---
title: CIS macOS Tahoe System Settings: 47 Checks | Wartiva
description: Wartiva's 47 checks for section 2, System Settings, of the CIS Apple macOS 26 Tahoe Benchmark: what each one finds, why it matters, and how to fix it.
url: https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html
updated: 2026-10-07
---

CIS Apple macOS 26 Tahoe Benchmark · Section 2

# macOS Tahoe System Settings: 47 Checks

Wartiva runs 47 checks for section 2, System Settings, of the CIS Apple macOS 26 Tahoe Benchmark. Each one lists what it finds, why it matters, and how to fix it.

Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. [How Wartiva works →](https://wartiva.com/platform.html)

## 2.1 Apple Account

### [Ensure iCloud Drive Document and Desktop Sync Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#icloud-drive-document-and-desktop-sync-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.1.1

**Finding:** iCloud Desktop and Documents sync is enabled.

Checks the MDM device-restriction controlling iCloud Drive Desktop & Documents folder syncing.

This rule fails when `allowCloudDesktopAndDocuments` is not `false`.

**Rationale:** Syncing Desktop and Documents to iCloud can move organizational data outside managed storage.

**Impact:** Desktop and Documents folders no longer sync to iCloud Drive.

#### Remediation

Deploy a configuration profile that sets **allowCloudDesktopAndDocuments** to false (Restrictions payload), or in **System Settings > [Apple Account] > iCloud > Drive** turn off **Desktop & Documents Folders**.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- **NIST SP 800-53 Rev. 5**: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 2.2 Network

### [Ensure Firewall Stealth Mode Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#firewall-stealth-mode-is-enabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.2

**Finding:** Firewall stealth mode is disabled.

Checks whether the macOS application firewall is running with stealth mode active.

This rule fails when no firewall product reports `productState` of `ON_WITH_STEALTH_MODE`.

**Rationale:** Stealth mode drops probes (e.g. ICMP, port scans), making the host harder to discover.

**Impact:** The host stops responding to unsolicited network probes.

#### Remediation

Open **System Settings > Network > Firewall > Options** and enable **Stealth Mode**.

From the command line:

```sh
/usr/bin/sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setstealthmode on
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.5 Implement and Manage a Firewall on End-User Devices; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SC-7 Boundary Protection
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Reconnaissance ([TA0043](https://attack.mitre.org/tactics/TA0043/))

### [Ensure the Application Firewall Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#the-application-firewall-is-enabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.2

**Finding:** The application firewall is disabled.

Checks the macOS application firewall product state reported by the endpoint.

This rule fails when no firewall product reports `productState` of `ON` or `ON_WITH_STEALTH_MODE`.

**Rationale:** The firewall limits inbound connections to listening services, reducing remote attack surface.

**Impact:** Inbound connections are filtered by the application firewall.

#### Remediation

Open **System Settings > Network > Firewall** and turn the firewall on.

From the command line:

```sh
/usr/bin/sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.5 Implement and Manage a Firewall on End-User Devices; 13.1 Centralize Security Event Alerting
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AU-6 Audit Record Review, Analysis, and Reporting; AU-7 Audit Record Reduction and Report Generation; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; IR-4 Incident Handling; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SC-7 Boundary Protection; SI-4 System Monitoring
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.14.3 Monitor system security alerts and advisories and take action in response
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; SI.L2-3.14.3 Monitor system security alerts and advisories and take action in response
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 10.7.1 Service providers alert promptly when critical security systems fail; 10.7.2 Alert promptly when critical controls like IDS or NSCs fail; 10.7.3 Handle security control failures by restoring functions and documenting impact; 11.5 Spot and react to intrusions and unauthorized file modifications

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 2.3 General

### [Ensure AirDrop Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#airdrop-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.1

**Finding:** AirDrop is enabled.

Checks the MDM device-restriction governing AirDrop.

This rule fails when `allowAirDrop` is not `false`.

**Rationale:** AirDrop can be used to exfiltrate data or receive unsolicited files from nearby devices.

**Impact:** Users cannot send or receive files via AirDrop.

#### Remediation

Deploy a configuration profile that sets **allowAirDrop** to false (Restrictions payload).

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 6.7 Centralize Access Control
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-3 Access Enforcement; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure AirPlay Receiver Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#airplay-receiver-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.1

**Finding:** AirPlay Receiver is enabled.

Checks the MDM device-restriction governing incoming AirPlay requests.

This rule fails when `allowAirPlayIncomingRequests` is not `false`.

**Rationale:** An enabled AirPlay receiver exposes a listening service that can accept content from nearby devices.

**Impact:** The Mac no longer accepts incoming AirPlay streams.

#### Remediation

Deploy a configuration profile that sets **allowAirPlayIncomingRequests** to false (Restrictions payload).

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Set Time and Date Automatically Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#set-time-and-date-automatically-is-enabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.2

**Finding:** Automatic date and time is disabled.

Checks whether the system synchronizes date and time automatically over the network.

This rule fails when `isNetworkTimeEnabled` is `false`.

**Rationale:** Accurate time is essential for certificate validation, Kerberos, and reliable log correlation.

**Impact:** System clock is kept synchronized with a network time source.

#### Remediation

Open **System Settings > General > Date & Time** and enable **Set time and date automatically**.

From the command line:

```sh
/usr/bin/sudo /usr/sbin/systemsetup -setusingnetworktime on
```

Framework mappings

- **CIS Controls v8**: 8.4 Standardize Time Synchronization
- **NIST SP 800-53 Rev. 5**: AU-8 Time Stamps; AU-12 Audit Record Generation
- **NIST SP 800-171 Rev. 2**: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- **CMMC 2.0 Level 2**: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- **PCI DSS v4.0.1**: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes

Risk

Reliability Impact

MITRE ATT&CK tactic

Defense Evasion ([TA0005](https://attack.mitre.org/tactics/TA0005/))

### [Ensure Bluetooth Sharing Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#bluetooth-sharing-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Bluetooth Sharing is enabled.

Checks each user's Bluetooth Sharing setting.

This rule fails when `bluetoothSharingEnabled` is `true` for a user.

**Rationale:** Bluetooth Sharing lets nearby devices exchange files, a data-exfiltration and malware vector.

**Impact:** Users can no longer exchange files over Bluetooth Sharing.

#### Remediation

Open **System Settings > General > Sharing** and turn **Bluetooth Sharing** off.

Framework mappings

- **CIS Controls v8**: 3.3 Configure Data Access Control Lists; 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: AC-3 Access Enforcement; AC-5 Separation of Duties; AC-6 Least Privilege; CA-3 Information Exchange; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; MP-2 Media Access; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); 3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.8.2 Limit access to CUI on system media to authorized users
- **CMMC 2.0 Level 1**: AC.L1-b.1.i Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems); AC.L1-b.1.ii Limit information system access to the types of transactions and functions that authorized users are permitted to execute
- **CMMC 2.0 Level 2**: AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems); AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute; AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; MP.L2-3.8.2 Limit access to CUI on system media to authorized users
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.3.1 Limit inbound CDE traffic to what is necessary, denying the rest; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 7.1 Governance processes for need-to-know access restriction are established

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Content Caching Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#content-caching-is-disabled)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Content Caching is enabled.

Checks the MDM device-restriction governing Content Caching.

This rule fails when `allowContentCaching` is not `false`.

**Rationale:** Content Caching opens a listening service and can serve cached Apple content to the network.

**Impact:** The Mac no longer caches or serves Apple content to other devices.

#### Remediation

Deploy a configuration profile that sets **allowContentCaching** to false, or in **System Settings > General > Sharing** turn **Content Caching** off.

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure File Sharing Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#file-sharing-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** File Sharing is enabled.

Checks each launchd service; fails when the SMB file-sharing service is running.

This rule fails when the `com.apple.smbd` service `state` is `RUNNING`.

**Rationale:** File Sharing exposes an SMB service that can leak data or be attacked over the network.

**Impact:** Network file sharing is unavailable until re-enabled.

#### Remediation

Open **System Settings > General > Sharing** and turn **File Sharing** off.

From the command line:

```sh
/usr/bin/sudo /bin/launchctl disable system/com.apple.smbd
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-6 Least Privilege; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions; 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions; AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Internet Sharing Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#internet-sharing-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Internet Sharing is not forced off.

Checks whether Internet Sharing is forced off by policy.

This rule fails when `forceInternetSharingOff` is not `true`.

**Rationale:** Internet Sharing turns the Mac into a router/AP, bridging networks and expanding attack surface.

**Impact:** The Mac cannot share its internet connection to other devices.

#### Remediation

Deploy a configuration profile that forces Internet Sharing off, or in **System Settings > General > Sharing** turn **Internet Sharing** off.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/SystemConfiguration/com.apple.nat NAT -dict Enabled -int 0
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Media Sharing Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#media-sharing-is-disabled)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Media Sharing is enabled.

Checks the MDM device-restriction governing Media Sharing.

This rule fails when `allowMediaSharing` is not `false`.

**Rationale:** Media Sharing exposes a listening service that shares the media library to the network.

**Impact:** The Mac no longer shares its media library.

#### Remediation

Deploy a configuration profile that sets **allowMediaSharing** to false, or in **System Settings > General > Sharing** turn **Media Sharing** off.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Printer Sharing Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#printer-sharing-is-disabled)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Printer Sharing is enabled.

Checks whether printer sharing is enabled on the system.

This rule fails when `printerSharingEnabled` is `true`.

**Rationale:** Shared printers expose a listening service and can be leveraged for lateral movement.

**Impact:** Locally connected printers are no longer shared to the network.

#### Remediation

Open **System Settings > General > Sharing** and turn **Printer Sharing** off.

From the command line:

```sh
/usr/bin/sudo /usr/sbin/cupsctl --no-share-printers
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Remote Apple Events Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#remote-apple-events-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Remote Apple Events is enabled.

Checks whether the system accepts remote Apple Events from other machines.

This rule fails when `getRemoteAppleEvents` is `true`.

**Rationale:** Remote Apple Events allow scripted control of the Mac from the network, aiding remote execution.

**Impact:** The Mac no longer accepts Apple Events from remote hosts.

#### Remediation

Open **System Settings > General > Sharing** and turn **Remote Apple Events** off.

From the command line:

```sh
/usr/bin/sudo /usr/sbin/systemsetup -setremoteappleevents off
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Remote Login Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#remote-login-is-disabled)

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Remote Login (SSH) is enabled.

Checks each launchd service; fails when the SSH remote-login service is running.

This rule fails when the `com.openssh.sshd` service `state` is `RUNNING`.

**Rationale:** SSH remote login is a high-value target for brute force and unauthorized remote access.

**Impact:** Remote SSH login is unavailable until re-enabled.

#### Remediation

Open **System Settings > General > Sharing** and turn **Remote Login** off.

From the command line:

```sh
/usr/bin/sudo /usr/sbin/systemsetup -setremotelogin off
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Remote Management Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#remote-management-is-disabled)

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Remote Management (ARD) is enabled.

Checks each launchd service; fails when the Apple Remote Desktop agent is running.

This rule fails when the `com.apple.RemoteDesktop.agent` service `state` is `RUNNING`.

**Rationale:** Apple Remote Desktop grants remote control and management, a major concern on mobile systems.

**Impact:** Remote Management access via ARD is disabled.

Remote Management is detected as the ARDAgent launchd job (com.apple.RemoteDesktop.agent); the CIS audit inspects the ARDAgent process.

#### Remediation

Open **System Settings > General > Sharing** and turn **Remote Management** off.

From the command line:

```sh
/usr/bin/sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -deactivate -stop
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-6 Least Privilege; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; 3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions; 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.6 Use non-privileged accounts or roles when accessing nonsecurity functions; AC.L2-3.1.7 Prevent non-privileged users from executing privileged functions and audit the execution of such functions; AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Screen Sharing Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#screen-sharing-is-disabled)

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.3

**Finding:** Screen Sharing is enabled.

Checks each launchd service; fails when the Screen Sharing service is running.

This rule fails when the `com.apple.screensharing` service `state` is `RUNNING`.

**Rationale:** Screen Sharing opens a remote-control listening service that expands remote attack surface.

**Impact:** Remote screen sharing is unavailable until re-enabled.

#### Remediation

Open **System Settings > General > Sharing** and turn **Screen Sharing** off.

From the command line:

```sh
/usr/bin/sudo /bin/launchctl disable system/com.apple.screensharing
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Time Machine Automatic Backup Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#time-machine-automatic-backup-is-enabled)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.4

**Finding:** Time Machine automatic backup is disabled.

Checks that automatic backup is enabled whenever Time Machine has a configured destination.

This rule fails when a Time Machine destination is configured but `autoBackup` is not `true`.

**Rationale:** Automatic backups ensure recoverable copies exist without relying on manual action.

**Impact:** Time Machine backs up automatically on the usual schedule.

Conditional: passes when Time Machine has no destinations (not in use) OR automatic backup is enabled.

#### Remediation

Open **System Settings > General > Time Machine** and enable **Back Up Automatically**.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.TimeMachine.plist AutoBackup -bool true
```

Framework mappings

- **CIS Controls v8**: 11.2 Perform Automated Backups
- **NIST SP 800-53 Rev. 5**: CP-9 System Backup; CP-10 System Recovery and Reconstitution

Risk

Reliability Impact

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

### [Ensure Time Machine Volumes Are Encrypted](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#time-machine-volumes-are-encrypted)

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.3.4

**Finding:** A Time Machine backup destination is not encrypted.

Checks that every configured Time Machine destination is encrypted.

This rule fails when any Time Machine destination's `lastKnownEncryptionState` is not `ENCRYPTED`.

**Rationale:** Unencrypted backups expose a full copy of system data if the backup media is lost or stolen.

**Impact:** Time Machine backups are stored encrypted.

Conditional: passes when no Time Machine destination exists OR every destination reports ENCRYPTED.

#### Remediation

In **System Settings > General > Time Machine** remove the destination and re-add it with **Encrypt Backups** enabled.

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices; 3.11 Encrypt Sensitive Data at Rest; 11.3 Protect Recovery Data
- **NIST SP 800-53 Rev. 5**: AU-9 Protection of Audit Information; CP-9 System Backup; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.8.9 Protect the confidentiality of backup CUI at storage locations; 3.13.16 Protect the confidentiality of CUI at rest
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; MP.L2-3.8.9 Protect the confidentiality of backup CUI at storage locations; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- **PCI DSS v4.0.1**: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Unprotected Data

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

## 2.5 Apple Intelligence & Siri

### [Ensure Apple Intelligence Writing Tools Are Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#apple-intelligence-writing-tools-are-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.5.1

**Finding:** Apple Intelligence writing tools are allowed.

Apple Intelligence Writing Tools rewrite, proofread and summarize text and may process it through Apple's private cloud rather than only on-device.

This rule fails when `allowWritingTools` is not `false`.

**Rationale:** Sensitive text handled by Writing Tools can leave the device for cloud processing, creating a data-leakage path.

**Impact:** Users lose the AI-assisted rewrite, proofread and summarize actions.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Allow Writing Tools to off.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- **NIST SP 800-53 Rev. 5**: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure External Intelligence Extensions Are Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#external-intelligence-extensions-are-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.5.1

**Finding:** External intelligence integrations are allowed.

External intelligence extensions let Apple Intelligence hand requests to third-party generative AI services such as ChatGPT.

This rule fails when `allowExternalIntelligenceIntegrations` or `allowExternalIntelligenceIntegrationsSignIn` is not `false`.

**Rationale:** Routing prompts or documents to an external AI provider moves organizational data outside managed controls and onto a third party.

**Impact:** Users can no longer reach third-party AI providers through Apple Intelligence.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Allow External Intelligence Extensions and Allow External Intelligence Sign-In to off.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- **NIST SP 800-53 Rev. 5**: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Mail Summarization Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#mail-summarization-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.5.1

**Finding:** Mail summarization is allowed.

Apple Intelligence Mail summarization condenses emails and threads and may process message content off-device.

This rule fails when `allowMailSummary` is not `false`.

**Rationale:** Confidential email content could be sent to Apple for summarization instead of staying under organizational controls.

**Impact:** Users no longer see automatic or on-demand email summaries.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Allow Mail Summary to off.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- **NIST SP 800-53 Rev. 5**: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Notes Summarization Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#notes-summarization-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.5.1

**Finding:** Notes summarization is allowed.

Apple Intelligence Notes summarization transcribes and summarizes written notes and in-app audio recordings, which may be processed off-device.

This rule fails when `allowNotesTranscription` or `allowNotesTranscriptionSummary` is not `false`.

**Rationale:** Transcribed audio and note content can contain highly sensitive material that should not leave the device for AI processing.

**Impact:** Users no longer get automatic or on-demand summaries of notes or recordings.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Allow Notes Transcription and Allow Notes Transcription Summary to off.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software; 15.3 Classify Service Providers
- **NIST SP 800-53 Rev. 5**: AC-20 Use of External Systems; CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management; SR-6 Supplier Assessments and Reviews
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks; 12.8.5 Record division of PCI DSS responsibilities between the entity and TPSPs

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Listen For Siri Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#listen-for-siri-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.5.2

**Finding:** Listen for Siri voice trigger is enabled.

The Hey Siri voice trigger keeps the microphone continuously listening for the wake phrase for this user.

This rule fails when a user's `siriVoiceTriggerEnabled` is not `false`.

**Rationale:** An always-on microphone listening for a wake word risks unintended capture and disclosure of nearby conversations.

**Impact:** The user must invoke Siri manually rather than by voice.

#### Remediation

Open System Settings > Apple Intelligence & Siri and turn off Listen for so the microphone is not always active for the voice trigger.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Siri Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#siri-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.5.2

**Finding:** Siri is allowed.

Siri accepts voice and text queries and can relay device context to Apple; the always-listening trigger cannot be reliably disabled while Siri is enabled.

This rule fails when `allowAssistant` is not `false`.

**Rationale:** A live assistant with cloud processing can disclose confidential activity captured by the microphone in shared work spaces.

**Impact:** Users lose hands-free voice control and Siri lookups.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Allow Assistant to off.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 2.6 Privacy & Security

### [Ensure An Administrator Password Is Required To Access System-Wide Preferences](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#an-administrator-password-is-required-to-access-system-wide-preferences)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6

**Finding:** System-wide preferences do not require an administrator password.

The system.preferences authorization right controls whether changing system-wide settings requires re-authenticating as an administrator.

This rule fails when the `system.preferences` right's `shared` value is not `false` (or is missing).

**Rationale:** Requiring an administrator password prevents standard users from altering configuration that affects the whole system.

**Impact:** Users must authenticate to unlock preference panes such as Network, Startup Disk and Printers & Scanners.

#### Remediation

Open System Settings > Privacy & Security > Advanced and turn on Require an administrator password to access system-wide settings.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Principal

MITRE ATT&CK tactic

Privilege Escalation ([TA0004](https://attack.mitre.org/tactics/TA0004/))

### [Ensure FileVault Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#filevault-is-enabled)

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6

**Finding:** FileVault disable is not restricted.

FileVault encrypts the boot volume so its contents require a password or recovery key to access; the enforcing policy prevents it from being turned off.

This rule fails when `fileVaultDisableRestricted` is not `true`.

**Rationale:** Full-volume encryption minimizes the risk of data exposure if the device or disk is lost or stolen.

**Impact:** Mounting the encrypted volume from another boot source requires a valid password.

#### Remediation

Open System Settings > Privacy & Security, turn FileVault on, and confirm an installed profile sets FileVault Can't Disable so it cannot be turned off.

Framework mappings

- **CIS Controls v8**: 3.6 Encrypt Data on End-User Devices; 3.11 Encrypt Sensitive Data at Rest
- **NIST SP 800-53 Rev. 5**: AU-9 Protection of Audit Information; IA-5 Authenticator Management; SC-28 Protection of Information at Rest
- **NIST SP 800-171 Rev. 2**: 3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; 3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; 3.13.16 Protect the confidentiality of CUI at rest
- **CMMC 2.0 Level 2**: AC.L2-3.1.13 Employ cryptographic mechanisms to protect the confidentiality of remote access sessions; MP.L2-3.8.1 Protect (i.e., physically control and securely store) system media containing CUI, both paper and digital; SC.L2-3.13.16 Protect the confidentiality of CUI at rest
- **PCI DSS v4.0.1**: 3.1.1 Stored account data policies and procedures kept documented, current, and applied; 3.3.2 Encrypt sensitive authentication data stored before authorization completes; 3.3.3 Issuers limit and protect any stored sensitive authentication data; 3.5.1.2 Restrict disk- or partition-level PAN encryption to removable media or paired controls; 3.5.1.3 Manage disk-level encryption access independently of operating system authentication; 8.3.2 Encrypt authentication factors in transit and at rest with strong cryptography

Risk

Unprotected Data

MITRE ATT&CK tactic

Impact ([TA0040](https://attack.mitre.org/tactics/TA0040/))

### [Ensure Gatekeeper Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#gatekeeper-is-enabled)

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6

**Finding:** Gatekeeper is disabled.

Gatekeeper verifies that applications are signed and notarized on every launch before allowing them to run.

This rule fails when `isGatekeeperEnabled` is not `true`.

**Rationale:** Blocking unsigned or unnotarized software reduces the risk of running tampered or malicious applications.

**Impact:** Users cannot launch unsigned applications without an explicit override.

#### Remediation

Open System Settings > Privacy & Security > Security and set Allow apps downloaded from to App Store and identified developers.

From the command line:

```sh
/usr/bin/sudo /usr/sbin/spctl --global-enable
```

Framework mappings

- **CIS Controls v8**: 10.1 Deploy and Maintain Anti-Malware Software; 10.2 Configure Automatic Anti-Malware Signature Updates; 10.5 Enable Anti-Exploitation Features
- **NIST SP 800-53 Rev. 5**: MP-6 Media Sanitization; SI-3 Malicious Code Protection; SI-16 Memory Protection
- **NIST SP 800-171 Rev. 2**: 3.14.2 Provide protection from malicious code at designated locations within organizational systems; 3.14.4 Update malicious code protection mechanisms when new releases are available
- **CMMC 2.0 Level 1**: SI.L1-b.1.xiii Provide protection from malicious code at appropriate locations within organizational information systems; SI.L1-b.1.xiv Update malicious code protection mechanisms when new releases are available
- **CMMC 2.0 Level 2**: SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems; SI.L2-3.14.4 Update malicious code protection mechanisms when new releases are available
- **PCI DSS v4.0.1**: 5.1.1 Malware protection policies and procedures kept documented, current, and applied; 5.2.1 Deploy anti-malware on all systems not evaluated as low risk; 5.2.2 Ensure anti-malware detects and removes or blocks all known malware; 5.3.1 Keep anti-malware current through automatic updates; 5.3.2 Run periodic and real-time anti-malware scans or behavioral analysis

Risk

Insecure Application

MITRE ATT&CK tactic

Execution ([TA0002](https://attack.mitre.org/tactics/TA0002/))

### [Ensure Limit Ad Tracking Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#limit-ad-tracking-is-enabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6

**Finding:** Personalized advertising is allowed.

Personalized advertising lets Apple correlate user data to target advertisements.

This rule fails when `allowApplePersonalizedAdvertising` is not `false`.

**Rationale:** Collected advertising metadata is valuable to attackers and has been used to help re-identify users.

**Impact:** Users see generic rather than targeted advertising.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Allow Apple Personalized Advertising to off.

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Location Icon Is Shown When System Services Request Location](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#location-icon-is-shown-when-system-services-request-location)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6.1

**Finding:** System Services location icon is not shown.

This setting shows a menu bar indicator whenever a system service accesses the device location.

This rule fails when `showLocationSystemServices` is not `true`.

**Rationale:** A visible indicator gives users awareness of when background system services use their location.

**Impact:** Users gain visibility into system-service location access; there is no functional downside.

#### Remediation

Open System Settings > Privacy & Security > Location Services > Details and turn on Show location icon in menu bar when System Services request your location.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.locationmenu.plist ShowSystemServices -bool true
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

### [Ensure Location Services Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#location-services-is-enabled)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6.1

**Finding:** Location Services is disabled.

Location Services lets macOS derive the device's location for time-zone, asset, and log correlation features.

This rule fails when `locationServicesEnabled` is not `true`.

**Rationale:** Consistent location data simplifies asset and time management across devices that change time zones.

**Impact:** If disabled by policy, features that depend on location will no longer work automatically.

#### Remediation

Open System Settings > Privacy & Security > Location Services and turn Location Services on.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults write /var/db/locationd/Library/Preferences/ByHost/com.apple.locationd LocationServicesEnabled -bool true
/usr/bin/sudo /usr/bin/killall locationd
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Discovery ([TA0007](https://attack.mitre.org/tactics/TA0007/))

### [Ensure Improve Siri And Dictation Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#improve-siri-and-dictation-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6.3

**Finding:** Siri and dictation improvement sharing is enabled.

Improve Siri & Dictation lets Apple store and review audio of a user's Siri and dictation interactions.

This rule fails when a user's `siriDataSharingOptIn` is not `OPTED_OUT`.

**Rationale:** Audio recordings sent to Apple may contain PII or restricted organizational information.

**Impact:** There is no user-facing impact from opting out of Siri and dictation sharing.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Siri Data Sharing Opt-In Status to opted out.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Share Mac Analytics Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#share-mac-analytics-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6.3

**Finding:** Mac analytics are shared with Apple.

Share Mac Analytics automatically forwards diagnostic, usage and location data to Apple.

This rule fails when `analyticsSharingEnabled` is not `false`.

**Rationale:** Automatically forwarded analytics may include internal organizational information that should not be processed by a third party.

**Impact:** There is no user-facing impact from disabling analytics sharing.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Auto Submit (Share Mac Analytics) to off.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

### [Ensure Share With App Developers Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#share-with-app-developers-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.6.3

**Finding:** Diagnostic data is shared with app developers.

Share with app developers forwards crash and usage data to third-party developers.

This rule fails when `allowDiagnosticSubmission` is not `false`.

**Rationale:** Diagnostic submissions can carry internal organizational information to parties outside the vendor relationship.

**Impact:** There is no user-facing impact from disabling developer diagnostic sharing.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Allow Diagnostic Submission to off.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 2.7 Desktop & Dock

### [Ensure Screen Saver Hot Corners Do Not Disable The Screen Saver](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#screen-saver-hot-corners-do-not-disable-the-screen-saver)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.7

**Finding:** A hot corner is set to disable the screen saver.

Checks the hot corner assignments for any corner mapped to the Disable Screen Saver action (value 6).

This rule fails when any hot corner (`bottomLeft`, `bottomRight`, `topLeft` or `topRight`) equals `6` (Disable Screen Saver).

**Rationale:** A corner that disables the screen saver lets someone bypass the automatic lock and reach an unlocked session.

**Impact:** There is no user-facing impact from clearing a screen-saver-disabling hot corner.

#### Remediation

Open System Settings > Desktop & Dock > Hot Corners and change any corner set to Disable Screen Saver to a setting allowed by your organization.

From the command line:

```sh
for u in $(/usr/bin/dscl . -list /Users UniqueID | /usr/bin/awk '$2 >= 500 {print $1}'); do for c in bl br tl tr; do /usr/bin/sudo -u "$u" /usr/bin/defaults delete /Users/"$u"/Library/Preferences/com.apple.dock wvous-$c-corner; done; done
```

Framework mappings

- **CIS Controls v8**: 4.3 Configure Automatic Session Locking on Enterprise Assets
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
- **NIST SP 800-171 Rev. 2**: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- **CMMC 2.0 Level 2**: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- **PCI DSS v4.0.1**: 8.2.8 Require re-authentication after 15 minutes of session inactivity

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 2.9 Spotlight

### [Ensure Help Apple Improve Search Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#help-apple-improve-search-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.9

**Finding:** Search data is shared with Apple.

Help Apple Improve Search forwards Spotlight and Search query metadata to Apple.

This rule fails when a user's `searchDataSharingEnabled` is not `false`.

**Rationale:** Search metadata may contain internal organizational information that should not be processed by a third party.

**Impact:** There is no user-facing impact beyond search metadata no longer being shared with Apple.

#### Remediation

Open System Settings > General > Device Management and confirm an installed profile sets Search Queries Data Sharing Status to not sharing.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

## 2.10 Battery (Energy Saver)

### [Ensure Power Nap Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#power-nap-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.10

**Finding:** Power Nap is enabled.

Verifies Power Nap (dark-wake background tasks) is off, so a sleeping Mac does not periodically wake to phone home over previously joined networks.

This rule fails when `darkWakeBackgroundTasks` is `true` on the battery or AC power profile.

**Rationale:** Power Nap wakes the system to reach known networks while unattended, expanding the attack surface.

**Impact:** With Power Nap off, the Mac will not fetch mail or updates while asleep.

Applies primarily to Intel Macs; on Apple Silicon the field is typically absent and passes by default.

#### Remediation

Open **System Settings > Battery** (and **Power Adapter**) and turn **Power Nap** off for every power source.

From the command line:

```sh
/usr/bin/sudo /usr/bin/pmset -a powernap 0
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process; 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems; CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.5 Approve and justify each allowed port, protocol, and service; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Persistence ([TA0003](https://attack.mitre.org/tactics/TA0003/))

### [Ensure Wake for Network Access Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#wake-for-network-access-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.10

**Finding:** Wake for network access is enabled.

Verifies Wake-on-LAN is disabled so an attacker cannot remotely wake an unattended, encrypted Mac.

This rule fails when `wakeOnLAN` is `true` on the battery or AC power profile.

**Rationale:** Remote wake lets an attacker resume a sleeping system and reach its shared resources.

**Impact:** Management tools relying on Wake-on-LAN cannot wake the Mac over the network.

#### Remediation

Open **System Settings > Battery > Options** (or **Energy Saver**) and set **Wake for network access** to Never.

From the command line:

```sh
/usr/bin/sudo /usr/bin/pmset -a womp 0
```

Framework mappings

- **CIS Controls v8**: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: CM-6 Configuration Settings; CM-7 Least Functionality
- **NIST SP 800-171 Rev. 2**: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **CMMC 2.0 Level 2**: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- **PCI DSS v4.0.1**: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks

Risk

External Attack Surface

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Sleep and Display Sleep Are Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#sleep-and-display-sleep-are-enabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.10.1

**Finding:** System or display sleep is disabled or exceeds the allowed interval.

Verifies that Apple Silicon laptops put the system to sleep within 15 minutes and the display within 10 minutes so an unattended Mac returns to a locked, encrypted state.

This rule fails on an Apple Silicon Mac with a battery power profile when `systemSleepTimer` is `0`/over 15 minutes or `displaySleepTimer` is `0`/over 10 minutes.

**Rationale:** Enabling sleep ensures an unattended laptop returns to a locked, encrypted state within a bounded time.

**Impact:** The system takes additional time to resume from sleep.

#### Remediation

Open **System Settings > Battery > Options** (or **Energy Saver**) and set the system to sleep after 15 minutes or less and the display to sleep after 10 minutes or less.

From the command line:

```sh
/usr/bin/sudo /usr/bin/pmset -a sleep 15
/usr/bin/sudo /usr/bin/pmset -a displaysleep 10
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 2.11 Lock Screen

### [Ensure a Custom Login Screen Message Is Configured](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#a-custom-login-screen-message-is-configured)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.11

**Finding:** No custom login screen message is configured.

Verifies a login-window banner is set to inform users the system is for authorized use only.

This rule fails when `loginWindowText` is empty or unset.

**Rationale:** An access warning deters casual attackers and supports prosecution by evidencing notice.

**Impact:** Users see an authorized-use message at the login window.

#### Remediation

Open **System Settings > Lock Screen**, enable **Show message when locked**, select **Set**, and enter your organization's authorized-use banner text.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow LoginwindowText "Authorized use only."
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure a Password Is Required After Screen Saver or Display Sleep](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#a-password-is-required-after-screen-saver-or-display-sleep)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.11

**Finding:** No password is required after the screen saver begins or the display sleeps.

Verifies each user must enter a password to wake from the screen saver or display sleep.

This rule fails when `askForPassword` is not `true` for a user.

**Rationale:** Prompting for a password on wake stops someone from using an unlocked, unattended session.

**Impact:** Users must re-authenticate when returning to the Mac.

Per-user rule anchored on USER_SYSTEM_SETTINGS. The '5 seconds or immediately' delay (askForPasswordDelay) is not exposed in the schema, so only the password requirement itself is enforced.

#### Remediation

Open **System Settings > Lock Screen** and set **Require password after screen saver begins or display is turned off** to immediately or after 5 seconds.

From the command line:

```sh
/usr/bin/defaults -currentHost write com.apple.screensaver askForPassword -int 1
```

Framework mappings

- **CIS Controls v8**: 4.7 Manage Default Accounts on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure Password Hints Are Not Shown at the Login Window](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#password-hints-are-not-shown-at-the-login-window)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.11

**Finding:** Password hints can be shown at the login window.

Verifies the login window never displays password hints after failed attempts.

This rule fails when `retriesUntilHint` is not `0`.

**Rationale:** Password hints can reveal the password or clues usable in social-engineering attacks.

**Impact:** Users no longer see a hint after mistyping their password.

#### Remediation

Open **System Settings > Lock Screen** and turn **Show password hints** off.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow RetriesUntilHint -int 0
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

### [Ensure Screen Saver Inactivity Interval Is 15 Minutes or Less](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#screen-saver-inactivity-interval-is-15-minutes-or-less)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.11

**Finding:** Screen saver inactivity interval exceeds 15 minutes.

Verifies each user's screen saver starts after no more than 15 minutes of inactivity so an unattended session locks.

This rule fails when `idleTime` is `0` (never) or greater than 15 minutes for a user.

**Rationale:** A locking screen saver limits access to an unattended session.

**Impact:** Users returning to an idle Mac must re-authenticate.

Per-user rule anchored on USER_SYSTEM_SETTINGS; idleTime is a Duration compared in nanoseconds (15 min = 900000000000).

#### Remediation

Open **System Settings > Lock Screen** and set **Start Screen Saver when inactive** to 15 minutes or less.

Framework mappings

- **CIS Controls v8**: 4.3 Configure Automatic Session Locking on Enterprise Assets
- **NIST SP 800-53 Rev. 5**: AC-2 Account Management; AC-11 Device Lock; AC-12 Session Termination
- **NIST SP 800-171 Rev. 2**: 3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- **CMMC 2.0 Level 2**: AC.L2-3.1.10 Use session lock with pattern-hiding displays to prevent access and viewing of data after period of inactivity
- **PCI DSS v4.0.1**: 8.2.8 Require re-authentication after 15 minutes of session inactivity

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure the Login Window Displays Name and Password](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#the-login-window-displays-name-and-password)

Low severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.11

**Finding:** The login window shows a user list instead of name and password fields.

Verifies the login window requires typing both a username and password rather than picking a user from a list.

This rule fails when `loginWindowShowFullName` is not `true`.

**Rationale:** Requiring both a username and password doubles the unknowns an attacker must supply.

**Impact:** Users type their account name at login instead of clicking an icon.

#### Remediation

Open **System Settings > Lock Screen** and set **Login window shows** to **Name and Password**.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow SHOWFULLNAME -bool true
```

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 2.12 Touch ID & Password (Login Password)

### [Ensure User Accounts Do Not Have a Password Hint](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#user-accounts-do-not-have-a-password-hint)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.12

**Finding:** A user account has a password hint set.

Verifies each user account has no password hint recorded.

This rule fails when `hasPasswordHint` is `true` for a user.

**Rationale:** Password hints are easily guessed or socially engineered and may reveal the password itself.

**Impact:** Users lose the hint shown after failed password attempts.

Per-user rule anchored on USER_SYSTEM_SETTINGS; evaluates each user account independently.

#### Remediation

Open **System Settings > Touch ID & Password** (or **Login Password**), select **Change**, and clear the **Password hint** field.

From the command line:

```sh
/usr/bin/sudo /usr/bin/dscl . -delete /Users/<username> hint
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **NIST SP 800-171 Rev. 2**: 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts

Risk

Unprotected Principal

MITRE ATT&CK tactic

Credential Access ([TA0006](https://attack.mitre.org/tactics/TA0006/))

## 2.13 Users & Groups

### [Ensure Automatic Login Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#automatic-login-is-disabled)

High severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.13

**Finding:** Automatic login is enabled.

Verifies the system does not bypass the login window by automatically logging a user in at boot.

This rule fails when `automaticLoginEnabled` is `true`.

**Rationale:** Automatic login lets anyone with physical access reach a user's session without credentials.

**Impact:** Users must authenticate at every boot.

#### Remediation

Open **System Settings > Users & Groups** and set **Automatically log in as** to **Off**.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults delete /Library/Preferences/com.apple.loginwindow autoLoginUser
```

Framework mappings

- **CIS Controls v8**: 4.7 Manage Default Accounts on Enterprise Assets and Software
- **NIST SP 800-53 Rev. 5**: IA-5 Authenticator Management
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 2.3.1 Replace or confirm default wireless settings when installing access points

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

### [Ensure the Guest Account Is Disabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#the-guest-account-is-disabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.13

**Finding:** The guest account is enabled.

Verifies the guest account cannot log in, either by system state or by MDM policy.

This rule fails when `guestEnabled` is `true` and `enableGuestAccount` is not `false`.

**Rationale:** A guest login lets an untrusted user perform reconnaissance and attempt privilege escalation.

**Impact:** Guests can no longer log in to the Mac.

#### Remediation

Open **System Settings > Users & Groups**, select the info button next to **Guest User**, and turn **Allow guests to log in to this computer** off.

From the command line:

```sh
/usr/bin/sudo /usr/bin/defaults write /Library/Preferences/com.apple.loginwindow GuestEnabled -bool false
```

Framework mappings

- **CIS Controls v8**: 5.2 Use Unique Passwords; 6.2 Establish an Access Revoking Process; 6.8 Define and Maintain Role-Based Access Control
- **NIST SP 800-53 Rev. 5**: AC-1 Policy and Procedures; AC-2 Account Management; AC-5 Separation of Duties; AC-6 Least Privilege; AU-9 Protection of Audit Information; CA-3 Information Exchange; IA-5 Authenticator Management; PS-4 Personnel Termination
- **NIST SP 800-171 Rev. 2**: 3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; 3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts; 3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **CMMC 2.0 Level 2**: AC.L2-3.1.4 Separate the duties of individuals to reduce the risk of malevolent activity without collusion; AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts; IA.L2-3.5.7 Enforce a minimum password complexity and change of characters when new passwords are created
- **PCI DSS v4.0.1**: 2.2.2 Reset passwords on, or disable, factory-supplied vendor accounts; 7.1.1 Access restriction policies and procedures kept documented, current, and applied; 7.2.1 Define a role- and privilege-based model for granting access; 7.2.2 Grant user privileges by job function and least privilege; 7.2.4 Recertify user and vendor account access at least semiannually; 7.2.6 Restrict queries against cardholder data stores to role-based programmatic access; 7.3.1 Access control systems cover every component and enforce need-to-know; 7.3.2 Configure access controls to enforce role-based permissions for people and systems; 8.2.4 Authorize and track additions, removals, and changes to user identities and credentials; 8.2.5 Remove access for departing users without delay; 8.3.5 Use unique initial passwords and force change on first use; 8.3.6 Enforce 12-character minimum password length with letters and numbers; 8.6.3 Rotate and harden passwords for application and system-level accounts; 10.3.1 Restrict viewing of audit log files to staff who need it

Risk

Unprotected Principal

MITRE ATT&CK tactic

Initial Access ([TA0001](https://attack.mitre.org/tactics/TA0001/))

## 2.18 Keyboard

### [Ensure On-Device Dictation Is Enabled](https://wartiva.com/policy-rules/apple-macos-26-tahoe/system-settings.html#on-device-dictation-is-enabled)

Medium severity · Wartiva check · CIS Apple macOS 26 Tahoe Benchmark 2.18

**Finding:** Dictation is allowed to send audio to Apple servers.

Verifies dictation is forced to run on-device so dictated content is not sent to Apple's servers.

This rule fails when `forceOnDeviceOnlyDictation` is not `true`.

**Rationale:** Server-side dictation can spill confidential dictated content off the device.

**Impact:** On-device dictation cannot use server-side learning to improve recognition.

#### Remediation

Deploy a configuration profile (payload `com.apple.applicationaccess`) that sets **forceOnDeviceOnlyDictation** to true.

Framework mappings

- **CIS Controls v8**: 4.1 Establish and Maintain a Secure Configuration Process
- **NIST SP 800-53 Rev. 5**: CM-1 Policy and Procedures; CM-2 Baseline Configuration; CM-6 Configuration Settings; CM-7 Least Functionality; CM-9 Configuration Management Plan; SA-3 System Development Life Cycle; SA-8 Security and Privacy Engineering Principles; SA-10 Developer Configuration Management
- **NIST SP 800-171 Rev. 2**: 3.1.18 Control connection of mobile devices; 3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; 3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **CMMC 2.0 Level 2**: AC.L2-3.1.18 Control connection of mobile devices; CM.L2-3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles; CM.L2-3.4.2 Establish and enforce security configuration settings for information technology products employed in organizational systems
- **PCI DSS v4.0.1**: 1.1.1 Network security control policies and procedures kept documented, current, and applied; 1.2.1 Establish and uphold configuration baselines for NSC rulesets; 1.2.6 Add security features that offset risk from active insecure services; 1.2.7 Review NSC configurations for relevance and effectiveness every six months; 1.5.1 Harden dual-connected computing devices that reach both the internet and CDE; 2.1.1 Secure configuration policies and procedures kept documented, current, and applied; 2.2.1 Develop and maintain hardening standards covering all system components

Risk

Unprotected Data

MITRE ATT&CK tactic

Command and Control / Exfiltration ([TA0011](https://attack.mitre.org/tactics/TA0011/), [TA0010](https://attack.mitre.org/tactics/TA0010/))

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
