Apple macOS 26 (Tahoe) STIG Implementation Checklist
20 items · Security · Hard difficulty · 1 day
Step-by-step STIG checklist to secure macOS 26 (Apple Silicon).
-
Download Apple macOS 26 STIG documents
Obtain STIG PDF from cyber.mil or public.cyber.mil for authoritative guidance.
-
Download XCCDF and automated SCC content for macOS ARM64
Get XCCDF 1.1.4 and SCC automated content for Apple Silicon from DISA.
-
Verify device is Apple Silicon running macOS 26.0.0
Confirm cpe:/o:apple:macos:26.0.0 target matches the system before applying guidance.
-
Enroll the device in a managed MDM solution
Required for centralized policy, updates, and compliance enforcement.
-
Configure automatic system and security updates via MDM
Ensure security updates are applied promptly and centrally managed.
-
Enable FileVault full-disk encryption
Activate FileVault and securely store recovery key per policy.
-
Configure and enforce smart card / CAC authentication
Follow STIG supplemental guidance; misconfiguration can lock out access.
-
Install smart card middleware and trusted CAC certificates
Add required middleware and system certificates for CAC authentication.
-
Test smart card login and fallback administrative accounts
Validate CAC login works and emergency admin access is available.
-
Confirm System Integrity Protection (SIP) and secure-boot settings meet STIG
Verify SIP enabled and secure-boot policies align with DISA guidance.
-
Disable guest and other unused user accounts
Remove or disable accounts that are not required to reduce attack surface.
-
Configure firewall and limit incoming connections
Enable macOS firewall; allow only required services and ports.
-
Harden Gatekeeper and app execution policies
Require notarized apps and enforce execution restrictions per STIG.
-
Disable Remote Login (SSH) if not required
Turn off remote access services or restrict them to authorized hosts.
-
Configure audit logging and forward logs to a central server
Send logs to SIEM or central collector per DoDI 8500.01 and STIG requirements.
-
Run STIG/XCCDF scan and remediate findings
Use SCAP/XCCDF tools to scan, then apply remediations for each finding.
-
Verify FIPS-compliant cryptography where required
Ensure crypto modules and settings meet FIPS requirements where applicable.
-
Backup system configuration and document baseline settings
Capture configuration, keys, and a system image for recovery and audit.
-
Submit comments or change requests to DISA if needed
Email proposed revisions to [email protected] per STIG maintenance process.
-
Schedule regular STIG reviews and re-evaluations
Plan periodic rescans after OS updates or configuration changes.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.