CIS Apple macOS 26 Tahoe Benchmark · Section 5

macOS Tahoe System Access: 22 Checks

Wartiva runs 22 checks for section 5, System Access, of the CIS Apple macOS 26 Tahoe Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →

All 22 checks on this page

Ensure a Login Window Banner Exists

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5

Finding: No login window policy banner exists.

Checks whether a login window policy banner file exists on the system.

This rule fails when loginWindowBannerExists is false.

Rationale: A policy banner provides legal notice of acceptable use at the login window.

Impact: A banner is displayed at the login window.

Remediation

From the command line:

/usr/bin/sudo /bin/mkdir -p /Library/Security/PolicyBanner.rtfd
Framework mappings
  • CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
  • NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
  • NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Unprotected Principal
MITRE ATT&CK tactic
Initial Access (TA0001)

Ensure a Separate Timestamp Is Enabled for Each User/tty Combo

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5

Finding: Sudo does not use a per-tty authentication timestamp.

Checks that sudo uses a per-tty authentication timestamp rather than a shared one.

This rule fails when timestampRecordType is not TTY.

Rationale: A per-tty timestamp prevents one terminal's sudo authentication from carrying to another.

Impact: Each terminal must authenticate to sudo independently.

Remediation

From the command line:

/bin/echo 'Defaults timestamp_type=tty' | /usr/bin/sudo /usr/sbin/visudo -f /etc/sudoers.d/timestamp_type
Framework mappings
  • CIS Controls v8: 4.3 Configure Automatic Session Locking on Enterprise Assets
  • NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
  • NIST SP 800-171 Rev. 2: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
  • CMMC 2.0 Level 2: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
  • PCI DSS v4.0.1: 8.2.8 Require re-authentication after 15 minutes of session inactivity
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure Logging Is Enabled for Sudo

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5

Finding: Sudo command logging is not enabled.

Checks whether sudo logs the commands it allows.

This rule fails when logCommandAllowed is not true.

Rationale: Logging sudo commands provides an audit trail of privileged actions.

Impact: Commands run via sudo are logged.

Remediation

From the command line:

/bin/echo 'Defaults log_allowed' | /usr/bin/sudo /usr/sbin/visudo -f /etc/sudoers.d/log_allowed
Framework mappings
  • CIS Controls v8: 4.3 Configure Automatic Session Locking on Enterprise Assets
  • NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
  • NIST SP 800-171 Rev. 2: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
  • CMMC 2.0 Level 2: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
  • PCI DSS v4.0.1: 8.2.8 Require re-authentication after 15 minutes of session inactivity
Risk
Unprotected Principal
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure the "root" Account Is Disabled

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5

Finding: The root account is enabled.

Checks whether the root account is disabled.

This rule fails when rootAccountDisabled is not true.

Rationale: An enabled root account is a high-value target and bypasses per-user accountability.

Impact: The root account cannot be used to log in directly.

Remediation

From the command line:

/usr/bin/sudo /usr/sbin/dsenableroot -d
Framework mappings
  • CIS Controls v8: 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-6 Least Privilege
  • NIST SP 800-171 Rev. 2: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
  • CMMC 2.0 Level 2: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure the Guest Home Folder Does Not Exist

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5

Finding: The guest home folder exists.

Checks whether the guest home folder (/Users/Guest) exists on the system.

This rule fails when guestHomeFolderExists is true.

Rationale: A leftover guest home folder can retain data and indicates guest access was used.

Impact: The guest home folder is removed.

Remediation

From the command line:

/usr/bin/sudo /bin/rm -rf '/Users/Guest'
Framework mappings
  • CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
  • NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
  • NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
  • PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
Risk
Unprotected Principal
MITRE ATT&CK tactic
Persistence (TA0003)

Ensure the Sudo Timeout Period Is Set to Zero

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5

Finding: The sudo timeout period is not zero.

Checks the sudo authentication timestamp timeout so that sudo re-prompts for a password every time.

This rule fails when authTimestampTimeout is not 0.

Rationale: A non-zero sudo timeout leaves a window in which sudo runs without re-authenticating.

Impact: sudo requires a password on every invocation.

authTimestampTimeout is a Duration (nanoseconds string); compared via to_number.

Remediation

From the command line:

/bin/echo 'Defaults timestamp_timeout=0' | /usr/bin/sudo /usr/sbin/visudo -f /etc/sudoers.d/timestamp_timeout
Framework mappings
  • CIS Controls v8: 4.3 Configure Automatic Session Locking on Enterprise Assets
  • NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
  • NIST SP 800-171 Rev. 2: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
  • CMMC 2.0 Level 2: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
  • PCI DSS v4.0.1: 8.2.8 Require re-authentication after 15 minutes of session inactivity
Risk
Unprotected Principal
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

Ensure XProtect Is Running

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5

Finding: XProtect scanning is not fully enabled.

Checks whether XProtect malware scanning is enabled for both application launch and background scans.

This rule fails when either xProtectLaunchScansEnabled or xProtectBackgroundScansEnabled is not true.

Rationale: XProtect provides Apple's built-in signature-based malware protection.

Impact: XProtect scans applications at launch and in the background.

'Updated' is not separately exposed; this rule verifies XProtect launch and background scanning are enabled.

Remediation

From the command line:

/usr/bin/sudo /bin/launchctl enable system/com.apple.XProtect
Framework mappings
  • CIS Controls v8: 10.1 Deploy and Maintain Anti-Malware Software; 10.2 Configure Automatic Anti-Malware Signature Updates; 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: MP-6 Media Sanitization; SI-3 Malicious Code Protection; SI-16 Memory Protection
  • NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems; 3.14.4 Update malicious code protection mechanisms when new releases are available
  • CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems; SI.L1-b.1.xiv Update malicious code protection mechanisms when new releases are available
  • CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems; SI.L2-3.14.4 Update malicious code protection mechanisms when new releases are available
  • PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.1 Keep anti-malware current through automatic updates; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
Risk
Insecure Application
MITRE ATT&CK tactic
Execution (TA0002)

5.1 File System Permissions and Access Controls

Ensure Apple Mobile File Integrity Is Enabled

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.1

Finding: Apple Mobile File Integrity is disabled.

Checks whether Apple Mobile File Integrity (AMFI) is enabled.

This rule fails when isAMFIEnabled is false.

Rationale: AMFI enforces code-signing and entitlement checks; disabling it allows unsigned code to run.

Impact: Code-signing and entitlement enforcement remain active.

AMFI is disabled via an amfi_get_out_of_my_way boot-arg; remediation clears offending boot-args (reboot required).

Remediation

From the command line:

/usr/bin/sudo /usr/sbin/nvram boot-args=""

Requires a restart to take effect.

Framework mappings
  • CIS Controls v8: 2.3 Address Unauthorized Software; 2.6 Allowlist Authorized Libraries
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-8 System Component Inventory; CM-10 Software Usage Restrictions; CM-11 User-installed Software
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 12.3.4 Annually assess whether hardware and software in use remain supported
Risk
Insecure Application
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure Home Folders Are Secure

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.1

Finding: A user home folder is accessible by other users.

Checks each user's home-folder permissions so that other users cannot read, write, or traverse them.

This rule fails when a /Users/<name> home folder's other-permission bits are not ---.

Rationale: World-accessible home folders expose personal and potentially sensitive user data to other accounts.

Impact: Other users lose read/write/execute access to each user's home folder.

Anchored on ENDPOINT_USER; flags user home folders under /Users whose other-permission bits are not '---'.

Remediation

From the command line:

/usr/bin/sudo /bin/chmod og-rwx /Users/<username>
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Unprotected Data
MITRE ATT&CK tactic
Discovery (TA0007)

Ensure Signed System Volume Is Enabled

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.1

Finding: Signed System Volume verification is disabled.

Checks that unauthenticated root is not permitted, indicating Signed System Volume verification is active.

This rule fails when csrFlags contains ALLOW_UNAUTHENTICATED_ROOT.

Rationale: SSV cryptographically verifies the system volume; disabling it allows tampering with system files.

Impact: The system volume must pass signature verification at boot.

SSV enforcement is inferred from the CSR flag set: ALLOW_UNAUTHENTICATED_ROOT disables signed-system-volume verification.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/csrutil authenticated-root enable

Requires a restart to take effect.

Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices; 3.11 Encrypt Sensitive Data at Rest
  • NIST SP 800-53 Rev. 5: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
  • PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
Insecure Application
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure System Integrity Protection Is Enabled

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.1

Finding: System Integrity Protection is disabled or weakened.

Checks the System Integrity Protection CSR flag set; any bypass flag indicates SIP is not fully enabled.

This rule fails when csrFlags contains any bypass flag.

Rationale: SIP protects system files and processes from modification even by root, blocking many rootkits.

Impact: Protected system locations and processes cannot be modified.

SIP is enabled when no CSR bypass flags are set; csrFlags lists any protections currently bypassed. Enabling SIP is performed from Recovery; the cli documents the intent.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/csrutil enable

Requires a restart to take effect.

Framework mappings
  • CIS Controls v8: 2.3 Address Unauthorized Software; 2.6 Allowlist Authorized Libraries; 10.5 Enable Anti-Exploitation Features
  • NIST SP 800-53 Rev. 5: CM-7 Least Functionality; CM-8 System Component Inventory; CM-10 Software Usage Restrictions; CM-11 User-installed Software; SI-16 Memory Protection
  • PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 12.3.4 Annually assess whether hardware and software in use remain supported
Risk
Insecure Application
MITRE ATT&CK tactic
Defense Evasion (TA0005)

Ensure System-Wide Applications Are Not World-Writable

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.1

Finding: A system-wide application is world-writable.

Checks each installed application under /Applications for world-writable permissions.

This rule fails when an install under /Applications has the other-write permission bit set.

Rationale: A world-writable application can be replaced or modified by any user, enabling code injection.

Impact: Non-privileged users can no longer modify system-wide applications.

Anchored on APPLICATION_INSTALL; flags installs under /Applications whose other-write permission bit is set.

Remediation

From the command line:

/usr/bin/sudo /bin/chmod -R o-w '<path>'
Framework mappings
  • CIS Controls v8: 3.3 Configure Data Access Control Lists
  • NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; MP-2 Media Access
  • NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.8.2 Limit access to CUI on system media to authorized users
  • CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
  • CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
  • PCI DSS v4.0.1: 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 7.1 Governance processes for need-to-know access restriction are established
Risk
Insecure Application
MITRE ATT&CK tactic
Privilege Escalation (TA0004)

5.2 Account and Password Policy Management

Ensure Password Account Lockout Threshold Is Configured

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.2

Finding: Account lockout threshold is not configured to 5 or fewer attempts.

Checks the maximum number of failed authentications allowed before an account is locked out.

This rule fails when maxFailedAuthentications is unset or greater than 5.

Rationale: A low lockout threshold slows password-guessing and brute-force attacks.

Impact: Accounts lock after five failed login attempts.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/pwpolicy -setglobalpolicy "maxFailedLoginAttempts=5"
Framework mappings
  • CIS Controls v8: 6.2 Establish an Access Revoking Process
  • NIST SP 800-53 Rev. 5: AC-1 Policy and Procedures; AC-2 Account Management; PS-4 Personnel Termination
  • PCI DSS v4.0.1: 8.2.4 Authorize and track additions, removals, and changes to user identities and credentials; 8.2.5 Remove access for departing users without delay
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Password Age Is Configured

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.2

Finding: A maximum password age is not configured.

Checks that account policy enforces a maximum password age of 365 days or less.

This rule fails when daysUntilExpiration is unset or greater than 365.

Rationale: Bounding password age limits the useful lifetime of a compromised credential.

Impact: Passwords must be changed within the configured interval.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/pwpolicy -setglobalpolicy "maxMinutesUntilChangePassword=525600"
Framework mappings
  • CIS Controls v8: 5.3 Disable Dormant Accounts
  • NIST SP 800-53 Rev. 5: AC-2 Account Management
  • PCI DSS v4.0.1: 8.3.7 Prevent users from reusing any of their four previous passwords
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Password History Is Configured

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.2

Finding: Password history is set to fewer than 24 passwords.

Checks that account policy remembers at least 24 previous passwords to prevent reuse.

This rule fails when passwordHistoryDepth is less than 24.

Rationale: A deep password history prevents users from cycling back to recently used passwords.

Impact: Users cannot reuse any of their last 24 passwords.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/pwpolicy -setglobalpolicy "usingHistory=24"
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Password Minimum Length Is Configured

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.2

Finding: Password minimum length is below 15 characters.

Checks the minimum password length enforced by account policy.

This rule fails when minPasswordLength is less than 15.

Rationale: Longer minimum lengths substantially increase resistance to brute-force attacks.

Impact: New passwords must be at least 15 characters.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/pwpolicy -setglobalpolicy "minChars=15"
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Passwords Must Contain a Numeric Character

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.2

Finding: Passwords are not required to contain a numeric character.

Checks that account policy requires at least one numeric character in passwords.

This rule fails when requiresNumeric is less than 1.

Rationale: Character-class requirements increase password complexity.

Impact: New passwords must include a numeric character.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/pwpolicy -setglobalpolicy "requiresNumeric=1"
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Passwords Must Contain a Special Character

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.2

Finding: Passwords are not required to contain a special character.

Checks that account policy requires at least one special character in passwords.

This rule fails when requiresSymbol is less than 1.

Rationale: Character-class requirements increase password complexity.

Impact: New passwords must include a special character.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/pwpolicy -setglobalpolicy "requiresSymbol=1"
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Passwords Must Contain an Alphabetic Character

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.2

Finding: Passwords are not required to contain an alphabetic character.

Checks that account policy requires at least one alphabetic character in passwords.

This rule fails when requiresAlpha is less than 1.

Rationale: Character-class requirements increase password complexity.

Impact: New passwords must include an alphabetic character.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/pwpolicy -setglobalpolicy "requiresAlpha=1"
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

Ensure Passwords Must Contain Uppercase and Lowercase Characters

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.2

Finding: Passwords are not required to contain mixed-case characters.

Checks that account policy requires both uppercase and lowercase characters in passwords.

This rule fails when requiresMixedCase is less than 1.

Rationale: Character-class requirements increase password complexity.

Impact: New passwords must include upper- and lowercase characters.

Remediation

From the command line:

/usr/bin/sudo /usr/bin/pwpolicy -setglobalpolicy "requiresMixedCase=1"
Framework mappings
  • CIS Controls v8: 5.2 Use Unique Passwords
  • NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
  • NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
  • PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
Risk
Unprotected Principal
MITRE ATT&CK tactic
Credential Access (TA0006)

5.3 Disk Encryption

Ensure External Storage Volumes Are Encrypted

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.3

Finding: An external storage volume is not encrypted.

Checks that every mounted non-system storage volume reports an encrypted state.

This rule fails when any non-system volume's encryptionState is not ON.

Rationale: Unencrypted external volumes expose data if the media is lost or stolen.

Impact: External storage volumes are encrypted at rest.

Approximates external/user volumes as disk-encryption entries whose mountPoints do not include '/'; passes when there are none or all are encrypted.

Remediation

In Finder, right-click the external volume and choose Encrypt, or enable encryption when formatting in Disk Utility.

Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices; 3.11 Encrypt Sensitive Data at Rest; 14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • NIST SP 800-53 Rev. 5: AT-2 Literacy Training and Awareness; AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
  • PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography; 12.6.3.2 Include appropriate end-user technology usage in awareness training
Risk
Unprotected Data
MITRE ATT&CK tactic
Impact (TA0040)

Ensure the Startup Volume Is Encrypted

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 5.3

Finding: The internal startup volume is not encrypted.

Checks the reported encryption state of the internal startup volume ('/').

This rule fails when the / mount's encryptionState is not ON.

Rationale: Encrypting internal storage protects data at rest against theft of the device or drive.

Impact: The internal startup volume is encrypted.

Distinct from the FileVault policy check (2.6.6): this verifies the actual reported encryption state of the startup volume via Security.diskEncryption.

Remediation

Open System Settings > Privacy & Security > FileVault and turn FileVault on.

From the command line:

/usr/bin/sudo /usr/bin/fdesetup enable
Framework mappings
  • CIS Controls v8: 3.6 Encrypt Data on End-User Devices; 3.11 Encrypt Sensitive Data at Rest
  • NIST SP 800-53 Rev. 5: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
  • NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
  • CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
  • PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
Risk
Unprotected Data
MITRE ATT&CK tactic
Impact (TA0040)