STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 7 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to STIGs

Apple macOS 14 (Sonoma) Security Technical Implementation Guide

Archived

Version

V2R3

Release Date

Jan 30, 2025

SCAP Benchmark ID

S-fca2b2173fd76f1334f4d92ff6d1c6cbbb052813

Total Checks

155

Tags

other
CAT I: 10CAT II: 143CAT III: 2

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSON

Checks (155)

V-259418MEDIUMThe macOS system must prevent Apple Watch from terminating a session lock.V-259419MEDIUMThe macOS system must enforce screen saver password.V-259420MEDIUMThe macOS system must enforce session lock no more than five seconds after screen saver is started.V-259421MEDIUMThe macOS system must configure user session lock when a smart token is removed.V-259422MEDIUMThe macOS system must disable hot corners.V-259423MEDIUMThe macOS system must prevent AdminHostInfo from being available at LoginWindow.V-259424MEDIUMThe macOS system must automatically remove or disable temporary or emergency user accounts within 72 hours.V-259425MEDIUMThe macOS system must enforce time synchronization.V-259428MEDIUMThe macOS system must limit consecutive failed log on attempts to three.V-259429MEDIUMThe macOS system must display the Standard Mandatory DOD Notice and Consent Banner at remote log on.V-259430MEDIUMThe macOS system must enforce SSH to display the Standard Mandatory DOD Notice and Consent Banner.V-259431MEDIUMThe macOS system must display the Standard Mandatory DOD Notice and Consent Banner at the login window.V-259432MEDIUMThe macOS system must configure audit log files to not contain access control lists.V-259433MEDIUMThe macOS system must configure audit log folders to not contain access control lists.V-259434MEDIUMThe macOS system must disable FileVault automatic log on.V-259435MEDIUMThe macOS system must configure SSHD ClientAliveInterval to 900.V-259436MEDIUMThe macOS system must configure SSHD ClientAliveCountMax to 1.V-259437MEDIUMThe macOS system must set Login Grace Time to 30.V-259438HIGHThe macOS system must limit SSHD to FIPS-compliant connections.V-259439HIGHThe macOS system must limit SSH to FIPS-compliant connections.V-259440MEDIUMThe macOS system must set account lockout time to 15 minutes.V-259441MEDIUMThe macOS system must enforce screen saver timeout.V-259443MEDIUMThe macOS system must disable logon to other user's active and locked sessions.V-259444MEDIUMThe macOS system must disable root logon.V-259445MEDIUMThe macOS system must configure SSH ServerAliveInterval option set to 900.V-259446MEDIUMThe macOS system must configure SSHD Channel Timeout to 900.V-259447MEDIUMThe macOS system must configure SSHD unused connection timeout to 900.V-259448MEDIUMThe macOS system must set SSH Active Server Alive Maximum to 0.V-259449MEDIUMThe macOS system must enforce auto logout after 86400 seconds of inactivity.V-259450MEDIUMThe macOS system must be configured to use an authorized time server.V-259451MEDIUMThe macOS system must enable time synchronization daemon.V-259452MEDIUMThe macOS system must be configured to audit all administrative action events.V-259453MEDIUMThe macOS system must be configured to audit all log on and log out events.V-259454MEDIUMThe macOS system must enable security auditing.V-259455MEDIUMThe macOS system must configure system to shut down upon audit failure.V-259456MEDIUMThe macOS system must configure audit log files to be owned by root.V-259457MEDIUMThe macOS system must configure audit log folders to be owned by root.V-259458MEDIUMThe macOS system must configure audit log files group to wheel.V-259459MEDIUMThe macOS system must configure audit log folders group to wheel.V-259460MEDIUMThe macOS system must configure audit log files to mode 440 or less permissive.V-259461MEDIUMThe macOS system must configure audit log folders to mode 700 or less permissive.V-259462MEDIUMThe macOS system must be configured to audit all deletions of object attributes.V-259463MEDIUMThe macOS system must be configured to audit all changes of object attributes.V-259464MEDIUMThe macOS system must be configured to audit all failed read actions on the system.V-259465MEDIUMThe macOS system must be configured to audit all failed write actions on the system.V-259466MEDIUMThe macOS system must be configured to audit all failed program execution on the system.V-259467LOWThe macOS system must configure audit retention to seven days.V-259468MEDIUMThe macOS system must configure audit capacity warning.V-259469MEDIUMThe macOS system must configure audit failure notification.V-259470MEDIUMThe macOS system must configure the system to audit all authorization and authentication events.V-259471MEDIUMThe macOS system must set smart card certificate trust to moderate.V-259472MEDIUMThe macOS system must disable root logon for SSH.V-259473MEDIUMThe macOS system must configure audit_control group to wheel.V-259474MEDIUMThe macOS system must configure audit_control owner to root.V-259475MEDIUMThe macOS system must configure audit_control to mode 440 or less permissive.V-259476MEDIUMThe macOS system must configure audit_control to not contain access control lists.V-259477HIGHThe macOS system must disable password authentication for SSH.V-259478MEDIUMThe macOS system must disable Server Message Block sharing.V-259479MEDIUMThe macOS system must disable Network File System service.V-259480MEDIUMThe macOS system must disable Location Services.V-259481MEDIUMThe macOS system must disable Bonjour multicast.V-259482MEDIUMThe macOS system must disable Unix-to-Unix Copy Protocol service.V-259483MEDIUMThe macOS system must disable Internet Sharing.V-259484MEDIUMThe macOS system must disable the built-in web server.V-259485MEDIUMThe macOS system must disable AirDrop.V-259486MEDIUMThe macOS system must disable FaceTime.app.V-259487MEDIUMThe macOS system must disable the iCloud Calendar services.V-259488MEDIUMThe macOS system must disable iCloud Reminders.V-259489MEDIUMThe macOS system must disable iCloud Address Book.V-259490MEDIUMThe macOS system must disable iCloud Mail.V-259491MEDIUMThe macOS system must disable iCloud Notes.V-259492MEDIUMThe macOS system must disable the camera.V-259493MEDIUMThe macOS system must disable Siri.V-259494MEDIUMThe macOS system must disable sending diagnostic and usage data to Apple.V-259495MEDIUMThe macOS system must disable Remote Apple Events.V-259496MEDIUMThe macOS system must disable Apple ID setup during Setup Assistant.V-259497MEDIUMThe macOS system must disable Privacy Setup services during Setup Assistant.V-259498MEDIUMThe macOS system must disable iCloud Storage Setup during Setup Assistant.V-259499HIGHThe macOS system must disable Trivial File Transfer Protocol service.V-259500MEDIUMThe macOS system must disable Siri Setup during Setup Assistant.V-259501MEDIUMThe macOS system must disable iCloud Keychain synchronization.V-259502MEDIUMThe macOS system must disable iCloud Document synchronization.V-259503MEDIUMThe macOS system must disable iCloud Bookmarks.V-259504MEDIUMThe macOS system must disable iCloud Photo Library.V-259505MEDIUMThe macOS system must disable Screen Sharing and Apple Remote Desktop.V-259506MEDIUMThe macOS system must disable the TouchID System Settings pane.V-259507MEDIUMThe macOS system must disable the System Settings pane for Wallet and Apple Pay.V-259508MEDIUMThe macOS system must disable the system settings pane for Siri.V-259509HIGHThe macOS system must apply gatekeeper settings to block applications from unidentified developers.V-259510HIGHThe macOS system must disable Bluetooth when no approved device is connected.V-259511MEDIUMThe macOS system must disable the guest account.V-259512HIGHThe macOS system must enable Gatekeeper.V-259513MEDIUMThe macOS system must disable unattended or automatic log on to the system.V-259514MEDIUMThe macOS system must secure user's home folders.V-259515HIGHThe macOS system must require administrator privileges to modify systemwide settings.V-259516MEDIUMThe macOS system must disable Airplay Receiver.V-259517MEDIUMThe macOS system must disable TouchID for unlocking the device.V-259518MEDIUMThe macOS system must disable Media Sharing.V-259519MEDIUMThe macOS system must disable Bluetooth sharing.V-259520MEDIUMThe macOS system must disable AppleID and Internet Account modifications.V-259521MEDIUMThe macOS system must disable CD/DVD Sharing.V-259522MEDIUMThe macOS system must disable content caching service.V-259523MEDIUMThe macOS system must disable iCloud desktop and document folder synchronization.V-259524MEDIUMThe macOS system must disable iCloud Game Center.V-259525MEDIUMThe macOS system must disable iCloud Private Relay.V-259526MEDIUMThe macOS system must disable Find My service.V-259527MEDIUMThe macOS system must disable password autofill.V-259528MEDIUMThe macOS system must disable personalized advertising.V-259529MEDIUMThe macOS system must disable sending Siri and Dictation information to Apple.V-259530MEDIUMThe macOS system must enforce on device dictation.V-259531MEDIUMThe macOS system must disable dictation.V-259532MEDIUMThe macOS system must disable Printer Sharing.V-259533MEDIUMThe macOS system must disable Remote Management.V-259534MEDIUMThe macOS system must disable the Bluetooth system settings pane.V-259535MEDIUMThe macOS system must disable the iCloud Freeform services.V-259536MEDIUMThe macOS system must issue or obtain public key certificates from an approved service provider.V-259537MEDIUMThe macOS system must require passwords contain a minimum of one numeric character.V-259538MEDIUMThe macOS system must restrict maximum password lifetime to 60 days.V-259540MEDIUMThe macOS system must require a minimum password length of 14 characters.V-259541MEDIUMThe macOS system must require passwords contain a minimum of one special character.V-259542MEDIUMThe macOS system must disable password hints.V-259543MEDIUMThe macOS system must enable firmware password.V-259544MEDIUMThe macOS system must remove password hints from user accounts.V-259545MEDIUMThe macOS system must enforce smart card authentication.V-259546MEDIUMThe macOS system must allow smart card authentication.V-259547MEDIUMThe macOS system must enforce multifactor authentication for logon.V-259548MEDIUMThe macOS system must enforce multifactor authentication for the su command.V-259549MEDIUMThe macOS system must enforce multifactor authentication for privilege escalation through the sudo command.V-259550MEDIUMThe macOS system must require passwords contain a minimum of one lowercase character and one uppercase character.V-259551MEDIUMThe macOS system must set minimum password lifetime to 24 hours.V-259552MEDIUMThe macOS system must disable accounts after 35 days of inactivity.V-259553MEDIUMThe macOS system must configure Apple System Log files to be owned by root and group to wheel.V-259554MEDIUMThe macOS system must configure Apple System Log files to mode 640 or less permissive.V-259555MEDIUMThe macOS system must require users to reauthenticate for privilege escalation when using the "sudo" command.V-259556MEDIUMThe macOS system must configure system log files to be owned by root and group to wheel.V-259557MEDIUMThe macOS system must configure system log files to mode 640 or less permissive.V-259558LOWThe macOS system must configure install.log retention to 365.V-259559MEDIUMThe macOS system must configure sudoers timestamp type.V-259560HIGHThe macOS system must ensure System Integrity Protection is enabled.V-259561HIGHThe macOS system must enforce FileVault.V-259562MEDIUMThe macOS system must enable the application firewall.V-259563MEDIUMThe macOS system must configure login window to prompt for username and password.V-259564MEDIUMThe macOS system must disable TouchID prompt during Setup Assistant.V-259565MEDIUMThe macOS system must disable Screen Time prompt during Setup Assistant.V-259566MEDIUMThe macOS system must disable Unlock with Apple Watch during Setup Assistant.V-259567MEDIUMThe macOS system must disable Handoff.V-259568MEDIUMThe macOS system must disable proximity-based password sharing requests.V-259569MEDIUMThe macOS system must disable Erase Content and Settings.V-259570MEDIUMThe macOS system must enable Authenticated Root.V-259571MEDIUMThe macOS system must prohibit user installation of software into /users/.V-259572MEDIUMThe macOS system must authorize USB devices before allowing connection.V-259573MEDIUMThe macOS system must ensure secure boot level set to full.V-259574MEDIUMThe macOS system must enforce enrollment in mobile device management.V-259575MEDIUMThe macOS system must enable recovery lock.V-259576MEDIUMThe macOS system must enforce installation of XProtect Remediator and Gatekeeper updates automatically.