DISA STIG Apple Mac OSX 10.10 v1r5

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: DISA STIG Apple Mac OSX 10.10 v1r5

Updated: 4/2/2021

Authority: DISA STIG

Plugin: Unix

Revision: 1.10

Estimated Item Count: 154

Audit Items

DescriptionCategories
AOSX-10-000005 - The system must conceal, via session lock, information previously visible on the display with a publicly viewable image.

ACCESS CONTROL

AOSX-10-000010 - The operating system must initiate a session lock after a 15-minute period of inactivity.

ACCESS CONTROL

AOSX-10-000020 - The system must retain the session lock until the user reestablishes access using identification and auth procedures.

ACCESS CONTROL

AOSX-10-000030 - The operating system must monitor remote access methods.

AUDIT AND ACCOUNTABILITY

AOSX-10-000035 - The operating system must implement DoD-approved encryption to protect the confidentiality of remote access sessions.

CONFIGURATION MANAGEMENT

AOSX-10-000040 - The operating system must implement cryptography to protect the integrity of remote access sessions.

CONFIGURATION MANAGEMENT

AOSX-10-000050 - The rshd service must be disabled.

CONFIGURATION MANAGEMENT

AOSX-10-000055 - The operating system must enforce requirements for remote connections to the information system.

CONFIGURATION MANAGEMENT

AOSX-10-000065 - The Bluetooth software driver must be removed. - 'IOBluetoothFamily.kext'

CONFIGURATION MANAGEMENT

AOSX-10-000065 - The Bluetooth software driver must be removed. - 'IOBluetoothHIDDriver.kext'

CONFIGURATION MANAGEMENT

AOSX-10-000070 - Wi-Fi support software must be disabled.

CONFIGURATION MANAGEMENT

AOSX-10-000075 - Infrared [IR] support must be disabled.

CONFIGURATION MANAGEMENT

AOSX-10-000085 - Automatic actions must be disabled for blank CDs.

CONFIGURATION MANAGEMENT

AOSX-10-000090 - Automatic actions must be disabled for blank DVDs.

CONFIGURATION MANAGEMENT

AOSX-10-000095 - Automatic actions must be disabled for music CDs.

CONFIGURATION MANAGEMENT

AOSX-10-000100 - Automatic actions must be disabled for picture CDs.

CONFIGURATION MANAGEMENT

AOSX-10-000105 - Automatic actions must be disabled for video DVDs.

CONFIGURATION MANAGEMENT

AOSX-10-000110 - The operating system must automatically remove or disable temporary user accounts after 72 hours.
AOSX-10-000115 - The operating system must be configured such that emergency administrator accounts are never automatically disabled.
AOSX-10-000120 - The operating system must automatically audit account creation.

AUDIT AND ACCOUNTABILITY

AOSX-10-000125 - The operating system must automatically audit account modification.

AUDIT AND ACCOUNTABILITY

AOSX-10-000130 - The operating system must automatically audit account disabling actions.

AUDIT AND ACCOUNTABILITY

AOSX-10-000135 - The operating system must automatically audit account removal actions.

AUDIT AND ACCOUNTABILITY

AOSX-10-000139 - SMB File Sharing must be disabled unless required.

CONFIGURATION MANAGEMENT

AOSX-10-000140 - Apple File (AFP) Sharing must be disabled.

CONFIGURATION MANAGEMENT

AOSX-10-000141 - The NFS daemon must be disabled unless required.

CONFIGURATION MANAGEMENT

AOSX-10-000142 - The NFS lock daemon must be disabled unless required.

CONFIGURATION MANAGEMENT

AOSX-10-000143 - The NFS stat daemon must be disabled unless required.

CONFIGURATION MANAGEMENT

AOSX-10-000155 - The system firewall must be configured with a default-deny policy.
AOSX-10-000170 - The operating system must generate audit records for privileged activities or other system-level access.

AUDIT AND ACCOUNTABILITY

AOSX-10-000185 - System must display the DoD Notice and Consent Banner before granting access to the system - 'PolicyBanner.rtf text'

ACCESS CONTROL

AOSX-10-000185 - System must display the DoD Notice and Consent Banner before granting access to the system - 'PolicyBanner.rtfd text'

ACCESS CONTROL

AOSX-10-000185 - System must display the DoD Notice and Consent Banner before granting access to the system - PolicyBanner.rtf exist

ACCESS CONTROL

AOSX-10-000185 - System must display the DoD Notice and Consent Banner before granting access to the system - PolicyBanner.rtfd exist

ACCESS CONTROL

AOSX-10-000186 - The SSH banner must contain the Standard Mandatory DoD Notice and Consent Banner. - '/etc/banner'

ACCESS CONTROL

AOSX-10-000186 - The SSH banner must contain the Standard Mandatory DoD Notice and Consent Banner. - 'Banner Content'

ACCESS CONTROL

AOSX-10-000187 - The system must display the DoD Notice and Consent Banner before granting access to the system via SSH.

ACCESS CONTROL

AOSX-10-000195 - Publically accessible connections to system must display the DoD Banner before granting access - 'PolicyBanner.rtf exist'

ACCESS CONTROL

AOSX-10-000195 - Publically accessible connections to system must display the DoD Banner before granting access - 'PolicyBanner.rtf text'

ACCESS CONTROL

AOSX-10-000195 - Publically accessible connections to system must display the DoD Banner before granting access - 'PolicyBanner.rtfd exist'

ACCESS CONTROL

AOSX-10-000195 - Publically accessible connections to system must display the DoD Banner before granting access - 'PolicyBanner.rtfd text'

ACCESS CONTROL

AOSX-10-000200 - The operating system must generate audit records when successful/unsuccessful logon attempts occur.

AUDIT AND ACCOUNTABILITY

AOSX-10-000230 - The operating system must initiate session audits at system startup.

AUDIT AND ACCOUNTABILITY

AOSX-10-000240 - System must provide audit record generation capability for DoD-defined auditable events for all system components.

AUDIT AND ACCOUNTABILITY

AOSX-10-000245 - System must generate audit records for all account creations, modifications, disabling, and termination events.

AUDIT AND ACCOUNTABILITY

AOSX-10-000295 - System must allocate audit record storage capacity to store at least one weeks worth of audit records.

AUDIT AND ACCOUNTABILITY

AOSX-10-000305 - System must provide an immediate warning to the SA and ISSO when allocated audit record storage volume reaches 75%.

AUDIT AND ACCOUNTABILITY

AOSX-10-000310 - System must provide an immediate real-time alert to the SA and ISSO of all audit failure events requiring real-time alerts.

AUDIT AND ACCOUNTABILITY

AOSX-10-000330 - System must compare internal system clocks at least every 24 hours with an approved server.

AUDIT AND ACCOUNTABILITY

AOSX-10-000331 - Audit log files must be owned by root.

AUDIT AND ACCOUNTABILITY