---
title: CIS macOS Tahoe Logging and Auditing: 4 Checks | Wartiva
description: Wartiva's 4 checks for section 3, Logging and Auditing, of the CIS Apple macOS 26 Tahoe Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/apple-macos-26-tahoe/logging-and-auditing.html
updated: 2026-10-07
---

CIS Apple macOS 26 Tahoe Benchmark · Section 3

# macOS Tahoe Logging and Auditing: 4 Checks

Wartiva runs 4 checks for section 3, Logging and Auditing, of the CIS Apple macOS 26 Tahoe Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## [Ensure Access to Audit Records Is Controlled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/logging-and-auditing.html#access-to-audit-records-is-controlled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 3

**Finding:** Audit records have permissive ownership or permissions.

Checks that audit trail files are owned by root and are not group- or world-writable (permission bits 0440).

This rule fails when any audit trail file is not owned by root (`uid` 0) or its permission bits are not `0440`.

**Rationale:** Audit records must be protected from unauthorized modification to remain trustworthy.

### Remediation

From the command line:

```sh
/usr/bin/sudo /usr/sbin/chown root:wheel /etc/security/audit_control /var/audit/*
/usr/bin/sudo /bin/chmod 440 /etc/security/audit_control /var/audit/*
```

Framework mappings

- **CIS Controls v8**: 3.3 Configure Data Access Control Lists
- **NIST SP 800-53 Rev. 5**: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
- **NIST SP 800-171 Rev. 2**: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
- **CMMC 2.0 Level 1**: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- **CMMC 2.0 Level 2**: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- **PCI DSS v4.0.1**: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established

Risk

Unprotected Data

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure install.log Is Retained for 365 Days or More](https://wartiva.com/policy-rules/apple-macos-26-tahoe/logging-and-auditing.html#install-log-is-retained-for-365-days-or-more)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 3

**Finding:** install.log is retained for fewer than 365 days.

Checks the retention period configured for /var/log/install.log.

This rule fails when `installLogRetention` is less than 365 days.

**Rationale:** A year of install history supports investigation of system changes during an incident.

**Impact:** Without sufficient log retention, forensics and maintenance cannot be performed properly.

### Remediation

From the command line:

```sh
/usr/bin/sudo /usr/bin/sed -i '' 's/all_max=[0-9]*[GMK]*//; s/ttl=[0-9]*/ttl=365/' /etc/asl/com.apple.install
```

Framework mappings

- **CIS Controls v8**: 8.1 Establish and Maintain an Audit Log Management Process; 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-1 Policy and Procedures; AU-2 Event Logging; AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
- **NIST SP 800-171 Rev. 2**: 3.3.1 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity
- **CMMC 2.0 Level 2**: AU.L2-3.3.1 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity
- **PCI DSS v4.0.1**: 10.1.1 Logging and monitoring policies and procedures kept documented, current, and applied

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure Security Auditing Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/logging-and-auditing.html#security-auditing-is-enabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 3

**Finding:** Security auditing is not enabled.

Checks whether the macOS audit facility (auditd) is enabled by verifying that audit flags are configured in the audit control policy.

This rule fails when no audit `flags` are configured.

**Rationale:** Audit logs are essential for investigating security incidents and attacker activity.

### Remediation

From the command line:

```sh
/usr/bin/sudo /bin/launchctl load -w /System/Library/LaunchDaemons/com.apple.auditd.plist
/usr/bin/sudo /bin/cp /etc/security/audit_control.example /etc/security/audit_control
```

Framework mappings

- **CIS Controls v8**: 8.2 Collect Audit Logs; 8.5 Collect Detailed Audit Logs
- **NIST SP 800-53 Rev. 5**: AU-2 Event Logging; AU-3 Content of Audit Records; AU-7 Audit Record Reduction and Report Generation; AU-12 Audit Record Generation; SI-4 System Monitoring
- **PCI DSS v4.0.1**: 5.3.4 Enable and retain anti-malware audit logs; 6.4.1 Assess or shield public-facing web applications against known attacks; 6.4.2 Deploy an automated solution that blocks attacks on public web apps; 9.4.5 Keep a log-based inventory of electronic media holding cardholder data; 10.2.1.1 Record every individual user's cardholder data access; 10.2.1.2 Log all actions by administrators, including interactive account use; 10.2.1.3 Record any access made to audit records themselves; 10.2.1.4 Record failed logical access attempts; 10.2.1.5 Record account creation, privilege elevation, and other credential changes; 10.2.1.6 Record when audit logging is initialized, started, stopped, or paused; 10.2.1.7 Record the creation or removal of system-level objects; 10.2.2 Include user, event type, date, and time in each log entry

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

## [Ensure Security Auditing Logs Are Retained for 30 Days or More](https://wartiva.com/policy-rules/apple-macos-26-tahoe/logging-and-auditing.html#security-auditing-logs-are-retained-for-30-days-or-more)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 3

**Finding:** Security audit logs are retained for fewer than 30 days.

Checks the audit log expire-after retention age.

This rule fails when the audit `expireAfter.age` is less than 30 days.

**Rationale:** Audit records must be retained long enough to be reviewed during an investigation.

### Remediation

From the command line:

```sh
/usr/bin/sudo /usr/bin/sed -i '' 's/^expire-after:.*/expire-after:30d/' /etc/security/audit_control
```

Framework mappings

- **CIS Controls v8**: 8.1 Establish and Maintain an Audit Log Management Process; 8.3 Ensure Adequate Audit Log Storage
- **NIST SP 800-53 Rev. 5**: AU-1 Policy and Procedures; AU-2 Event Logging; AU-4 Audit Log Storage Capacity; AU-5 Response to Audit Logging Process Failures
- **NIST SP 800-171 Rev. 2**: 3.3.1 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity
- **CMMC 2.0 Level 2**: AU.L2-3.3.1 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity
- **PCI DSS v4.0.1**: 10.1.1 Logging and monitoring policies and procedures kept documented, current, and applied

Risk

High Profile Threat

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
