| Checked | Name | Title |
|---|---|---|
| ☐ | SV-268420r1034200_rule | The macOS system must prevent Apple Watch from terminating a session lock. |
| ☐ | SV-268421r1034203_rule | The macOS system must enforce screen saver password. |
| ☐ | SV-268422r1131177_rule | The macOS system must enforce session lock no more than five seconds after screen saver is started. |
| ☐ | SV-268423r1034209_rule | The macOS system must configure user session lock when a smart token is removed. |
| ☐ | SV-268424r1034212_rule | The macOS system must disable hot corners. |
| ☐ | SV-268425r1034215_rule | The macOS system must prevent AdminHostInfo from being available at LoginWindow. |
| ☐ | SV-268426r1034218_rule | The macOS system must automatically remove or disable temporary or emergency user accounts within 72 hours. |
| ☐ | SV-268427r1131179_rule | The macOS system must enforce time synchronization. |
| ☐ | SV-268428r1131182_rule | The macOS system must limit consecutive failed login attempts to three. |
| ☐ | SV-268429r1034227_rule | The macOS system must display a policy banner at remote login. |
| ☐ | SV-268431r1131186_rule | The macOS system must display the Standard Mandatory DOD Notice and Consent Banner at the login window. |
| ☐ | SV-268432r1034236_rule | The macOS system must configure audit log files to not contain access control lists (ACLs). |
| ☐ | SV-268433r1034239_rule | The macOS system must configure the audit log folder to not contain access control lists (ACLs). |
| ☐ | SV-268434r1137691_rule | The macOS system must disable FileVault automatic login. |
| ☐ | SV-268435r1131188_rule | The macOS system must configure SSHD ClientAliveInterval to 900. |
| ☐ | SV-268436r1034780_rule | The macOS system must configure SSHD ClientAliveCountMax to 1. |
| ☐ | SV-268437r1034251_rule | The macOS system must set login grace time to 30. |
| ☐ | SV-268438r1184563_rule | The macOS system must limit SSHD to FIPS-compliant connections. |
| ☐ | SV-268439r1131194_rule | The macOS system must limit SSH to FIPS-compliant connections. |
| ☐ | SV-268440r1131197_rule | The macOS system must set account lockout time to 15 minutes. |
| ☐ | SV-268441r1131199_rule | The macOS system must enforce screen saver timeout. |
| ☐ | SV-268442r1131200_rule | The macOS system must disable login to other users' active and locked sessions. |
| ☐ | SV-268443r1034269_rule | The macOS system must disable root login. |
| ☐ | SV-268444r1131203_rule | The macOS system must configure the SSH ServerAliveInterval to 900. |
| ☐ | SV-268445r1034275_rule | The macOS system must configure SSHD channel timeout to 900. |
| ☐ | SV-268446r1034278_rule | The macOS system must configure SSHD unused connection timeout to 900. |
| ☐ | SV-268447r1131206_rule | The macOS system must set SSH Active Server Alive Maximum to 0. |
| ☐ | SV-268448r1034284_rule | The macOS system must enforce auto logout after 86400 seconds of inactivity. |
| ☐ | SV-268449r1038944_rule | The macOS system must be configured to use an authorized time server. |
| ☐ | SV-268450r1038944_rule | The macOS system must enable the time synchronization daemon. |
| ☐ | SV-268451r1131208_rule | The macOS system must configure sudo to log events. |
| ☐ | SV-268452r1131210_rule | The macOS system must be configured to audit all administrative action events. |
| ☐ | SV-268453r1034299_rule | The macOS system must be configured to audit all login and logout events. |
| ☐ | SV-268454r1034302_rule | The macOS system must enable security auditing. |
| ☐ | SV-268455r1038966_rule | The macOS system must be configured to shut down upon audit failure. |
| ☐ | SV-268456r1034308_rule | The macOS system must configure audit log files to be owned by root. |
| ☐ | SV-268457r1034311_rule | The macOS system must configure audit log folders to be owned by root. |
| ☐ | SV-268458r1034314_rule | The macOS system must configure the audit log files group to wheel. |
| ☐ | SV-268459r1034317_rule | The macOS system must configure the audit log folders group to wheel. |
| ☐ | SV-268460r1034320_rule | The macOS system must configure audit log files to mode 440 or less permissive. |
| ☐ | SV-268461r1034323_rule | The macOS system must configure audit log folders to mode 700 or less permissive. |
| ☐ | SV-268462r1034326_rule | The macOS system must be configured to audit all deletions of object attributes. |
| ☐ | SV-268463r1034329_rule | The macOS system must be configured to audit all changes of object attributes. |
| ☐ | SV-268464r1034332_rule | The macOS system must be configured to audit all failed read actions on the system. |
| ☐ | SV-268465r1034335_rule | The macOS system must be configured to audit all failed write actions on the system. |
| ☐ | SV-268467r1034341_rule | The macOS system must configure audit retention to seven days. |
| ☐ | SV-268468r1034344_rule | The macOS system must configure audit capacity warning. |
| ☐ | SV-268469r1038966_rule | The macOS system must configure audit failure notification. |
| ☐ | SV-268470r1034350_rule | The macOS system must be configured to audit all authorization and authentication events. |
| ☐ | SV-268471r1034353_rule | The macOS system must set smart card certificate trust to moderate. |
| ☐ | SV-268472r1034356_rule | The macOS system must disable root login for SSH. |
| ☐ | SV-268473r1034359_rule | The macOS system must configure audit_control group to wheel. |
| ☐ | SV-268474r1034362_rule | The macOS system must configure audit_control owner to root. |
| ☐ | SV-268475r1034365_rule | The macOS system must configure audit_control owner to mode 440 or less permissive. |
| ☐ | SV-268477r1034371_rule | The macOS system must disable password authentication for SSH. |
| ☐ | SV-268478r1137691_rule | The macOS system must disable Server Message Block (SMB) sharing. |
| ☐ | SV-268479r1137691_rule | The macOS system must disable Network File System (NFS) service. |
| ☐ | SV-268480r1034380_rule | The macOS system must disable Location Services. |
| ☐ | SV-268481r1034383_rule | The macOS system must disable Bonjour multicast. |
| ☐ | SV-268482r1137691_rule | The macOS system must disable Unix-to-Unix Copy Protocol (UUCP) service. |
| ☐ | SV-268483r1034389_rule | The macOS system must disable Internet Sharing. |
| ☐ | SV-268484r1137691_rule | The macOS system must disable the built-in web server. |
| ☐ | SV-268485r1137691_rule | The macOS system must disable AirDrop. |
| ☐ | SV-268486r1034398_rule | The macOS system must disable FaceTime.app. |
| ☐ | SV-268487r1034401_rule | The macOS system must disable the iCloud Calendar services. |
| ☐ | SV-268488r1034404_rule | The macOS system must disable iCloud Reminders. |
| ☐ | SV-268489r1034407_rule | The macOS system must disable iCloud Address Book. |
| ☐ | SV-268490r1034410_rule | The macOS system must disable iCloud Mail. |
| ☐ | SV-268491r1034413_rule | The macOS system must disable iCloud Notes. |
| ☐ | SV-268492r1034416_rule | The macOS system must disable the camera. |
| ☐ | SV-268493r1034419_rule | The macOS system must disable Siri. |
| ☐ | SV-268494r1131212_rule | The macOS system must disable sending diagnostic and usage data to Apple. |
| ☐ | SV-268495r1137691_rule | The macOS system must disable Remote Apple Events. |
| ☐ | SV-268496r1034428_rule | The macOS system must disable Apple ID setup during Setup Assistant. |
| ☐ | SV-268497r1034431_rule | The macOS system must disable Privacy Setup services during Setup Assistant. |
| ☐ | SV-268498r1034434_rule | The macOS system must disable iCloud storage setup during Setup Assistant. |
| ☐ | SV-268499r1034437_rule | The macOS system must disable Trivial File Transfer Protocol (TFTP) service. |
| ☐ | SV-268500r1034440_rule | The macOS system must disable Siri Setup during Setup Assistant. |
| ☐ | SV-268501r1034443_rule | The macOS system must disable iCloud Keychain Sync. |
| ☐ | SV-268502r1034446_rule | The macOS system must disable iCloud Document Sync. |
| ☐ | SV-268503r1034449_rule | The macOS system must disable iCloud Bookmarks. |
| ☐ | SV-268504r1034452_rule | The macOS system must disable iCloud Photo Library. |
| ☐ | SV-268505r1137691_rule | The macOS system must disable Screen Sharing and Apple Remote Desktop. |
| ☐ | SV-268506r1034458_rule | The macOS system must disable the System Settings pane for Wallet and Apple Pay. |
| ☐ | SV-268507r1034461_rule | The macOS system must disable the system settings pane for Siri. |
| ☐ | SV-268508r1131219_rule | The macOS system must apply gatekeeper settings to block applications from unidentified developers. |
| ☐ | SV-268509r1034467_rule | The macOS system must disable Bluetooth when no approved device is connected. |
| ☐ | SV-268510r1131221_rule | The macOS system must disable the guest account. |
| ☐ | SV-268511r1131224_rule | The macOS system must enable gatekeeper. |
| ☐ | SV-268512r1034476_rule | The macOS system must disable unattended or automatic login to the system. |
| ☐ | SV-268513r1131226_rule | The macOS system must secure users' home folders. |
| ☐ | SV-268514r1131229_rule | The macOS system must require an administrator password to modify systemwide preferences. |
| ☐ | SV-268515r1034485_rule | The macOS system must disable Airplay Receiver. |
| ☐ | SV-268516r1034488_rule | The macOS system must disable TouchID for unlocking the device. |
| ☐ | SV-268517r1137691_rule | The macOS system must disable Media Sharing. |
| ☐ | SV-268518r1137691_rule | The macOS system must disable Bluetooth Sharing. |
| ☐ | SV-268519r1034497_rule | The macOS system must disable AppleID and internet Account Modification. |
| ☐ | SV-268521r1034503_rule | The macOS system must disable Content Caching service. |
| ☐ | SV-268522r1034506_rule | The macOS system must disable iCloud Desktop and Document folder sync. |
| ☐ | SV-268523r1034509_rule | The macOS system must disable iCloud Game Center. |
| ☐ | SV-268524r1034512_rule | The macOS system must disable iCloud Private Relay. |
| ☐ | SV-268525r1131237_rule | The macOS system must disable Find My service. |
| ☐ | SV-268526r1034518_rule | The macOS system must disable Personalized Advertising. |
| ☐ | SV-268527r1034521_rule | The macOS system must disable sending Siri and Dictation information to Apple. |
| ☐ | SV-268528r1034524_rule | The macOS system must enforce On Device Dictation. |
| ☐ | SV-268529r1034527_rule | The macOS system must disable Dictation. |
| ☐ | SV-268530r1034530_rule | The macOS system must disable Printer Sharing. |
| ☐ | SV-268531r1034533_rule | The macOS system must disable Remote Management. |
| ☐ | SV-268532r1034536_rule | The macOS system must disable the Bluetooth System Settings pane. |
| ☐ | SV-268533r1034539_rule | The macOS system must disable the iCloud Freeform services. |
| ☐ | SV-268534r1034542_rule | The macOS system must issue or obtain public key certificates from an approved service provider. |
| ☐ | SV-268535r1034545_rule | The macOS system must require that passwords contain a minimum of one numeric character. |
| ☐ | SV-268536r1038967_rule | The macOS system must restrict maximum password lifetime to 60 days. |
| ☐ | SV-268537r1034551_rule | The macOS system must require a minimum password length of 14 characters. |
| ☐ | SV-268538r1131239_rule | The macOS system must require that passwords contain a minimum of one special character. |
| ☐ | SV-268539r1034557_rule | The macOS system must disable password hints. |
| ☐ | SV-268540r1034560_rule | The macOS system must enable firmware password. |
| ☐ | SV-268541r1131242_rule | The macOS system must remove password hints from user accounts. |
| ☐ | SV-268542r1034566_rule | The macOS system must enforce smart card authentication. |
| ☐ | SV-268543r1034569_rule | The macOS system must allow smart card authentication. |
| ☐ | SV-268544r1034572_rule | The macOS system must enforce multifactor authentication for login. |
| ☐ | SV-268545r1034575_rule | The macOS system must enforce multifactor authentication for the su command. |
| ☐ | SV-268546r1034578_rule | The macOS system must enforce multifactor authentication for privilege escalation through the sudo command. |
| ☐ | SV-268547r1034581_rule | The macOS system must require that passwords contain a minimum of one lowercase character and one uppercase character. |
| ☐ | SV-268548r1131244_rule | The macOS system must set minimum password lifetime to 24 hours. |
| ☐ | SV-268549r1131246_rule | The macOS system must disable accounts after 35 days of inactivity. |
| ☐ | SV-268550r1034590_rule | The macOS system must configure Apple System Log (ASL) files owned by root and group to wheel. |
| ☐ | SV-268551r1034593_rule | The macOS system must configure Apple System Log (ASL) files to mode 640 or less permissive. |
| ☐ | SV-268552r1034596_rule | The macOS system must configure system log files owned by root and group to wheel. |
| ☐ | SV-268553r1034599_rule | The macOS system must configure system log files to mode 640 or less permissive. |
| ☐ | SV-268554r1034602_rule | The macOS system must configure install.log retention to 365. |
| ☐ | SV-268555r1034605_rule | The macOS system must ensure System Integrity Protection is enabled. |
| ☐ | SV-268556r1131248_rule | The macOS system must enforce FileVault. |
| ☐ | SV-268557r1034611_rule | The macOS system must enable macOS Application Firewall. |
| ☐ | SV-268558r1034614_rule | The macOS system must configure the login window to prompt for username and password. |
| ☐ | SV-268559r1034617_rule | The macOS system must disable the TouchID prompt during Setup Assistant. |
| ☐ | SV-268560r1034620_rule | The macOS system must disable the Screen Time prompt during Setup Assistant. |
| ☐ | SV-268561r1034623_rule | The macOS system must disable Unlock with Apple Watch during Setup Assistant. |
| ☐ | SV-268562r1137691_rule | The macOS system must disable Handoff. |
| ☐ | SV-268563r1034629_rule | The macOS system must disable proximity-based password sharing requests. |
| ☐ | SV-268564r1034632_rule | The macOS system must disable Erase Content and Settings. |
| ☐ | SV-268565r1137691_rule | The macOS system must enable Authenticated Root. |
| ☐ | SV-268566r1131250_rule | The macOS system must prohibit user installation of software into /users/. |
| ☐ | SV-268567r1131252_rule | The macOS system must authorize USB devices before allowing connection. |
| ☐ | SV-268568r1034644_rule | The macOS system must ensure Secure Boot level is set to "full". |
| ☐ | SV-268569r1034647_rule | The macOS system must enforce enrollment in Mobile Device Management (MDM). |
| ☐ | SV-268570r1034650_rule | The macOS system must enable Recovery Lock. |
| ☐ | SV-268571r1034653_rule | The macOS system must enforce installation of XProtect Remediator and Gatekeeper updates automatically. |
| ☐ | SV-268572r1034656_rule | The macOS system must disable Genmoji. |
| ☐ | SV-268573r1034659_rule | The macOS system must disable Apple Intelligence Image Generation. |
| ☐ | SV-268574r1034662_rule | The macOS system must disable Apple Intelligence Writing Tools. |
| ☐ | SV-268575r1149426_rule | The macOS system must install security-relevant software updates within 30 days unless the time period is directed by an authoritative source (e.g., IAVM, CTOs, DTMs, STIGs). |
| ☐ | SV-269093r1131184_rule | The macOS system must enforce SSH to display a policy banner. |
| ☐ | SV-269094r1034757_rule | The macOS system must be configured to audit all failed program execution on the system. |
| ☐ | SV-269095r1034760_rule | The macOS system must configure audit_control to not contain access control lists (ACLs). |
| ☐ | SV-269096r1131214_rule | The macOS system must disable sending audio recordings and transcripts to Apple. |
| ☐ | SV-269566r1131216_rule | The macOS system must disable sending search data from Spotlight to Apple. |
| ☐ | SV-272477r1137691_rule | The macOS system must disable iPhone Mirroring. |
| ☐ | SV-274880r1099901_rule | The macOS system must configure sudoers timestamp type. |
| ☐ | SV-274881r1099904_rule | The macOS system must require users to reauthenticate for privilege escalation when using the "sudo" command. |