STIGQter STIGQter: STIG Summary: Apple macOS 15 (Sequoia) Security Technical Implementation Guide Version: 1 Release: 7 Benchmark Date: 01 Apr 2026:

The macOS system must ensure Secure Boot level is set to "full".

DISA Rule

SV-268568r1034644_rule

Vulnerability Number

V-268568

Group Title

SRG-OS-000445-GPOS-00199

Rule Version

APPL-15-005100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the macOS system to ensure Secure Boot level is set to "full" by booting into Recovery Mode and enabling Full Secure Boot.

Check Contents

Verify the macOS system is configured to ensure Secure Boot level is set to "full" using the following command:

/usr/libexec/mdmclient QuerySecurityInfo | /usr/bin/grep -c "SecureBootLevel = full"

If the result is not "1", this is a finding.

Vulnerability Number

V-268568

Documentable

False

Rule Version

APPL-15-005100

Severity Override Guidance

Verify the macOS system is configured to ensure Secure Boot level is set to "full" using the following command:

/usr/libexec/mdmclient QuerySecurityInfo | /usr/bin/grep -c "SecureBootLevel = full"

If the result is not "1", this is a finding.

Check Content Reference

M

Target Key

5661