rules listed in the wrong section in baselines #321

Closed
opened 2026-01-19 18:30:03 +00:00 by michael · 1 comment
Owner

Originally created by @robertgendler on GitHub.

Summary

These rules are listed in the wrong sections in the following baselines.
sysprefs_wifi_disable - 800-53_high, 800-53_moderate, cnssi-1253, all_rules - should be inherent, not system preferences

os_peripherals_identify - 800-53_high, 800-53_moderate, cnssi-1253, all_rules - should be inherent, no OS

pwpolicy_emergency_accounts_disable - 800-53_high, 800-53_moderate, cnssi-1253, all_rules - should be inherent, not password policy

pwpolicy_temporary_accounts_disable - 800-53_high, 800-53_moderate, cnssi-1253, all_rules - should be inherent, not password policy

audit_auditd_enabled - 800-53_high, 800-53_moderate, 800-53_low, cnssi-1253, all_rules - should be audit, not inherent

pwpolicy_force_password_change - 800-53_high, 800-53_moderate, 800-53_low, cnssi-1253, all_rules - should be inherent, not permanent

Originally created by @robertgendler on GitHub. <!--- Please read this! Before opening a new issue, make sure to search for keywords in the issues filtered by the "regression" or "bug" label and verify the issue you're about to submit isn't a duplicate. ---> ### Summary These rules are listed in the wrong sections in the following baselines. sysprefs_wifi_disable - 800-53_high, 800-53_moderate, cnssi-1253, all_rules - should be inherent, not system preferences os_peripherals_identify - 800-53_high, 800-53_moderate, cnssi-1253, all_rules - should be inherent, no OS pwpolicy_emergency_accounts_disable - 800-53_high, 800-53_moderate, cnssi-1253, all_rules - should be inherent, not password policy pwpolicy_temporary_accounts_disable - 800-53_high, 800-53_moderate, cnssi-1253, all_rules - should be inherent, not password policy audit_auditd_enabled - 800-53_high, 800-53_moderate, 800-53_low, cnssi-1253, all_rules - should be audit, not inherent pwpolicy_force_password_change - 800-53_high, 800-53_moderate, 800-53_low, cnssi-1253, all_rules - should be inherent, not permanent
Author
Owner

@robertgendler commented on GitHub:

Rules moved

@robertgendler commented on GitHub: Rules moved
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: usnistgov/macos_security#321