Configure Security Auditing Flags – ‘audit successful/failed login/logout events’ Details Maintaining an audit trail of system activity logs can help identify configuration errors, troubleshoot service disruptions, and analyze compromises...
Create a Login window banner Details An access warning may reduce a casual attacker’s tendency to target the system. Access warnings may also aid in...
Create network specific locations Details Network locations allow the computer to have specific configurations ready for network access when required. Locations can be used...
Create specialized keychains for different purposes Details If the user can logically split password and other entries into different keychains with different passwords, a compromise of...
Disable Bonjour advertising service Details Bonjour can simplify device discovery from an internal rogue or compromised host. An attacker could use Bonjour’s multicast DNS...
Disable Fast User Switching Details Fast user switching allows multiple users to run applications simultaneously at console. There can be information disclosed about processes...
Disable sleeping the computer when connected to power Details The ability to apply security patches and perform vulnerability assessments on the system is reduced when the system is...
Disable ‘Wake for network access’ Details Disabling this feature mitigates the risk of an attacker remotely waking the system and gaining access. Solution Perform the...
Enable Location Services Details Location services are helpful in most use cases and can simplify log and time management where computers change time...
Enable OCSP and CRL certificate checking – CRLStyle Details A rogue or compromised certificate should not be trsuted Solution Run the following commands to enforce the compliant state...