Tony Young 0136fa8b3d fix(cis): correct manual supplementals for macOS 15 and 26
The per-version files were seeded from supplemental_cis_manual.yaml
before PR #781's corrections to it merged, so those corrections reached
supplemental_cis_manual_27 but not these two. Checked against Sequoia
v2.1.0 and Tahoe v1.1.0.

Both files:
- Remove 5.3.1 and 5.3.2. They are Automated, level 1, and implemented
  by os_internal_apfs_volumes_encrypted and os_external_apfs_hfs_
  volumes_encrypted on macOS 15, 26 and 27.
- Add 5.3.3 Audit Connected FAT32 and ExFAT Drives, which is Manual.
- Use the published titles for 2.1.1.1, 2.5.2.2 and 2.15.1.

macOS 15 only:
- Add 2.4.1 Audit Menu Bar and Control Center Icons, which is Manual.
- Use the published titles for 2.1.1.4 and 6.5.1, and list 6.5.1 under
  Applications as the macOS 26 and 27 files do.

macOS 26 only:
- Remove 1.7. Tahoe v1.1.0 ends at 1.6, and no MDM recommendation
  appears in the Sequoia, Tahoe or Golden Gate benchmarks.
2026-09-24 06:12:37 -04:00
2026-09-17 15:41:29 -04:00
2020-06-11 17:47:26 -04:00
2026-06-15 15:22:05 -04:00
2026-05-05 11:31:53 -04:00
2026-06-16 09:33:50 -04:00
2026-05-05 11:31:53 -04:00
2026-06-12 12:57:11 -04:00

macOS Security Compliance

Apple macOS 27.0 Website License Stars

Supported platforms: macOS, iOS/iPadOS, and visionOS.

The macOS Security Compliance Project (mSCP) is an open-source project that helps organizations secure their Apple devices. You choose the security rules to enforce, and mSCP generates everything you need:

  • Configuration profiles to apply the rules
  • Declarative Device Management (DDM) assets for device management solutions that support declarative delivery
  • Documentation to explain the setup
  • Compliance scripts to verify and enforce rules that profiles cannot

Beyond the built-in frameworks, organizations can build customized baselines to meet their specific cybersecurity needs. Vendors can also use mSCP as a source to build manifests, datapoints, and other compliance content for their products.

The security rules are derived from NIST Special Publication (SP) 800-53, Security and Privacy Controls for Information Systems and Organizations, Revision 5. mSCP is a joint project of federal IT security staff from the National Institute of Standards and Technology (NIST), the National Aeronautics and Space Administration (NASA), the Defense Information Systems Agency (DISA), and Los Alamos National Laboratory (LANL), along with a community of contributors who test the project and provide feedback to keep it on the cutting edge of Apple platform security.

mSCP is the technical implementation of NIST SP 800-219 (Rev. 2), Automated Secure Configuration Guidance from the macOS Security Compliance Project — the official NIST guidance for automated secure configuration of macOS. Apple also acknowledges the project on its Apple Platform Certifications for macOS & iOS/iPadOS pages.

To learn more, visit the project website. If you would like to contribute, see the contributor guidance.

Supported Frameworks

Country of Origin Framework Name OS Supported
NIST NIST SP 800-53 macOSiOS & iPadOSvisionOS
NIST NIST SP 800-171r3 macOSiOS & iPadOSvisionOS
NIST NIST SP 800-171r2 (CMMC) macOSiOS & iPadOSvisionOS
NIST CIS Benchmarks (Level 1 & 2) macOSiOS & iPadOS
NIST CIS Controls (v8) macOSiOS & iPadOSvisionOS
NIST CNSSI 1253 macOSiOS & iPadOSvisionOS
DISA DISA STIG macOSiOS & iPadOSvisionOS
BSI BSI Indigo iOS & iPadOS
BIO NLMAPGOV (Base and Plus) macOSiOS & iPadOS
HHS HICP — Health Industry Cybersecurity Practices (Large Organizations) macOS

Don't see your framework listed? Reach out through the contributor guidance or the project website to find out how we can get it included.

Usage

Civilian agencies are to use the National Checklist Program as required by NIST 800-70.

Note

Part 39 of the Federal Acquisition Regulations, section 39.101 paragraph (c) states, “In acquiring information technology, agencies shall include the appropriate information technology security policies and requirements, including use of common security configurations available from the National Institute of Standards and Technology’s website at https://checklists.nist.gov. Agency contracting officers should consult with the requiring official to ensure the appropriate standards are incorporated.”

Authors

Name Organization
Bob Gendler NIST
Allen Golbig Jamf
Dan Brodjieski NASA
John Mahlman IV Leidos
Aaron Kegerreis DISA
Cody Keats Coursera
Henry Stamerjohann Declarative IT GmbH
Marco A Piñeyro II State Department
Jason Blake NIST
Blair Heiserman NIST
Joshua Glemza NASA
Elyse Anderson NASA
Gary Gapinski NASA

Changelog

Refer to the CHANGELOG for a complete list of changes.

NIST Disclaimer

Any identification of commercial or open-source software in this document is done so purely in order to specify the methodology adequately. Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology, nor is it intended to imply that the software identified are necessarily the best available for the purpose.

Description
No description provided
Readme 46 MiB
Languages
YAML 57.8%
Python 28.8%
Jinja 5.7%
CSS 3.2%
JSON 1.9%
Other 2.5%