STIGQter STIGQter: STIG Summary: Apple macOS 15 (Sequoia) Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Apr 2026:

The macOS system must enable firmware password.

DISA Rule

SV-268540r1034560_rule

Vulnerability Number

V-268540

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

APPL-15-003013

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the macOS system with a firmware password with the following command:

/usr/sbin/firmwarepasswd -setpasswd

NOTE: If firmware password or passcode is forgotten, the only way to reset the forgotten password is through a machine-specific binary generated and provided by Apple. Users must schedule a support call and provide proof of purchase before the firmware binary will be generated.

Check Contents

For Apple Silicon systems, this is not applicable.

Verify the macOS system is configured with a firmware password with the following command:

/usr/sbin/firmwarepasswd -check | /usr/bin/grep -c "Password Enabled: Yes"

If the result is not "1", this is a finding.

Vulnerability Number

V-268540

Documentable

False

Rule Version

APPL-15-003013

Severity Override Guidance

For Apple Silicon systems, this is not applicable.

Verify the macOS system is configured with a firmware password with the following command:

/usr/sbin/firmwarepasswd -check | /usr/bin/grep -c "Password Enabled: Yes"

If the result is not "1", this is a finding.

Check Content Reference

M

Target Key

5661