STIGQter STIGQter: STIG Summary: Apple macOS 15 (Sequoia) Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Apr 2026:

The macOS system must be configured to use an authorized time server.

DISA Rule

SV-268449r1038944_rule

Vulnerability Number

V-268449

Group Title

SRG-OS-000355-GPOS-00143

Rule Version

APPL-15-000170

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the macOS system to use an authorized time server by installing the "com.apple.MCX" configuration profile.

Check Contents

Verify the macOS system is configured to use an authorized time server with the following command:

/usr/bin/osascript -l JavaScript << EOS
$.NSUserDefaults.alloc.initWithSuiteName('com.apple.MCX')\
.objectForKey('timeServer').js
EOS

If the result is not an authoritative time server that is synchronized with redundant USNO time servers as designated for the appropriate DOD network, this is a finding.

Vulnerability Number

V-268449

Documentable

False

Rule Version

APPL-15-000170

Severity Override Guidance

Verify the macOS system is configured to use an authorized time server with the following command:

/usr/bin/osascript -l JavaScript << EOS
$.NSUserDefaults.alloc.initWithSuiteName('com.apple.MCX')\
.objectForKey('timeServer').js
EOS

If the result is not an authoritative time server that is synchronized with redundant USNO time servers as designated for the appropriate DOD network, this is a finding.

Check Content Reference

M

Target Key

5661