Lesson 6: Device Compliance - Jamf 170 Course

Jamf 170 Course

Solution
Application
Content Type
Training Content
Utilities & Services
ft:locale
en-US

Goal

Understand the process for creating and implementing a compliance baseline. Explore Jamf Compliance Editor and learn how baselines can be customized for specific organizations.

Video

Key points

  • Device compliance refers to managed computers and mobile devices meeting the security recommendations set forth in a compliance baseline.

  • A security or compliance baseline is a set of recommendations or rules intended to work together to ensure a specific level of security on a device.

  • Jamf Compliance Editor provides a graphical interface for creating, customizing, and exporting security baselines tailored to your organization.

  • Baselines in Jamf Compliance Editor can be customized to your organization's needs.

    • After selecting a benchmark, additional rules can be added to the baseline.

    • Rules that contain organization-defined values (ODVs) can be customized by administrators.

  • Jamf Compliance Editor also creates guidance documentation for generated baselines.

  • To implement and enforce a security baseline, a mobile device management (MDM) solution like Jamf Pro is needed.

  • Compliance status can be monitored in the macOS Security portal under the Compliance section.

    • The Compliance section contains tools to monitor rules from the CIS Level 1 and Level 2 Benchmarks, as well as rules maintained by Jamf.

Review

To view answers, click arrow next to each question.

  1. A device is considered compliant when it meets or exceeds the set level of security recommendations in a managed environment.
  2. Organization-defined values (ODVs) represent a specific setting that can be customized by an administrator to precisely fit the needs of their environment. For example, a password length security recommendation might have an ODV of 8, meaning all passwords need to be at least 8 characters long to be in compliance with that recommendation.
  3. A mobile device management (MDM) solution is needed to deploy the profiles, policies, settings, and scripts to devices in the environment, which in turn enforce the rules set in the security baseline. A security solution, such as Jamf Protect, can then be used to continually monitor the compliance status of devices to ensure they continue to adhere to the recommendations.

Practice

  1. Download, install, and open Jamf Compliance Editor.

    1. Navigate to the Jamf Compliance Editor GitHub repository releases.

    2. Download the PKG containing the latest release.

    3. Open the PKG and follow the prompts to install Jamf Compliance Editor.

  2. Create a new macOS baseline for macOS Sequoia using the CIS Level 1 Benchmark.

    1. Click the Create new project button.

    2. Choose "Sequoia" from the macOS Security Compliance Project branch list.

    3. Choose a baseline directory when prompted; for example, ~/Desktop.

  3. Modify the baseline from Task 2 as follows:

    1. Deselect the 2.3.3.1 Disable DVD Sharing checkbox to remove this rule.

    2. Select the 4.1 Disable Bonjour Multicast checkbox to add this rule.

    3. Select the 5.2.7 Restrict Maximum Password Lifetime to $ODV Days rule and customize it by setting an organization-defined value of 180.

  4. Create the baseline guidance for the modified baseline from Task 3.

    1. Click the Create Guidance button in the lower right.

    2. Provide a name for the tailored benchmark, or press Return for the default name.

    3. Click View Project to open the baseline directory.

  5. Review the created PDF file, locating the rules that were added in Task 3.

    1. In the baseline directory, locate the PDF file containing your baseline title; e.g., CIS_LVL1.pdf.

    2. In the Table of Contents, locate and select the Disable Bonjour Multicast rule to review it.

    3. In the Table of Contents, locate and select the Restrict Maximum Password Lifetime to 180 Days rule to review it.

Resources

Jamf Protect Documentation

Jamf