CISv8 from [] to "N/A" 2025-05-13 11:01:17 -04:00
Bob Gendler
368510e41c rules[refactor] Updated check/fix for nfsd 2025-05-07 13:49:04 -04:00
Dan Brodjieski
16d0501b28 update[cis]: additional controls for v1.1.0 2025-05-07 10:30:12 -04:00
Bob Gendler
0b4d809ae0 Fixed r5 to 800-53r5 in references 2025-04-16 09:48:41 -04:00
Bob Gendler
448a11248d Merge branch 'dev_sequoia_issue469' into sequoia 2025-04-14 11:50:38 -04:00