Goal
Understand the process for creating and implementing a compliance baseline. Explore Jamf Compliance Editor and learn how baselines can be customized for specific organizations.
Video
Key points
-
Device compliance refers to managed computers and mobile devices meeting the security recommendations set forth in a compliance baseline.
-
A security or compliance baseline is a set of recommendations or rules intended to work together to ensure a specific level of security on a device.
-
Jamf Compliance Editor provides a graphical interface for creating, customizing, and exporting security baselines tailored to your organization.
-
Baselines in Jamf Compliance Editor can be customized to your organization's needs.
-
After selecting a benchmark, additional rules can be added to the baseline.
-
Rules that contain organization-defined values (ODVs) can be customized by administrators.
-
-
Jamf Compliance Editor also creates guidance documentation for generated baselines.
-
To implement and enforce a security baseline, a mobile device management (MDM) solution like Jamf Pro is needed.
-
For a full walk-through of deployment, see the Jamf Compliance Editor User Guide.
-
-
Compliance status can be monitored in the macOS Security portal under the Compliance section.
-
The Compliance section contains tools to monitor rules from the CIS Level 1 and Level 2 Benchmarks, as well as rules maintained by Jamf.
-
Review
To view answers, click arrow next to each question.
Practice
-
Download, install, and open Jamf Compliance Editor.
-
Navigate to the Jamf Compliance Editor GitHub repository releases.
-
Download the PKG containing the latest release.
-
Open the PKG and follow the prompts to install Jamf Compliance Editor.
-
-
Create a new macOS baseline for macOS Sequoia using the CIS Level 1 Benchmark.
-
Click the Create new project button.
-
Choose from the macOS Security Compliance Project branch list.
-
Choose a baseline directory when prompted; for example, ~/Desktop.
-
-
Modify the baseline from Task 2 as follows:
-
Deselect the 2.3.3.1 Disable DVD Sharing checkbox to remove this rule.
-
Select the 4.1 Disable Bonjour Multicast checkbox to add this rule.
-
Select the 5.2.7 Restrict Maximum Password Lifetime to $ODV Days rule and customize it by setting an organization-defined value of 180.
-
-
Create the baseline guidance for the modified baseline from Task 3.
-
Click the Create Guidance button in the lower right.
-
Provide a name for the tailored benchmark, or press Return for the default name.
-
Click View Project to open the baseline directory.
-
-
Review the created PDF file, locating the rules that were added in Task 3.
-
In the baseline directory, locate the PDF file containing your baseline title; e.g., CIS_LVL1.pdf.
-
In the Table of Contents, locate and select the Disable Bonjour Multicast rule to review it.
-
In the Table of Contents, locate and select the Restrict Maximum Password Lifetime to 180 Days rule to review it.
-
Resources
Jamf Protect Documentation
Jamf