Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sequoia Release 1.1 #457

Merged
merged 77 commits into from
Dec 16, 2024
Merged

Sequoia Release 1.1 #457

merged 77 commits into from
Dec 16, 2024

Conversation

robertgendler
Copy link
Collaborator

No description provided.

robertgendler and others added 30 commits July 25, 2024 11:20
Initial STIG-IDs added to rule files.
New CCIs added to rules
New SRGs added to stig rules
- os_authenticated_root_enable, updated check
- os_directory_services_configured, removed from stig
- os_ess_installed, removed from stig
- os_firewall_log_enable, removed from 15.x
- os_genmoji_disable, added 800-53 and stig
- os_image_generation_disable, added 800-53 and sti.yaml
- os_iphone_mirroring_disable
- os_password_autofill_disable, added 800-53 and sti
- os_ssh_fips_compliant, fixed check/fix
- os_ssh_server_alive_count_max_configure, fixed fix
- os_ssh_server_alive_interval_configure, fixed fix
- os_sshd_fips_compliant, fixed fix/check
- os_sudo_log_enforce, added 800-53 and stig
- os_writing_tools_disable, added 800-53 and sti
- pwpolicy_custom_regex_enforce, updated regex
- system_settings_ssh_enable, removed from stig
Removed CCI, SRG, STIG ID, and STIG tag
Added STIG ID to
- os_genmoji_disable
- os_image_generation_disable
- os_sudo_log_enforce
- os_writing_tools_disable
removed tags from rules removed from cis
Updated check and fix for ssh and sshd for FIPS
added check into sshd to not fix if proper
Updated ssh fixes to match os_ssh_fips_compliant
golbiga and others added 29 commits October 30, 2024 10:07
remove cis ref & tag from system_settings_improve_search_disable

issue #443
os_world_writable_library_folder_configure

issue# 445
Replaced N/A CCEs for os_mail_summary_disable and os_photos_enhanced_search_disable
pwpolicy_custom_regex_enforce odv hint updated
Removed 800-53 and 800-171 tags

Updated discussion to reflect NIST SP 800-63 and Executive Order M-22-09
Added rules to disable external intelligence features for 15.2
fix[supplemental]: update note about filevault unlock
Updated check to allow greater than ODV.

Issue #451
Added mention of /usr/libexec/reset-ssh-configuration.
@robertgendler robertgendler merged commit 30d4a1a into main Dec 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants