Lesson 5: Compliance Benchmarks - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Understand and explore compliance benchmarks for macOS and iOS. Learn how compliance recommendations are used to create a compliance baseline for an organization.

Video

Key points

  • Compliance benchmarks are collections of individual security recommendations or rules.

  • Several organizations publish compliance benchmarks, such as the Center for Internet Security (CIS®), the National Institute of Standards and Technology (NIST), and the Defense Information Systems Agency (DISA).

  • CIS publishes the CIS Benchmarks® for a variety of operating systems, applications, and networks.

  • Each recommendation in a CIS Benchmark contains details about a setting and methods to check and change that setting to be compliant with that recommendation.

    • The rationale statement justifies implementing the recommendation.

    • The impact statement details the possible ramifications of implementation.

    • The audit procedure details how administrators can check the status of the relevant setting.

    • The remediation procedure details precisely how to make the change on a device to bring it into compliance with the recommendation.

  • CIS organizes its recommendations into one of two profiles:

    • Level 1 profile: practical security practices that introduce little to no impact to the user's experience

    • Level 2 profile: for organizations where security is of the highest importance; these profiles may restrict a user's experience in favor of tighter security

  • In the macOS Security portal, these recommendations are used to create security rules within a compliance baseline.

Review

To view answers, click arrow next to each question.

  1. An impact statement details the possible ramifications of implementing that recommendation.
  2. The remediation procedure provides step-by-step instructions on how to bring a device into compliance with the recommendation.
  3. Recommendations in the Level 2 profile may restrict a user's experience on a device in favor of more advanced security configurations.

Practice

  1. Obtain the CIS Benchmark for the latest available version of macOS.

  2. In the Benchmark, locate the "2.3.3.3 Ensure File Sharing Is Disabled (Automated)" recommendation.

  3. Follow the audit steps in the recommendation above to determine if your computer is compliant with this recommendation.

    1. Open System Settings.

    2. Select General.

    3. Select Sharing.

    4. Verify that file sharing is not enabled.

Resources

Jamf Protect Documentation

Center for Internet Security