|
2 | 2 |
|
3 | 3 | This document provides a high-level view of the changes to the macOS Security Compliance Project. |
4 | 4 |
|
5 | | -== [Ventura, Revision 2.0] - 2023-06-26 |
| 5 | +== [Sonoma, Revision 1.0] - 2023-09-21 |
6 | 6 |
|
7 | 7 | * Rules |
8 | 8 | ** Added Rules |
9 | | -*** os_home_folders_default |
10 | | -*** supplemental_stig |
| 9 | +*** icloud_freeform_disable |
| 10 | +*** os_account_modification_disable |
| 11 | +*** os_on_device_dictation_enforce |
| 12 | +*** os_setup_assistant_filevault_enforce |
| 13 | +*** os_sshd_channel_timeout_configure |
| 14 | +*** os_sshd_unused_connection_timeout_configure |
11 | 15 | ** Modified Rules |
12 | | -*** audit_acls_files_configure |
13 | | -*** audit_acls_folders_configure |
14 | | -*** audit_auditd_enabled |
15 | | -*** audit_control_mode_configure |
16 | | -*** audit_files_group_configure |
17 | | -*** audit_files_mode_configure |
18 | | -*** audit_files_owner_configure |
19 | | -*** audit_folder_group_configure |
20 | | -*** audit_folder_group_configure |
21 | | -*** audit_folders_mode_configure |
22 | 16 | *** auth_ssh_password_authentication_disable |
23 | | -*** icloud_appleid_preference_pane_disable |
24 | | -*** icloud_appleid_system_settings_disable |
25 | | -*** os_anti_virus_installed |
26 | | -*** os_home_folders_secure |
27 | | -*** os_policy_banner_loginwindow_enforce |
28 | | -*** os_policy_banner_ssh_configure |
29 | 17 | *** os_policy_banner_ssh_enforce |
30 | | -*** os_screensaver_timeout_loginwindow_enforce |
31 | 18 | *** os_sshd_client_alive_count_max_configure |
32 | 19 | *** os_sshd_client_alive_interval_configure |
33 | | -*** os_sshd_fips_140_ciphers |
34 | | -*** os_sshd_fips_140_macs |
35 | 20 | *** os_sshd_fips_compliant |
36 | | -*** os_sshd_key_exchange_algorithm_configure |
37 | 21 | *** os_sshd_login_grace_time_configure |
38 | 22 | *** os_sshd_permit_root_login_configure |
39 | | -*** pwpolicy_account_lockout_timeout_enforce |
40 | | -*** pwpolicy_minimum_length_enforce |
41 | | -*** pwpolicy_special_character_enforce |
42 | | -*** system_settings_assistant_disable |
| 23 | +*** system_settings_location_services_menu_enforce |
| 24 | +*** system_settings_siri_disable |
| 25 | +** Deleted Rules |
| 26 | +*** icloud_appleid_preference_pane_disable.yaml |
| 27 | +*** os_efi_integrity_validated |
| 28 | +*** os_sshd_key_exchange_algorithm_configure |
| 29 | +*** os_sshd_fips_140_ciphers |
| 30 | +*** os_sshd_fips_140_macs |
43 | 31 | *** system_settings_bluetooth_prefpane_disable |
44 | | -*** system_settings_firewall_enable |
45 | | -*** system_settings_firewall_stealth_mode_enable |
46 | | -*** system_settings_guest_account_disable |
47 | 32 | *** system_settings_internet_accounts_preference_pane_disable |
48 | 33 | *** system_settings_siri_prefpane_disable |
49 | 34 | *** system_settings_touch_id_pane_disable |
50 | | -*** system_settings_usb_restricted_mode |
51 | 35 | *** system_settings_wallet_applepay_prefpane_disable |
52 | 36 | *** system_settings_wallet_applepay_prefpane_hide |
53 | | - |
54 | | -* Baselines |
55 | | -** Added Baselines |
56 | | -*** cmmc_lvl1 |
57 | | -*** cmmc_lvl2 |
58 | | -*** cnssi-1253_high |
59 | | -*** cnssi-1253_moderate |
60 | | -*** cnssi-1253_low |
61 | | -*** DISA-STIG |
62 | | -** Modified Baselines |
63 | | -*** all_rules |
64 | | -*** Removed Baselines |
65 | | -** cnssi-1253 |
66 | | - |
67 | | -* Scripts |
68 | | -** generate_guidance |
69 | | -*** Added base64 support for documentation logo |
70 | | -*** Added support for CMMC references |
71 | | -*** Added ssh key generation to compliance script |
72 | | -*** Added cfc argument to compliance script |
73 | | -*** Bug Fixes |
74 | | -** generate_baseline |
75 | | -*** Bug Fixes |
76 | | -** generate_scap |
77 | | -*** Bug Fixes |
78 | | - |
79 | | -* Includes |
80 | | -** mscp-data |
81 | | -*** Added CMMC data |
82 | | -*** Updated CNSSI-1253 data |
83 | | -** supported_payloads |
84 | | -*** Added com.apple.sharingd |
85 | | -*** Removed com.apple.locationmenu |
86 | | - |
87 | | -== [Ventura, Revision 1.1] - 2022-12-08 |
88 | | - |
89 | | -* Rules |
90 | | -** Added Rules |
91 | | -*** icloud_game_center_disable |
92 | | -*** os_safari_advertising_privacy_protection_enable |
93 | | -*** os_safari_prevent_cross-site_tracking_enable |
94 | | -*** os_safari_show_full_website_address_enable |
95 | | -*** os_safari_warn_fraudulent_website_enable |
96 | | -** Modified Rules |
97 | | -*** os_dvdram_disable |
98 | | -*** os_hibernate_mode_enable |
99 | | -*** os_rapid_security_response_removal_disable |
100 | | -*** os_tftpd_disable |
101 | | -*** system_settings_automatic_logout_enforce |
102 | | -*** system_settings_internet_accounts_disable |
103 | | -*** system_settings_ssh_enable |
104 | | -*** system_settings_system_wide_preferences_configure |
105 | | -*** system_settings_time_server_configure |
106 | | -*** system_settings_time_server_enforce |
107 | | -*** supplemental_cis_manual |
108 | | -** Bug fixes |
109 | | - |
110 | | -* Baselines |
111 | | -** Updated all baselines |
112 | | - |
113 | | -* Scripts |
114 | | -** generate_guidance |
115 | | -*** Added custom references to compliance check script |
116 | | -*** Added debug option |
117 | | -*** Bug Fixes |
118 | | -** generate_baseline |
119 | | -*** Added author function |
120 | | -*** Bug Fixes |
121 | | -** generate_mapping |
122 | | -*** Bug Fixes |
123 | | - |
124 | | -== [Ventura, Revision 1] - 2022-10-20 |
125 | | - |
126 | | -* Rules |
127 | | -** Added ODV support |
128 | | -** Added Rules |
129 | | -*** icloud_appleid_system_settings_disable |
130 | | -*** os_config_profile_ui_install_disable |
131 | | -*** os_firewall_ui_disable |
132 | | -*** os_power_nap_enable |
133 | | -*** os_rapid_security_response_allow |
134 | | -*** os_rapid_security_response_removal_disable |
135 | | -*** os_software_update_deferral |
136 | | -*** system_settings_USB_restricted_mode |
137 | | -*** system_settings_internet_accounts_disable |
138 | | -** Modified Rules |
139 | | -*** os_power_nap_disable |
140 | | -*** os_ssh_fips_compliant |
141 | | -*** os_ssh_server_alive_count_max_configure |
142 | | -*** os_ssh_server_alive_interval_configure |
143 | | -*** os_sshd_client_alive_count_max_configure |
144 | | -*** os_sshd_client_alive_interval_configure |
145 | | -*** os_sshd_fips_140_ciphers |
146 | | -*** os_sshd_fips_140_macs |
147 | | -*** os_sshd_fips_compliant |
148 | | -*** os_sshd_key_exchange_algorithm_configure |
149 | | -*** os_sshd_login_grace_time_configure |
150 | | -*** os_sshd_permit_root_login_configure |
151 | | -*** os_sudo_timeout_configure |
152 | | -*** os_sudoers_timestamp_type_configure |
153 | | -*** pwpolicy_account_inactivity_enforce.yaml |
154 | | -*** pwpolicy_account_lockout_enforce.yaml |
155 | | -*** pwpolicy_account_lockout_timeout_enforce.yaml |
156 | | -*** pwpolicy_alpha_numeric_enforce.yaml |
157 | | -*** pwpolicy_history_enforce.yaml |
158 | | -*** pwpolicy_lower_case_character_enforce.yaml |
159 | | -*** pwpolicy_max_lifetime_enforce.yaml |
160 | | -*** pwpolicy_minimum_length_enforce.yaml |
161 | | -*** pwpolicy_minimum_lifetime_enforce.yaml |
162 | | -*** pwpolicy_simple_sequence_disable.yaml |
163 | | -*** pwpolicy_special_character_enforce.yaml |
164 | | -*** pwpolicy_upper_case_character_enforce.yaml |
165 | | -*** system_settings_system_wide_preferences_configure |
166 | | -*** System Preferences -> System Settings |
167 | | -** Deleted Rules |
168 | | -*** os_sudoers_tty_configure |
169 | 37 | ** Bug Fixes |
170 | 38 |
|
171 | 39 | * Baselines |
172 | 40 | ** Modified existing baselines |
173 | | -** Added parent_values |
174 | 41 |
|
175 | 42 | * Scripts |
176 | 43 | ** generate_guidance |
177 | | -*** Added ODV support |
178 | | -*** Added Ruby gem generation |
179 | | -*** Added support for fix/check in compliance script |
180 | | -*** Added unified log support to compliance script |
| 44 | +*** Added iOS support |
| 45 | +*** Added support for pwpolicy regex |
| 46 | +*** Modified ssh_key_check |
181 | 47 | *** Bug Fixes |
182 | 48 | ** generate_baseline |
183 | | -*** Added ODV support |
184 | | -*** Added tailoring support |
| 49 | +*** Added iOS support |
185 | 50 | *** Bug Fixes |
186 | 51 | ** generate_mappings |
| 52 | +*** Added iOS support |
187 | 53 | *** Bug Fixes |
188 | 54 | ** generate_scap |
189 | | -*** Added support for ODV |
190 | | -*** Added support for new checks |
191 | | -*** Generate scap, xccdf, or oval |
192 | | -*** Bug Fixes |
193 | | - |
194 | | - |
| 55 | +*** Added iOS support |
| 56 | +*** Added support for pwpolicy regex |
| 57 | +*** Bug Fixes |
0 commit comments