Skip to content

III - Administrative Sensitive

Rules and Groups employed by this XCCDF Profile

  • SRG-OS-000373-GPOS-00156

    Group
  • The macOS system must require users to reauthenticate for privilege escalation when using the "sudo" command.

    Without reauthentication, users may access resources or perform tasks for which they do not have authorization. When operating systems provide the capability to escalate a functional capability, ...
    Rule Medium Severity
  • SRG-OS-000051-GPOS-00024

    Group
  • The macOS system must enable System Integrity Protection.

    System Integrity Protection (SIP) is vital to the protection of the integrity of macOS. SIP restricts what actions can be performed by administrative users, including root, against protected parts ...
    Rule High Severity
  • SRG-OS-000185-GPOS-00079

    Group
  • The macOS system must implement cryptographic mechanisms to protect the confidentiality and integrity of all information at rest.

    Information at rest refers to the state of information when it is located on a secondary storage device (e.g., disk drive and tape drive) within an organizational information system. Mobile devices...
    Rule High Severity
  • SRG-OS-000480-GPOS-00232

    Group
  • The macOS Application Firewall must be enabled.

    Firewalls protect computers from network attacks by blocking or limiting access to open network ports. Application firewalls limit which applications are allowed to communicate over the network.
    Rule Medium Severity
  • SRG-OS-000480-GPOS-00227

    Group
  • The macOS system must restrict the ability of individuals to use USB storage devices.

    External writeable media devices must be disabled for users. External USB devices are a potential vector for malware and can be used to exfiltrate sensitive data if an approved data-loss prevention...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules