Apple macOS 15 (Sequoia) STIG Compliance Checklist
21 items · Security · Medium difficulty · 4 hours
Essential macOS 15 STIG tasks to secure and validate your Sequoia systems.
-
Download the Apple macOS 15 STIG and XCCDF/SCC automated content
Get official STIG PDF and XCCDF/SCC content from DISA or NIST for authoritative controls.
-
Review the STIG summary and Smart Card guidance
Read sections on Smart Card policy and remote access to avoid lockouts.
-
Test STIG settings in a lab or non-production environment
Validate changes and rollback procedures before production deployment.
-
Backup system and critical data before applying STIG changes
Create full backups or snapshots to restore if changes cause issues.
-
Patch macOS to the latest 15.x release
Install all macOS security updates to meet baseline requirements.
- Configure authentication policies
-
Enforce password complexity and expiration
Set complexity, minimum length, and rotation to DoD or organizational policy.
-
Enable smart card authentication per STIG guidance
Follow the STIG supplemental guidance to avoid loss of OS access.
-
Disable automatic login and Guest account
Ensure no account allows bypassing authentication on boot.
- Harden macOS security settings
-
Enable FileVault full-disk encryption
Encrypt system volumes to protect data at rest.
-
Enable System Integrity Protection (SIP)
Keep SIP enabled to limit kernel and system file changes.
-
Enable Gatekeeper and restrict app installation
Require notarized apps and limit sources to reduce malware risk.
- Configure network and remote access controls
-
Disable unnecessary network services and close unused ports
Stop and disable services not required for system function.
-
Restrict remote access and enforce VPN and MFA
Allow remote access only via approved VPNs and multifactor auth.
-
Configure logging and auditing; forward logs to a central system
Enable unified audit logging and ship events to SIEM or log server.
-
Apply configuration management and baseline with XCCDF/SCC content
Use the downloaded automated content to enforce baselines across hosts.
-
Validate compliance and generate STIG reports
Run scans, review findings, and produce artifacts for A&A and auditors.
-
Document configuration changes and record STIG exceptions
Keep change records, rationale, and any accepted deviations.
-
Submit comments or change requests to DISA when appropriate
Send proposed revisions or feedback to the DISA contact if needed.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.