Monterey – Configure macOS to Use an Authorized Time Server Details Approved time servers _MUST_ be the only servers configured for use. This rule ensures the uniformity of time stamps...
Monterey – Configure SSHD ClientAliveInterval option set to 900 or less Details If SSHD is enabled then it _MUST_ be configured with an Active Client Alive Maximum Count set to 900...
Monterey – Configure SSHD to Use Secure Key Exchange Algorithms Details Unapproved mechanisms for authentication to the cryptographic module are not verified, and therefore cannot be relied upon to provide...
Monterey – Configure System Log Files Owned by Root and Group to Wheel Details The system log files _MUST_ be owned by root. System logs contain sensitive data about the system and users....
Monterey – Configure System Log Files to Mode 640 or Less Permissive Details The system logs _MUST_ be configured to be writable by root and readable only by the root user and...
Monterey – Configure System to Audit All Administrative Action Events Details The auditing system _MUST_ be configured to flag administrative action (ad) events. Administrative action events include changes made to...
Monterey – Configure System to Audit All Authorization and Authentication Events Details The auditing system _MUST_ be configured to flag authorization and authentication (aa) events. Authentication events contain information about the...
Monterey – Configure System to Audit All Changes of Object Attributes Details The audit system _MUST_ be configured to record enforcement actions of attempts to modify file attributes (fm). Enforcement actions...
Monterey – Configure System to Audit All Deletions of Object Attributes Details The audit system _MUST_ be configured to record enforcement actions of attempts to delete file attributes (fd). ***Enforcement actions...
Monterey – Configure System to Audit All Failed Change of Object Attributes Details The audit system _MUST_ be configured to record enforcement actions of failed attempts to modify file attributes (fm). Enforcement...