Monterey – Configure Audit Log Folders to Mode 700 or Less Permissive Details The audit log folder _MUST_ be configured to mode 700 or less permissive so that only the root user...
Monterey – Configure Audit Log Folder to Not Contain Access Control Lists Details The audit log folder _MUST_ not contain access control lists (ACLs). Audit logs contain sensitive data about the system...
Monterey – Configure Audit Retention to a Minimum of Seven Days Details The audit service _MUST_ be configured to require records be kept for seven days or longer before deletion, unless...
Monterey – Configure Gatekeeper to Disallow End User Override Details Gatekeeper _MUST_ be configured with a configuration profile to prevent normal users from overriding its settings. If users are...
Monterey – Configure Login Window to Prompt for Username and Password Details The login window _MUST_ be configured to prompt all users for both a username and a password. By default,...
Monterey – Configure macOS to Use an Authorized Time Server Details Approved time servers _MUST_ be the only servers configured for use. This rule ensures the uniformity of time stamps...
Monterey – Configure Sudoers to Authenticate Users on a Per -tty Basis Details The file /etc/sudoers _MUST_ be configured to include tty_tickets. This rule ensures that the “sudo” command will prompt for...
Monterey – Configure System to Audit All Administrative Action Events Details The auditing system _MUST_ be configured to flag administrative action (ad) events. Administrative action events include changes made to...
Monterey – Configure System to Audit All Authorization and Authentication Events Details The auditing system _MUST_ be configured to flag authorization and authentication (aa) events. Authentication events contain information about the...
Monterey – Configure System to Audit All Deletions of Object Attributes Details The audit system _MUST_ be configured to record enforcement actions of attempts to delete file attributes (fd). ***Enforcement actions...