macOS 27 had no CIS coverage. Adds Level 1 and Level 2 mappings for CIS
Apple macOS 27 Golden Gate v1.0.0, and maps the one recommendation new to
CIS Apple macOS Tahoe 26 v2.0.0.
cis_lvl1_macos_27.0 0 -> 96
cis_lvl2_macos_27.0 0 -> 117
cis_lvl1_macos_26.0 97 -> 97
cis_lvl2_macos_26.0 116 -> 118
116 rules receive references.cis.benchmark.macos_27 (118 references across
95 distinct recommendations). Applied via `./mscp.py admin import`.
Golden Gate carries 121 of the 125 published Tahoe v1.1.0 recommendations
unchanged, renumbers one, drops three, and adds none. Every change sits in
2.10 Battery and follows from macOS 27 dropping Intel support:
2.10.1.1 OS Not Active When Resuming from Standby (Intel) dropped
2.10.1.2 Sleep and Display Sleep on Apple Silicon -> 2.10.1
2.10.2 Power Nap Disabled for Intel Macs dropped
2.10.3 Wake for Network Access Is Disabled -> 2.10.2
Version differences use the existing per-OS reference structure; no rule
modelling changed. Levels follow the established convention - level 1 tags
cis_lvl1 and cis_lvl2, level 2 tags cis_lvl2 alone - and all 95 mapped
recommendations were confirmed against their CIS Workbench pages.
2.3.5.1 (allowUIConfigurationProfileInstallation, Manual, Level 2) is new
in both benchmarks and maps to the existing
os_install_configuration_profile_disable, which already enforced that key
and additionally asserts objectIsForcedForKey.
supplemental_cis_manual was two revisions out of date. Drops 1.7 (in
neither benchmark) and 5.3.1/5.3.2 (Automated, with dedicated rules), adds
5.3.3 and 2.3.5.1, and corrects five titles.
Also corrects pre-existing defects surfaced by the mapping, in files the
mapping already touches:
- system_settings_software_update_app_update_enforce and
os_software_update_deferral had CIS references but no 26.0/27.0
platform blocks, so CIS 1.4 and 1.6 could not enter the baselines
- system_settings_improve_search_disable was missing "(level 1)"
- system_settings_location_services_menu_enforce tagged a Level 2
recommendation into cis_lvl1
- os_internal_apfs_volumes_encrypted and
os_external_apfs_hfs_volumes_encrypted listed CIS Controls v7 entries
in controls_v8
Supported platforms: macOS, iOS/iPadOS, and visionOS.
The macOS Security Compliance Project (mSCP) is an open-source project that helps organizations secure their Apple devices. You choose the security rules to enforce, and mSCP generates everything you need:
- Configuration profiles to apply the rules
- Declarative Device Management (DDM) assets for device management solutions that support declarative delivery
- Documentation to explain the setup
- Compliance scripts to verify and enforce rules that profiles cannot
Beyond the built-in frameworks, organizations can build customized baselines to meet their specific cybersecurity needs. Vendors can also use mSCP as a source to build manifests, datapoints, and other compliance content for their products.
The security rules are derived from NIST Special Publication (SP) 800-53, Security and Privacy Controls for Information Systems and Organizations, Revision 5. mSCP is a joint project of federal IT security staff from the National Institute of Standards and Technology (NIST), the National Aeronautics and Space Administration (NASA), the Defense Information Systems Agency (DISA), and Los Alamos National Laboratory (LANL), along with a community of contributors who test the project and provide feedback to keep it on the cutting edge of Apple platform security.
mSCP is the technical implementation of NIST SP 800-219 (Rev. 2), Automated Secure Configuration Guidance from the macOS Security Compliance Project — the official NIST guidance for automated secure configuration of macOS. Apple also acknowledges the project on its Apple Platform Certifications for macOS & iOS/iPadOS pages.
To learn more, visit the project website. If you would like to contribute, see the contributor guidance.
Supported Frameworks
Don't see your framework listed? Reach out through the contributor guidance or the project website to find out how we can get it included.
Usage
Civilian agencies are to use the National Checklist Program as required by NIST 800-70.
Note
Part 39 of the Federal Acquisition Regulations, section 39.101 paragraph (c) states, “In acquiring information technology, agencies shall include the appropriate information technology security policies and requirements, including use of common security configurations available from the National Institute of Standards and Technology’s website at https://checklists.nist.gov. Agency contracting officers should consult with the requiring official to ensure the appropriate standards are incorporated.”
Authors
| Name | Organization |
|---|---|
| Bob Gendler | NIST |
| Allen Golbig | Jamf |
| Dan Brodjieski | NASA |
| John Mahlman IV | Leidos |
| Aaron Kegerreis | DISA |
| Cody Keats | Coursera |
| Henry Stamerjohann | Declarative IT GmbH |
| Marco A Piñeyro II | State Department |
| Jason Blake | NIST |
| Blair Heiserman | NIST |
| Joshua Glemza | NASA |
| Elyse Anderson | NASA |
| Gary Gapinski | NASA |
Changelog
Refer to the CHANGELOG for a complete list of changes.
NIST Disclaimer
Any identification of commercial or open-source software in this document is done so purely in order to specify the methodology adequately. Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology, nor is it intended to imply that the software identified are necessarily the best available for the purpose.
