# | Mode | Name | Severity | UIX impact | Default Value | Recommended Value | Apply |
---|---|---|---|---|---|---|---|
Filter | |||||||
Updates |
|||||||
1001 | Basic | Software Update : Automatically check new software updates | Medium | No impact | true |
true |
|
Software Update : Automatically check new software updatesAutomaticUpdates
IntroductionAuto Update verifies that your system has the newest security patches and software updates. If "Automatically check for updates" is not selected background updates for new malware definition files from Apple for XProtect and Gatekeeper will not occur. Read more >Graphical Method
Table of settingsUIXNo impact :0
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactWithout automatic update, updates may not be made in a timely manner and the system will be exposed to additional risk.
AdvicesIt is important that a system has the newest updates applied so as to prevent unauthorized persons from exploiting identified vulnerabilities.
Notes |
|||||||
1002 | Basic | Software Update : Automatically download new software updates | Medium | No impact | true |
true |
|
Software Update : Automatically download new software updatesAutomaticUpdateDownload
IntroductionThis policy download new updates automaticly Read more >Graphical Method
Table of settingsUIXNo impact :0
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactIf "Download new updates when available" is not selected, updates may not made in a timely manner and the system will be exposed to additional risk.
AdvicesIt is important that a system has the newest updates applied so as to prevent unauthorized persons from exploiting identified vulnerabilities.
|
|||||||
1003 | Basic | Software Update : Enable system data files updates install | Medium | No impact | true |
true |
|
Software Update : Enable system data files updates installUpdates Install
IntroductionThis policy install and update system data files Read more >Graphical Method
Table of settingsUIXNo impact :0
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactUnpatched software may be exploited.
AdvicesPatches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited.
|
|||||||
1004 | Basic | Software Update : Enable security updates install | Medium | No impact | true |
true |
|
Software Update : Enable security updates installUpdates Install Security
IntroductionThis policy allow security updates/installation Read more >Graphical Method
Table of settingsUIXNo impact :0
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactUnpatched software may be exploited.
AdvicesPatches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited.
|
|||||||
1005 | Basic | Software Update : Automatically install macOS updates | Medium | No impact | false |
true |
|
Software Update : Automatically install macOS updatesAutomaticUpdates Install
IntroductionThis policy install MacOS updates automaticly Read more >Graphical Method
Table of settingsUIXNo impact :0
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactUnpatched software may be exploited.
AdvicesPatches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited.
|
|||||||
1100 | Basic | AppStore : Automatically keep apps up to date from app store | Medium | No impact | false |
true |
|
AppStore : Automatically keep apps up to date from app storeAutomaticUpdates Install Apps
IntroductionThis policy install apps from AppStore updates automaticly Read more >Graphical Method
Table of settingsUIXNo impact :0
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactUnpatched software may be exploited.
AdvicesPatches need to be applied in a timely manner to reduce the risk of vulnerabilities being exploited.
|
|||||||
Login/Logout |
|||||||
2000 | Basic | Sleep : AC display sleep timer | Medium | Impact | 10 |
5 |
|
Sleep : AC display sleep timerBattery Sleep Display
IntroductionThis policy turn off the display after a time of inactivity when your computer is using his battery. Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
2001 | Basic | Sleep : Battery display sleep timer | Medium | Impact | 2 |
2 |
|
Sleep : Battery display sleep timerBattery Sleep Display
IntroductionThis policy turn off the display after a time of inactivity when your computer is charging. Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
2100 | Basic | Screen Saver : Enable prompt for a password on screen saver | High | Impact | false |
true |
|
Screen Saver : Enable prompt for a password on screen saverPassword Sleep
IntroductionThis policy ask for a password after sleep or screen saver begins Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
2101 | Basic | Screen Saver : Set password delay | High | Impact |
|
0 |
|
Screen Saver : Set password delayPassword Sleep Timer
IntroductionThis policy set the time after the password is asked Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsAdvicesIf true, the user is prompted for a password when the screen saver is unlocked or stopped. When you use this prompt, you must also provide askForPasswordDelay. Available in macOS 10.13 and later. Default: false
|
|||||||
2102 | Basic | Screen Saver : Set an inactivity interval for the screen saver | Medium | Impact | 1200 |
1200 |
|
Screen Saver : Set an inactivity interval for the screen saverScreen Saver
IntroductionThis policy set an inactivity interval before Screen saver Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsAdvicesThe number of seconds to delay before the password will be required to unlock or stop the screen saver (the grace period). A value of 2147483647 (for example, 0x7FFFFFFF) disables this requirement. To use this option, you must set askForPassword to true. Available in macOS 10.13 and later.
|
|||||||
21031 | Basic | Screen Saver : Secure screen saver corners (top-left) | Medium | Impact | 0 |
0 |
|
Screen Saver : Secure screen saver corners (top-left)Hot corners
IntroductionHot Corners can be configured to disable the screen saver by moving the mouse cursor to a corner of the screen. Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactIf the screensaver is not set users may leave the computer available for an unauthorized person to access information.
AdvicesSetting an inactivity interval for the screensaver prevents unauthorized persons from viewing a system left unattended for an extensive period of time.
|
|||||||
21032 | Basic | Screen Saver : Secure screen saver corners (bottom-left) | Medium | Impact | 0 |
0 |
|
Screen Saver : Secure screen saver corners (bottom-left)Hot corners
IntroductionHot Corners can be configured to disable the screen saver by moving the mouse cursor to a corner of the screen. Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactIf the screensaver is not set users may leave the computer available for an unauthorized person to access information.
AdvicesSetting an inactivity interval for the screensaver prevents unauthorized persons from viewing a system left unattended for an extensive period of time.
|
|||||||
21033 | Basic | Screen Saver : Secure screen saver corners (top-right) | Medium | Impact | 0 |
0 |
|
Screen Saver : Secure screen saver corners (top-right)Hot corners
IntroductionHot Corners can be configured to disable the screen saver by moving the mouse cursor to a corner of the screen. Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactIf the screensaver is not set users may leave the computer available for an unauthorized person to access information.
AdvicesSetting an inactivity interval for the screensaver prevents unauthorized persons from viewing a system left unattended for an extensive period of time.
|
|||||||
21034 | Basic | Screen Saver : Secure screen saver corners (bottom-right) | Medium | Impact | 0 |
0 |
|
Screen Saver : Secure screen saver corners (bottom-right)Hot corners
IntroductionHot Corners can be configured to disable the screen saver by moving the mouse cursor to a corner of the screen. Read more >Graphical Method
Table of settingsUIXImpact :2
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More InformationsPotential impactIf the screensaver is not set users may leave the computer available for an unauthorized person to access information.
AdvicesSetting an inactivity interval for the screensaver prevents unauthorized persons from viewing a system left unattended for an extensive period of time.
|
|||||||
2200 | Policy Banner : Enable Policy Banner | Low | Not defined |
|
|
||
Policy Banner : Enable Policy BannerTable of settingsUIXNot defined :
ValuesType :
Possible Values :
More Informations |
|||||||
2300 | Logout : Set Logout delay | High | Not defined |
|
3600 |
||
Logout : Set Logout delayTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
2400 | Windows text : Set Login Window Text | Low | Not defined |
|
Protected by Cyberlib |
||
Windows text : Set Login Window TextTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
2500 | Automatic login : Disable automatic login | Medium | Not defined | false |
false |
||
Automatic login : Disable automatic loginTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
2600 | Console : Disable console logon from the logon screen | Medium | Not defined | false |
true |
||
Console : Disable console logon from the logon screenTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
2700 | Remote Login : Disable Remote Login | Not defined | off |
off |
|||
Remote Login : Disable Remote LoginTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
User Preferences |
|||||||
3000 | iCloud : iCloud configuration | High | Not defined | ND |
1 |
||
iCloud : iCloud configurationTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3001 | iCloud : Enable Find my Mac | High | Not defined | 0 |
2 |
||
iCloud : Enable Find my MacTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
3100 | Bluetooth : Disable Bluetooth | Low | Not defined | true |
false |
||
Bluetooth : Disable BluetoothTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3101 | Bluetooth : Show Bluetooth status in menu bar | Low | Not defined | 24 |
18 |
||
Bluetooth : Show Bluetooth status in menu barTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3102 | Bluetooth : Disable Bluetooth Sharing | Low | Not defined | false |
false |
||
Bluetooth : Disable Bluetooth SharingTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3200 | Finder : Show hidden files in Finder | Medium | Not defined | NO |
YES |
||
Finder : Show hidden files in FinderTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3201 | Finder : Display all files extentions | Medium | Not defined | false |
true |
||
Finder : Display all files extentionsTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3202 | Finder : Show status bar | Low | Not defined | false |
true |
||
Finder : Show status barTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3400 | Date and Time : Set time and date automatically | High | Not defined |
|
time.apple.com |
||
Date and Time : Set time and date automaticallyTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
3500 | Sharing : Remote Apple Events | Medium | Not defined | off |
off |
||
Sharing : Remote Apple EventsTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
3501 | Sharing : Internet Sharing | Medium | Not defined | 0 |
0 |
||
Sharing : Internet SharingTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3502 | Sharing : Disable Screen Sharing | Medium | Not defined | disable |
disable |
||
Sharing : Disable Screen SharingTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
3503 | Sharing : Disable File Sharing | Medium | Not defined | disable |
disable |
||
Sharing : Disable File SharingTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
3504 | Sharing : Disable DVD or CD Sharing | Medium | Not defined | disable |
disable |
||
Sharing : Disable DVD or CD SharingTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
3505 | Sharing : Disable Media Sharing | Medium | Not defined | 0 |
0 |
||
Sharing : Disable Media SharingTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3600 | Location : Enable Location Services | Medium | Not defined | disable |
enable |
||
Location : Enable Location ServicesTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
3700 | Diagnostic : Disable sending diagnostic and usage data to Apple | Medium | Not defined |
|
false |
||
Diagnostic : Disable sending diagnostic and usage data to AppleTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3701 | Diagnostic : Share with App Developers | Medium | Not defined |
|
false |
||
Diagnostic : Share with App DevelopersTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
3800 | Advertisements : Limit Ad tracking and personalized Ads | Medium | Not defined |
|
false |
||
Advertisements : Limit Ad tracking and personalized AdsTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
Protections |
|||||||
4000 | Systeme intergrity protection : Enable Systeme intergrity protection | High | Not defined | enable |
enable |
||
Systeme intergrity protection : Enable Systeme intergrity protectionTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
4100 | Gatekeeper : Enable Gatekeeper | High | Not defined | enable |
enable |
||
Gatekeeper : Enable GatekeeperTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
4200 | Secure Keyboard Entry : Enable Secure Keyboard Entry in terminal.app | Medium | Not defined | false |
true |
||
Secure Keyboard Entry : Enable Secure Keyboard Entry in terminal.appTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
Encryption |
|||||||
5000 | FileVault : Enable FileVault | High | Not defined | disable |
enable |
||
FileVault : Enable FileVaultTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
Network |
|||||||
6000 | Firewall : Enable Firewall | High | Not defined | 0 |
1 |
||
Firewall : Enable FirewallTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
6001 | Firewall : Enable logging | Low | Not defined | true |
true |
||
Firewall : Enable loggingTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
6002 | Firewall : Enable Enable Stealth Mode | Medium | Not defined | false |
true |
||
Firewall : Enable Enable Stealth ModeTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
6003 | Firewall : Disable automatic software whitelisting | Medium | Not defined | true |
false |
||
Firewall : Disable automatic software whitelistingTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
6004 | Firewall : Disable automatic signed software whitelisting | Medium | Not defined | true |
false |
||
Firewall : Disable automatic signed software whitelistingTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
6005 | Firewall : Disable captive portal | Medium | Not defined | true |
false |
||
Firewall : Disable captive portalTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |
|||||||
6100 | Remote Management : Disable Remote Management | Medium | Not defined |
|
disable |
||
Remote Management : Disable Remote ManagementTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
6200 | Power Nap : Disable Power Nap | Medium | Not defined | 0 |
0 |
||
Power Nap : Disable Power NapTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
Cache |
|||||||
7000 | Disable Content Caching | Medium | Not defined | deactivate |
deactivate |
||
Disable Content CachingTable of settingsUIXNot defined :
MethodMethod :
ValuesType :
Possible Values :
More Informations |
|||||||
Siri |
|||||||
8000 | Disable Siri | Low | Not defined |
|
false |
||
Disable SiriTable of settingsUIXNot defined :
MethodMethod :
RegistryRegistryPath :
RegistryItem :
ValuesType :
Possible Values :
More Informations |