Catalina – Configure Audit Retention to a Minimum of Seven Days Details The audit service _MUST_ be configured to require records be kept for seven days or longer before deletion, unless...
Catalina – Configure Automated Flaw Remediation Details The macOS system _MUST_ be configured to determine the state of system components with regard to flaw remediation. NOTE:...
Catalina – Configure Gatekeeper to Disallow End User Override Details Gatekeeper _MUST_ be configured with a configuration profile to prevent normal users from overriding its settings. If users are...
Catalina – Configure Login Window to Prompt for Username and Password Details The login window _MUST_ be configured to prompt all users for both a username and a password. By default,...
Catalina – Configure SSH ServerAliveInterval option set to 900 or less Details SSH _MUST_ be configured with an Active Server Alive Maximum Count set to 900 or less. Setting the Active...
Catalina – Configure Sudoers to Authenticate Users on a Per -tty Basis Details The file /etc/sudoers _MUST_ be configured to include tty_tickets. This rule ensures that the “sudo” command will prompt for...
Catalina – Configure System Log Files Owned by Root and Group to Wheel Details The system log files _MUST_ be owned by root. System logs contain sensitive data about the system and users....
Catalina – Configure System Log Files to Mode 640 or Less Permissive Details The system logs _MUST_ be configured to be writable by root and readable only by the root user and...
Catalina – Configure System to Audit All Administrative Action Events Details The auditing system _MUST_ be configured to flag administrative action (ad) events. Administrative action events include changes made to...
Catalina – Configure System to Audit All Authorization and Authentication Events Details The auditing system _MUST_ be configured to flag authorization and authentication (aa) events. Authentication events contain information about the...