Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 47 checks on this page
- 2.1 Apple Account
- Ensure iCloud Drive Document and Desktop Sync Is Disabled
- 2.2 Network
- Ensure Firewall Stealth Mode Is Enabled
- Ensure the Application Firewall Is Enabled
- 2.3 General
- Ensure AirDrop Is Disabled
- Ensure AirPlay Receiver Is Disabled
- Ensure Set Time and Date Automatically Is Enabled
- Ensure Bluetooth Sharing Is Disabled
- Ensure Content Caching Is Disabled
- Ensure File Sharing Is Disabled
- Ensure Internet Sharing Is Disabled
- Ensure Media Sharing Is Disabled
- Ensure Printer Sharing Is Disabled
- Ensure Remote Apple Events Is Disabled
- Ensure Remote Login Is Disabled
- Ensure Remote Management Is Disabled
- Ensure Screen Sharing Is Disabled
- Ensure Time Machine Automatic Backup Is Enabled
- Ensure Time Machine Volumes Are Encrypted
- 2.5 Apple Intelligence & Siri
- Ensure Apple Intelligence Writing Tools Are Disabled
- Ensure External Intelligence Extensions Are Disabled
- Ensure Mail Summarization Is Disabled
- Ensure Notes Summarization Is Disabled
- Ensure Listen For Siri Is Disabled
- Ensure Siri Is Disabled
- 2.6 Privacy & Security
- Ensure An Administrator Password Is Required To Access System-Wide Preferences
- Ensure FileVault Is Enabled
- Ensure Gatekeeper Is Enabled
- Ensure Limit Ad Tracking Is Enabled
- Ensure Location Icon Is Shown When System Services Request Location
- Ensure Location Services Is Enabled
- Ensure Improve Siri And Dictation Is Disabled
- Ensure Share Mac Analytics Is Disabled
- Ensure Share With App Developers Is Disabled
- 2.7 Desktop & Dock
- Ensure Screen Saver Hot Corners Do Not Disable The Screen Saver
- 2.9 Spotlight
- Ensure Help Apple Improve Search Is Disabled
- 2.10 Battery (Energy Saver)
- Ensure Power Nap Is Disabled
- Ensure Wake for Network Access Is Disabled
- Ensure Sleep and Display Sleep Are Enabled
- 2.11 Lock Screen
- Ensure a Custom Login Screen Message Is Configured
- Ensure a Password Is Required After Screen Saver or Display Sleep
- Ensure Password Hints Are Not Shown at the Login Window
- Ensure Screen Saver Inactivity Interval Is 15 Minutes or Less
- Ensure the Login Window Displays Name and Password
- 2.12 Touch ID & Password (Login Password)
- Ensure User Accounts Do Not Have a Password Hint
- 2.13 Users & Groups
- Ensure Automatic Login Is Disabled
- Ensure the Guest Account Is Disabled
- 2.18 Keyboard
- Ensure On-Device Dictation Is Enabled
2.1 Apple Account
Ensure iCloud Drive Document and Desktop Sync Is Disabled
Finding: iCloud Desktop and Documents sync is enabled.
Checks the MDM device-restriction controlling iCloud Drive Desktop & Documents folder syncing.
This rule fails when allowCloudDesktopAndDocuments is not false.
Rationale: Syncing Desktop and Documents to iCloud can move organizational data outside managed storage.
Impact: Desktop and Documents folders no longer sync to iCloud Drive.
Remediation
Deploy a configuration profile that sets allowCloudDesktopAndDocuments to false (Restrictions payload), or in System Settings > [Apple Account] > iCloud > Drive turn off Desktop & Documents Folders.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- NIST SP 800-53 Rev. 5: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
2.2 Network
Ensure Firewall Stealth Mode Is Enabled
Finding: Firewall stealth mode is disabled.
Checks whether the macOS application firewall is running with stealth mode active.
This rule fails when no firewall product reports productState of ON_WITH_STEALTH_MODE.
Rationale: Stealth mode drops probes (e.g. ICMP, port scans), making the host harder to discover.
Impact: The host stops responding to unsolicited network probes.
Remediation
Open System Settings > Network > Firewall > Options and enable Stealth Mode.
From the command line:
/usr/bin/sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setstealthmode on
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.5 Implement and Manage a Firewall on End-User Devices; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SC-7 Boundary Protection
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Reconnaissance (TA0043)
Ensure the Application Firewall Is Enabled
Finding: The application firewall is disabled.
Checks the macOS application firewall product state reported by the endpoint.
This rule fails when no firewall product reports productState of ON or ON_WITH_STEALTH_MODE.
Rationale: The firewall limits inbound connections to listening services, reducing remote attack surface.
Impact: Inbound connections are filtered by the application firewall.
Remediation
Open System Settings > Network > Firewall and turn the firewall on.
From the command line:
/usr/bin/sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.5 Implement and Manage a Firewall on End-User Devices; 13.1 Centralize Security Event Alerting
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AU-6 Audit Record Review, Analysis, and Reporting; AU-7 Audit Record Reduction and Report Generation; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; IR-4 Incident Handling; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SC-7 Boundary Protection; SI-4 System Monitoring
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.14.3 Monitor system security alerts and advisories and take action in response
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; SI.L2-3.14.3 Monitor system security alerts and advisories and take action in response
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 10.7.1 Service providers alert promptly when critical security systems fail; 10.7.2 Alert promptly when critical controls like IDS or NSCs fail; 10.7.3 Handle security control failures by restoring functions and documenting impact; 11.5 Spot and react to intrusions and unauthorized file modifications
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
2.3 General
Ensure AirDrop Is Disabled
Finding: AirDrop is enabled.
Checks the MDM device-restriction governing AirDrop.
This rule fails when allowAirDrop is not false.
Rationale: AirDrop can be used to exfiltrate data or receive unsolicited files from nearby devices.
Impact: Users cannot send or receive files via AirDrop.
Remediation
Deploy a configuration profile that sets allowAirDrop to false (Restrictions payload).
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 6.7 Centralize Access Control
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-3 Access Enforcement; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure AirPlay Receiver Is Disabled
Finding: AirPlay Receiver is enabled.
Checks the MDM device-restriction governing incoming AirPlay requests.
This rule fails when allowAirPlayIncomingRequests is not false.
Rationale: An enabled AirPlay receiver exposes a listening service that can accept content from nearby devices.
Impact: The Mac no longer accepts incoming AirPlay streams.
Remediation
Deploy a configuration profile that sets allowAirPlayIncomingRequests to false (Restrictions payload).
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Set Time and Date Automatically Is Enabled
Finding: Automatic date and time is disabled.
Checks whether the system synchronizes date and time automatically over the network.
This rule fails when isNetworkTimeEnabled is false.
Rationale: Accurate time is essential for certificate validation, Kerberos, and reliable log correlation.
Impact: System clock is kept synchronized with a network time source.
Remediation
Open System Settings > General > Date & Time and enable Set time and date automatically.
From the command line:
/usr/bin/sudo /usr/sbin/systemsetup -setusingnetworktime on
- Framework mappings
- CIS Controls v8: 8.4 Standardize Time Synchronization
- NIST SP 800-53 Rev. 5: AU-8 Time Stamps; AU-12 Audit Record Generation
- NIST SP 800-171 Rev. 2: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- CMMC 2.0 Level 2: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- PCI DSS v4.0.1: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure Bluetooth Sharing Is Disabled
Finding: Bluetooth Sharing is enabled.
Checks each user's Bluetooth Sharing setting.
This rule fails when bluetoothSharingEnabled is true for a user.
Rationale: Bluetooth Sharing lets nearby devices exchange files, a data-exfiltration and malware vector.
Impact: Users can no longer exchange files over Bluetooth Sharing.
Remediation
Open System Settings > General > Sharing and turn Bluetooth Sharing off.
- Framework mappings
- CIS Controls v8: 3.3 Configure Data Access Control Lists; 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; MP-2 Media Access; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.8.2 Limit access to CUI on system media to authorized users
- CMMC 2.0 Level 1: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- CMMC 2.0 Level 2: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 7.1 Governance processes for need-to-know access restriction are established
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Content Caching Is Disabled
Finding: Content Caching is enabled.
Checks the MDM device-restriction governing Content Caching.
This rule fails when allowContentCaching is not false.
Rationale: Content Caching opens a listening service and can serve cached Apple content to the network.
Impact: The Mac no longer caches or serves Apple content to other devices.
Remediation
Deploy a configuration profile that sets allowContentCaching to false, or in System Settings > General > Sharing turn Content Caching off.
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure File Sharing Is Disabled
Finding: File Sharing is enabled.
Checks each launchd service; fails when the SMB file-sharing service is running.
This rule fails when the com.apple.smbd service state is RUNNING.
Rationale: File Sharing exposes an SMB service that can leak data or be attacked over the network.
Impact: Network file sharing is unavailable until re-enabled.
Remediation
Open System Settings > General > Sharing and turn File Sharing off.
From the command line:
/usr/bin/sudo /bin/launchctl disable system/com.apple.smbd
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-6 Least Privilege; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions; 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions; AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Internet Sharing Is Disabled
Finding: Internet Sharing is not forced off.
Checks whether Internet Sharing is forced off by policy.
This rule fails when forceInternetSharingOff is not true.
Rationale: Internet Sharing turns the Mac into a router/AP, bridging networks and expanding attack surface.
Impact: The Mac cannot share its internet connection to other devices.
Remediation
Deploy a configuration profile that forces Internet Sharing off, or in System Settings > General > Sharing turn Internet Sharing off.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/SystemConfiguration/com.apple.nat NAT -dict Enabled -int 0
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Media Sharing Is Disabled
Finding: Media Sharing is enabled.
Checks the MDM device-restriction governing Media Sharing.
This rule fails when allowMediaSharing is not false.
Rationale: Media Sharing exposes a listening service that shares the media library to the network.
Impact: The Mac no longer shares its media library.
Remediation
Deploy a configuration profile that sets allowMediaSharing to false, or in System Settings > General > Sharing turn Media Sharing off.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Printer Sharing Is Disabled
Finding: Printer Sharing is enabled.
Checks whether printer sharing is enabled on the system.
This rule fails when printerSharingEnabled is true.
Rationale: Shared printers expose a listening service and can be leveraged for lateral movement.
Impact: Locally connected printers are no longer shared to the network.
Remediation
Open System Settings > General > Sharing and turn Printer Sharing off.
From the command line:
/usr/bin/sudo /usr/sbin/cupsctl --no-share-printers
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Remote Apple Events Is Disabled
Finding: Remote Apple Events is enabled.
Checks whether the system accepts remote Apple Events from other machines.
This rule fails when getRemoteAppleEvents is true.
Rationale: Remote Apple Events allow scripted control of the Mac from the network, aiding remote execution.
Impact: The Mac no longer accepts Apple Events from remote hosts.
Remediation
Open System Settings > General > Sharing and turn Remote Apple Events off.
From the command line:
/usr/bin/sudo /usr/sbin/systemsetup -setremoteappleevents off
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Remote Login Is Disabled
Finding: Remote Login (SSH) is enabled.
Checks each launchd service; fails when the SSH remote-login service is running.
This rule fails when the com.openssh.sshd service state is RUNNING.
Rationale: SSH remote login is a high-value target for brute force and unauthorized remote access.
Impact: Remote SSH login is unavailable until re-enabled.
Remediation
Open System Settings > General > Sharing and turn Remote Login off.
From the command line:
/usr/bin/sudo /usr/sbin/systemsetup -setremotelogin off
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Remote Management Is Disabled
Finding: Remote Management (ARD) is enabled.
Checks each launchd service; fails when the Apple Remote Desktop agent is running.
This rule fails when the com.apple.RemoteDesktop.agent service state is RUNNING.
Rationale: Apple Remote Desktop grants remote control and management, a major concern on mobile systems.
Impact: Remote Management access via ARD is disabled.
Remote Management is detected as the ARDAgent launchd job (com.apple.RemoteDesktop.agent); the CIS audit inspects the ARDAgent process.
Remediation
Open System Settings > General > Sharing and turn Remote Management off.
From the command line:
/usr/bin/sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -deactivate -stop
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-6 Least Privilege; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions; 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions; AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Screen Sharing Is Disabled
Finding: Screen Sharing is enabled.
Checks each launchd service; fails when the Screen Sharing service is running.
This rule fails when the com.apple.screensharing service state is RUNNING.
Rationale: Screen Sharing opens a remote-control listening service that expands remote attack surface.
Impact: Remote screen sharing is unavailable until re-enabled.
Remediation
Open System Settings > General > Sharing and turn Screen Sharing off.
From the command line:
/usr/bin/sudo /bin/launchctl disable system/com.apple.screensharing
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Time Machine Automatic Backup Is Enabled
Finding: Time Machine automatic backup is disabled.
Checks that automatic backup is enabled whenever Time Machine has a configured destination.
This rule fails when a Time Machine destination is configured but autoBackup is not true.
Rationale: Automatic backups ensure recoverable copies exist without relying on manual action.
Impact: Time Machine backs up automatically on the usual schedule.
Conditional: passes when Time Machine has no destinations (not in use) OR automatic backup is enabled.
Remediation
Open System Settings > General > Time Machine and enable Back Up Automatically.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.TimeMachine.plist AutoBackup -bool true
- Framework mappings
- CIS Controls v8: 11.2 Perform Automated Backups
- NIST SP 800-53 Rev. 5: CP-9 System Backup; CP-10 System Recovery and Reconstitution
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure Time Machine Volumes Are Encrypted
Finding: A Time Machine backup destination is not encrypted.
Checks that every configured Time Machine destination is encrypted.
This rule fails when any Time Machine destination's lastKnownEncryptionState is not ENCRYPTED.
Rationale: Unencrypted backups expose a full copy of system data if the backup media is lost or stolen.
Impact: Time Machine backups are stored encrypted.
Conditional: passes when no Time Machine destination exists OR every destination reports ENCRYPTED.
Remediation
In System Settings > General > Time Machine remove the destination and re-add it with Encrypt Backups enabled.
- Framework mappings
- CIS Controls v8: 3.6 Encrypt Data on End-User Devices; 3.11 Encrypt Sensitive Data at Rest; 11.3 Protect Recovery Data
- NIST SP 800-53 Rev. 5: AU-9 Protection of Audit Information; CP-9 System Backup; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.8.9 Protect the confidentiality of backup CUI at storage locations; 3.13.16 Protect the confidentiality of CUI at rest
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; MP.L2-3.8.9 Protect the confidentiality of backup CUI at storage locations; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Impact (TA0040)
2.5 Apple Intelligence & Siri
Ensure Apple Intelligence Writing Tools Are Disabled
Finding: Apple Intelligence writing tools are allowed.
Apple Intelligence Writing Tools rewrite, proofread and summarize text and may process it through Apple's private cloud rather than only on-device.
This rule fails when allowWritingTools is not false.
Rationale: Sensitive text handled by Writing Tools can leave the device for cloud processing, creating a data-leakage path.
Impact: Users lose the AI-assisted rewrite, proofread and summarize actions.
Remediation
Open System Settings > General > Device Management and confirm an installed profile sets Allow Writing Tools to off.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- NIST SP 800-53 Rev. 5: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure External Intelligence Extensions Are Disabled
Finding: External intelligence integrations are allowed.
External intelligence extensions let Apple Intelligence hand requests to third-party generative AI services such as ChatGPT.
This rule fails when allowExternalIntelligenceIntegrations or allowExternalIntelligenceIntegrationsSignIn is not false.
Rationale: Routing prompts or documents to an external AI provider moves organizational data outside managed controls and onto a third party.
Impact: Users can no longer reach third-party AI providers through Apple Intelligence.
Remediation
Open System Settings > General > Device Management and confirm an installed profile sets Allow External Intelligence Extensions and Allow External Intelligence Sign-In to off.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- NIST SP 800-53 Rev. 5: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Mail Summarization Is Disabled
Finding: Mail summarization is allowed.
Apple Intelligence Mail summarization condenses emails and threads and may process message content off-device.
This rule fails when allowMailSummary is not false.
Rationale: Confidential email content could be sent to Apple for summarization instead of staying under organizational controls.
Impact: Users no longer see automatic or on-demand email summaries.
Remediation
Open System Settings > General > Device Management and confirm an installed profile sets Allow Mail Summary to off.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- NIST SP 800-53 Rev. 5: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Notes Summarization Is Disabled
Finding: Notes summarization is allowed.
Apple Intelligence Notes summarization transcribes and summarizes written notes and in-app audio recordings, which may be processed off-device.
This rule fails when allowNotesTranscription or allowNotesTranscriptionSummary is not false.
Rationale: Transcribed audio and note content can contain highly sensitive material that should not leave the device for AI processing.
Impact: Users no longer get automatic or on-demand summaries of notes or recordings.
Remediation
Open System Settings > General > Device Management and confirm an installed profile sets Allow Notes Transcription and Allow Notes Transcription Summary to off.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- NIST SP 800-53 Rev. 5: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Listen For Siri Is Disabled
Finding: Listen for Siri voice trigger is enabled.
The Hey Siri voice trigger keeps the microphone continuously listening for the wake phrase for this user.
This rule fails when a user's siriVoiceTriggerEnabled is not false.
Rationale: An always-on microphone listening for a wake word risks unintended capture and disclosure of nearby conversations.
Impact: The user must invoke Siri manually rather than by voice.
Remediation
Open System Settings > Apple Intelligence & Siri and turn off Listen for so the microphone is not always active for the voice trigger.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Siri Is Disabled
Finding: Siri is allowed.
Siri accepts voice and text queries and can relay device context to Apple; the always-listening trigger cannot be reliably disabled while Siri is enabled.
This rule fails when allowAssistant is not false.
Rationale: A live assistant with cloud processing can disclose confidential activity captured by the microphone in shared work spaces.
Impact: Users lose hands-free voice control and Siri lookups.
Remediation
Open System Settings > General > Device Management and confirm an installed profile sets Allow Assistant to off.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
2.6 Privacy & Security
Ensure An Administrator Password Is Required To Access System-Wide Preferences
Finding: System-wide preferences do not require an administrator password.
The system.preferences authorization right controls whether changing system-wide settings requires re-authenticating as an administrator.
This rule fails when the system.preferences right's shared value is not false (or is missing).
Rationale: Requiring an administrator password prevents standard users from altering configuration that affects the whole system.
Impact: Users must authenticate to unlock preference panes such as Network, Startup Disk and Printers & Scanners.
Remediation
Open System Settings > Privacy & Security > Advanced and turn on Require an administrator password to access system-wide settings.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
Ensure FileVault Is Enabled
Finding: FileVault disable is not restricted.
FileVault encrypts the boot volume so its contents require a password or recovery key to access; the enforcing policy prevents it from being turned off.
This rule fails when fileVaultDisableRestricted is not true.
Rationale: Full-volume encryption minimizes the risk of data exposure if the device or disk is lost or stolen.
Impact: Mounting the encrypted volume from another boot source requires a valid password.
Remediation
Open System Settings > Privacy & Security, turn FileVault on, and confirm an installed profile sets FileVault Can't Disable so it cannot be turned off.
- Framework mappings
- CIS Controls v8: 3.6 Encrypt Data on End-User Devices; 3.11 Encrypt Sensitive Data at Rest
- NIST SP 800-53 Rev. 5: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- NIST SP 800-171 Rev. 2: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
- CMMC 2.0 Level 2: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- PCI DSS v4.0.1: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Impact (TA0040)
Ensure Gatekeeper Is Enabled
Finding: Gatekeeper is disabled.
Gatekeeper verifies that applications are signed and notarized on every launch before allowing them to run.
This rule fails when isGatekeeperEnabled is not true.
Rationale: Blocking unsigned or unnotarized software reduces the risk of running tampered or malicious applications.
Impact: Users cannot launch unsigned applications without an explicit override.
Remediation
Open System Settings > Privacy & Security > Security and set Allow apps downloaded from to App Store and identified developers.
From the command line:
/usr/bin/sudo /usr/sbin/spctl --global-enable
- Framework mappings
- CIS Controls v8: 10.1 Deploy and Maintain Anti-Malware Software; 10.2 Configure Automatic Anti-Malware Signature Updates; 10.5 Enable Anti-Exploitation Features
- NIST SP 800-53 Rev. 5: MP-6 Media Sanitization; SI-3 Malicious Code Protection; SI-16 Memory Protection
- NIST SP 800-171 Rev. 2: 3.14.2 Provide protection from malicious code at designated locations within organizational systems; 3.14.4 Update malicious code protection mechanisms when new releases are available
- CMMC 2.0 Level 1: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems; SI.L1-b.1.xiv Update malicious code protection mechanisms when new releases are available
- CMMC 2.0 Level 2: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems; SI.L2-3.14.4 Update malicious code protection mechanisms when new releases are available
- PCI DSS v4.0.1: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.1 Keep anti-malware current through automatic updates; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis
- Risk
- Insecure Application
- MITRE ATT&CK tactic
- Execution (TA0002)
Ensure Limit Ad Tracking Is Enabled
Finding: Personalized advertising is allowed.
Personalized advertising lets Apple correlate user data to target advertisements.
This rule fails when allowApplePersonalizedAdvertising is not false.
Rationale: Collected advertising metadata is valuable to attackers and has been used to help re-identify users.
Impact: Users see generic rather than targeted advertising.
Remediation
Open System Settings > General > Device Management and confirm an installed profile sets Allow Apple Personalized Advertising to off.
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
Ensure Location Icon Is Shown When System Services Request Location
Finding: System Services location icon is not shown.
This setting shows a menu bar indicator whenever a system service accesses the device location.
This rule fails when showLocationSystemServices is not true.
Rationale: A visible indicator gives users awareness of when background system services use their location.
Impact: Users gain visibility into system-service location access; there is no functional downside.
Remediation
Open System Settings > Privacy & Security > Location Services > Details and turn on Show location icon in menu bar when System Services request your location.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.locationmenu.plist ShowSystemServices -bool true
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Location Services Is Enabled
Finding: Location Services is disabled.
Location Services lets macOS derive the device's location for time-zone, asset, and log correlation features.
This rule fails when locationServicesEnabled is not true.
Rationale: Consistent location data simplifies asset and time management across devices that change time zones.
Impact: If disabled by policy, features that depend on location will no longer work automatically.
Remediation
Open System Settings > Privacy & Security > Location Services and turn Location Services on.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd LocationServicesEnabled -bool true
/usr/bin/sudo /usr/bin/killall locationd
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Discovery (TA0007)
Ensure Improve Siri And Dictation Is Disabled
Finding: Siri and dictation improvement sharing is enabled.
Improve Siri & Dictation lets Apple store and review audio of a user's Siri and dictation interactions.
This rule fails when a user's siriDataSharingOptIn is not OPTED_OUT.
Rationale: Audio recordings sent to Apple may contain PII or restricted organizational information.
Impact: There is no user-facing impact from opting out of Siri and dictation sharing.
Remediation
Open System Settings > General > Device Management and confirm an installed profile sets Siri Data Sharing Opt-In Status to opted out.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
2.7 Desktop & Dock
Ensure Screen Saver Hot Corners Do Not Disable The Screen Saver
Finding: A hot corner is set to disable the screen saver.
Checks the hot corner assignments for any corner mapped to the Disable Screen Saver action (value 6).
This rule fails when any hot corner (bottomLeft, bottomRight, topLeft or topRight) equals 6 (Disable Screen Saver).
Rationale: A corner that disables the screen saver lets someone bypass the automatic lock and reach an unlocked session.
Impact: There is no user-facing impact from clearing a screen-saver-disabling hot corner.
Remediation
Open System Settings > Desktop & Dock > Hot Corners and change any corner set to Disable Screen Saver to a setting allowed by your organization.
From the command line:
for u in $(/usr/bin/dscl . -list /Users UniqueID | /usr/bin/awk '$2 >= 500 {print $1}'); do for c in bl br tl tr; do /usr/bin/sudo -u "$u" /usr/bin/defaults delete /Users/"$u"/Library/Preferences/com.apple.dock wvous-$c-corner; done; done
- Framework mappings
- CIS Controls v8: 4.3 Configure Automatic Session Locking on Enterprise Assets
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
- NIST SP 800-171 Rev. 2: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- CMMC 2.0 Level 2: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- PCI DSS v4.0.1: 8.2.8 Require re-authentication after 15 minutes of session inactivity
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
2.9 Spotlight
Ensure Help Apple Improve Search Is Disabled
Finding: Search data is shared with Apple.
Help Apple Improve Search forwards Spotlight and Search query metadata to Apple.
This rule fails when a user's searchDataSharingEnabled is not false.
Rationale: Search metadata may contain internal organizational information that should not be processed by a third party.
Impact: There is no user-facing impact beyond search metadata no longer being shared with Apple.
Remediation
Open System Settings > General > Device Management and confirm an installed profile sets Search Queries Data Sharing Status to not sharing.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)
2.10 Battery (Energy Saver)
Ensure Power Nap Is Disabled
Finding: Power Nap is enabled.
Verifies Power Nap (dark-wake background tasks) is off, so a sleeping Mac does not periodically wake to phone home over previously joined networks.
This rule fails when darkWakeBackgroundTasks is true on the battery or AC power profile.
Rationale: Power Nap wakes the system to reach known networks while unattended, expanding the attack surface.
Impact: With Power Nap off, the Mac will not fetch mail or updates while asleep.
Applies primarily to Intel Macs; on Apple Silicon the field is typically absent and passes by default.
Remediation
Open System Settings > Battery (and Power Adapter) and turn Power Nap off for every power source.
From the command line:
/usr/bin/sudo /usr/bin/pmset -a powernap 0
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Persistence (TA0003)
Ensure Wake for Network Access Is Disabled
Finding: Wake for network access is enabled.
Verifies Wake-on-LAN is disabled so an attacker cannot remotely wake an unattended, encrypted Mac.
This rule fails when wakeOnLAN is true on the battery or AC power profile.
Rationale: Remote wake lets an attacker resume a sleeping system and reach its shared resources.
Impact: Management tools relying on Wake-on-LAN cannot wake the Mac over the network.
Remediation
Open System Settings > Battery > Options (or Energy Saver) and set Wake for network access to Never.
From the command line:
/usr/bin/sudo /usr/bin/pmset -a womp 0
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Sleep and Display Sleep Are Enabled
Finding: System or display sleep is disabled or exceeds the allowed interval.
Verifies that Apple Silicon laptops put the system to sleep within 15 minutes and the display within 10 minutes so an unattended Mac returns to a locked, encrypted state.
This rule fails on an Apple Silicon Mac with a battery power profile when systemSleepTimer is 0/over 15 minutes or displaySleepTimer is 0/over 10 minutes.
Rationale: Enabling sleep ensures an unattended laptop returns to a locked, encrypted state within a bounded time.
Impact: The system takes additional time to resume from sleep.
Remediation
Open System Settings > Battery > Options (or Energy Saver) and set the system to sleep after 15 minutes or less and the display to sleep after 10 minutes or less.
From the command line:
/usr/bin/sudo /usr/bin/pmset -a sleep 15
/usr/bin/sudo /usr/bin/pmset -a displaysleep 10
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
2.11 Lock Screen
Ensure a Custom Login Screen Message Is Configured
Finding: No custom login screen message is configured.
Verifies a login-window banner is set to inform users the system is for authorized use only.
This rule fails when loginWindowText is empty or unset.
Rationale: An access warning deters casual attackers and supports prosecution by evidencing notice.
Impact: Users see an authorized-use message at the login window.
Remediation
Open System Settings > Lock Screen, enable Show message when locked, select Set, and enter your organization's authorized-use banner text.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow LoginwindowText "Authorized use only."
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure a Password Is Required After Screen Saver or Display Sleep
Finding: No password is required after the screen saver begins or the display sleeps.
Verifies each user must enter a password to wake from the screen saver or display sleep.
This rule fails when askForPassword is not true for a user.
Rationale: Prompting for a password on wake stops someone from using an unlocked, unattended session.
Impact: Users must re-authenticate when returning to the Mac.
Per-user rule anchored on USER_SYSTEM_SETTINGS. The '5 seconds or immediately' delay (askForPasswordDelay) is not exposed in the schema, so only the password requirement itself is enforced.
Remediation
Open System Settings > Lock Screen and set Require password after screen saver begins or display is turned off to immediately or after 5 seconds.
From the command line:
/usr/bin/defaults -currentHost write com.apple.screensaver askForPassword -int 1
- Framework mappings
- CIS Controls v8: 4.7 Manage Default Accounts on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure Password Hints Are Not Shown at the Login Window
Finding: Password hints can be shown at the login window.
Verifies the login window never displays password hints after failed attempts.
This rule fails when retriesUntilHint is not 0.
Rationale: Password hints can reveal the password or clues usable in social-engineering attacks.
Impact: Users no longer see a hint after mistyping their password.
Remediation
Open System Settings > Lock Screen and turn Show password hints off.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow RetriesUntilHint -int 0
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure Screen Saver Inactivity Interval Is 15 Minutes or Less
Finding: Screen saver inactivity interval exceeds 15 minutes.
Verifies each user's screen saver starts after no more than 15 minutes of inactivity so an unattended session locks.
This rule fails when idleTime is 0 (never) or greater than 15 minutes for a user.
Rationale: A locking screen saver limits access to an unattended session.
Impact: Users returning to an idle Mac must re-authenticate.
Per-user rule anchored on USER_SYSTEM_SETTINGS; idleTime is a Duration compared in nanoseconds (15 min = 900000000000).
Remediation
Open System Settings > Lock Screen and set Start Screen Saver when inactive to 15 minutes or less.
- Framework mappings
- CIS Controls v8: 4.3 Configure Automatic Session Locking on Enterprise Assets
- NIST SP 800-53 Rev. 5: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
- NIST SP 800-171 Rev. 2: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- CMMC 2.0 Level 2: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- PCI DSS v4.0.1: 8.2.8 Require re-authentication after 15 minutes of session inactivity
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure the Login Window Displays Name and Password
Finding: The login window shows a user list instead of name and password fields.
Verifies the login window requires typing both a username and password rather than picking a user from a list.
This rule fails when loginWindowShowFullName is not true.
Rationale: Requiring both a username and password doubles the unknowns an attacker must supply.
Impact: Users type their account name at login instead of clicking an icon.
Remediation
Open System Settings > Lock Screen and set Login window shows to Name and Password.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow SHOWFULLNAME -bool true
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
2.12 Touch ID & Password (Login Password)
Ensure User Accounts Do Not Have a Password Hint
Finding: A user account has a password hint set.
Verifies each user account has no password hint recorded.
This rule fails when hasPasswordHint is true for a user.
Rationale: Password hints are easily guessed or socially engineered and may reveal the password itself.
Impact: Users lose the hint shown after failed password attempts.
Per-user rule anchored on USER_SYSTEM_SETTINGS; evaluates each user account independently.
Remediation
Open System Settings > Touch ID & Password (or Login Password), select Change, and clear the Password hint field.
From the command line:
/usr/bin/sudo /usr/bin/dscl . -delete /Users/<username> hint
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- NIST SP 800-171 Rev. 2: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Credential Access (TA0006)
2.13 Users & Groups
Ensure Automatic Login Is Disabled
Finding: Automatic login is enabled.
Verifies the system does not bypass the login window by automatically logging a user in at boot.
This rule fails when automaticLoginEnabled is true.
Rationale: Automatic login lets anyone with physical access reach a user's session without credentials.
Impact: Users must authenticate at every boot.
Remediation
Open System Settings > Users & Groups and set Automatically log in as to Off.
From the command line:
/usr/bin/sudo /usr/bin/defaults delete /Library/Preferences/com.apple.loginwindow autoLoginUser
- Framework mappings
- CIS Controls v8: 4.7 Manage Default Accounts on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: IA-5 Authenticator Management
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure the Guest Account Is Disabled
Finding: The guest account is enabled.
Verifies the guest account cannot log in, either by system state or by MDM policy.
This rule fails when guestEnabled is true and enableGuestAccount is not false.
Rationale: A guest login lets an untrusted user perform reconnaissance and attempt privilege escalation.
Impact: Guests can no longer log in to the Mac.
Remediation
Open System Settings > Users & Groups, select the info button next to Guest User, and turn Allow guests to log in to this computer off.
From the command line:
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow GuestEnabled -bool false
- Framework mappings
- CIS Controls v8: 5.2 Use Unique Passwords; 6.2 Establish an Access Revoking Process; 6.8 Define and Maintain Role-Based Access Control
- NIST SP 800-53 Rev. 5: AC-1 Policy and Procedures; AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange; IA-5 Authenticator Management; PS-4 Personnel Termination
- NIST SP 800-171 Rev. 2: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts; 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- CMMC 2.0 Level 2: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts; IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- PCI DSS v4.0.1: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 8.2.4 Authorize and track additions, removals, and changes to user identities and credentials; 8.2.5 Remove access for departing users without delay; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts; 10.3.1 Restrict viewing of audit log files to staff who need it
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Initial Access (TA0001)
2.18 Keyboard
Ensure On-Device Dictation Is Enabled
Finding: Dictation is allowed to send audio to Apple servers.
Verifies dictation is forced to run on-device so dictated content is not sent to Apple's servers.
This rule fails when forceOnDeviceOnlyDictation is not true.
Rationale: Server-side dictation can spill confidential dictated content off the device.
Impact: On-device dictation cannot use server-side learning to improve recognition.
Remediation
Deploy a configuration profile (payload com.apple.applicationaccess) that sets forceOnDeviceOnlyDictation to true.
- Framework mappings
- CIS Controls v8: 4.1 Establish and Maintain a Secure Configuration Process
- NIST SP 800-53 Rev. 5: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- NIST SP 800-171 Rev. 2: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- CMMC 2.0 Level 2: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- PCI DSS v4.0.1: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components
- Risk
- Unprotected Data
- MITRE ATT&CK tactic
- Command and Control / Exfiltration (TA0011, TA0010)