Skip to content

Jamf Pro v10.x EMM Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • PP-MDM-411058

    Group
  • PP-MDM-414002

    Group
  • The Jamf Pro EMM server must be configured to leverage the MDM platform user accounts and groups for Jamf Pro EMM server user identification and CAC authentication.

    A comprehensive account management process that includes automation helps to ensure the accounts designated as requiring attention are consistently and promptly addressed. If an attacker compromise...
    Rule Medium Severity
  • PP-MDM-991000

    Group
  • PP-MDM-991000

    Group
  • PP-MDM-991000

    Group
  • Jamf Pro EMM must be maintained at a supported version.

    The MDM/EMM vendor maintains specific product versions for a specific period of time. MDM/EMM server versions no longer supported by the vendor will not receive security updates for new vulnerabili...
    Rule High Severity
  • PP-MDM-991000

    Group
  • The default mysql_secure_installation must be installed.

    The mysql_secure_installation configuration of MySQL adds several important configuration settings that block several attack vectors. The My SQL application could be exploited by an adversary witho...
    Rule Medium Severity
  • PP-MDM-991000

    Group
  • A unique database name and a unique MySQL user with a secure password must be created for use in Jamf Pro EMM.

    If the default MySQL database name and password are not changed an adversary could gain unauthorized access to the application which could lead to the compromise of sensitive DOD data. SFR ID: FMT...
    Rule Medium Severity
  • PP-MDM-991000

    Group
  • PP-MDM-991000

    Group
  • MySQL database backups must be scheduled in Jamf Pro EMM.

    Database backups are a recognized best practice to protect against key data loss and possible adverse impacts to the mission of the organization. SFR ID: FMT_SMF.1(2)b. / CM-6 b Satisfies: SRG-AP...
    Rule Medium Severity
  • PP-MDM-991000

    Group
  • PP-MDM-431005

    Group
  • PP-MDM-991000

    Group
  • The Jamf Pro EMM local accounts must be configured with at least one lowercase character.

    Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resistin...
    Rule Medium Severity
  • PP-MDM-991000

    Group
  • The Jamf Pro EMM local accounts must be configured with at least one uppercase character.

    Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resistin...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules