Apple macOS 14 (Sonoma) STIG
20 items · Security · Hard difficulty · 4 hours
Practical STIG steps to harden macOS 14 (Sonoma) endpoints.
-
Inventory macOS 14 devices
Identify all Sonoma devices in scope for STIG implementation.
-
Enroll devices in MDM
Ensure all managed systems are enrolled for configuration and policy enforcement.
-
Apply latest Apple security updates
Install all current macOS 14 security patches and firmware updates.
-
Enable FileVault full-disk encryption
Turn on FileVault to protect data at rest on all devices.
-
Record each FileVault recovery key securely
Store keys in MDM or an encrypted enterprise vault for recovery.
-
Verify FileVault encryption status on all devices
Confirm every endpoint reports FileVault enabled and fully encrypted.
-
Enable System Integrity Protection (SIP) and Secure Boot
Ensure SIP and platform secure boot features are active where supported.
-
Configure Gatekeeper to allow only signed apps
Restrict execution to Apple-signed or notarized applications via policy.
-
Enable macOS firewall and stealth mode
Turn on the built-in firewall and enable stealth mode to block unsolicited traffic.
-
Disable unnecessary sharing and remote services
Turn off Remote Login, AirDrop, File Sharing, and other unused services.
-
Require strong password policy and screen lock
Enforce complexity, lockout, and idle lock requirements via profile.
-
Set password complexity and expiration via configuration profile
Deploy profiles that require length, history, and expiration rules.
-
Set automatic screen lock and require password on wake
Configure short idle timeout and require immediate password after sleep.
-
Disable Guest and Shared Accounts
Turn off macOS Guest and shared account login to prevent anonymous access.
-
Configure secure auditing and log forwarding
Enable audit logging and forward logs to a centralized SIEM or log server.
-
Restrict removable media and external drive access
Use MDM controls to limit or encrypt USB and external storage use.
-
Install and configure smart card authentication (if required)
Follow supplemental guidance to avoid loss of access when enabling smart cards.
-
Harden privacy and permissions (TCC) for apps
Audit and restrict applications' access to camera, microphone, and files.
-
Enforce secure time sync and timezone settings
Configure NTP sources and lock timezone settings to prevent tampering.
-
Document configurations and maintain STIG compliance records
Log changes, baselines, and evidence to demonstrate ongoing compliance.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.