Catalina – Configure the System to Protect Memory from Unauthorized Code Execution Details The information system _IS_ configured to implement non-executable data to protect memory from code execution. Some adversaries launch attacks...
Catalina – Configure the System to Separate User and System Functionality – isolate Details The information system _IS_ configured to isolate security functions from non-security functions. link:https://support.apple.com/guide/security/welcome/web[] Solution The technology inherently meets this...
Catalina – Configure the System to Separate User and System Functionality – separate Details The information system _IS_ configured to separate user and system functionality. Operating system management functionality includes functions necessary for...
Catalina – Configure the System to Uniquely Identify and Authenticate Non-Organizational Users Details The information system uniquely identifies and authenticates non-organizational users (or processes acting on behalf of non-organizational users). NOTE: Nessus...
Catalina – Configure User Session Lock When a Smart Token is Removed Details The screen lock _MUST_ be configured to initiate automatically when the smart token is removed from the system. Session...
Catalina – Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall Policy Details A deny-all and allow-by-exception firewall policy _MUST_ be employed for managing connections to other systems. Organizations _MUST_ ensure the...
Catalina – Disable Ad Tracking Details Ad tracking and targeted ads _MUST_ be disabled. The information system _MUST_ be configured to provide only essential capabilities....
Catalina – Disable AirDrop Details AirDrop _MUST_ be disabled to prevent file transfers to or from unauthorized devices. AirDrop allows users to share and...
Catalina – Disable Accounts after 35 Days of Inactivity Details The macOS _MUST_ be configured to disable accounts after 35 days of inactivity. This rule prevents malicious users from...
Catalina – Disable Apple Filing Protocol Sharing Details If the system does not require Apple Filing Protocol (AFP) Sharing, support it is non-essential and _MUST_ be disabled....