Goal
Configure the compliance baseline and analytic set that make up the default plan in the macOS Security portal. Deploy the plan to computers.
Video
Key points
-
Plans determine what to log, where to send data, and how the Jamf Protect agent responds to threats when detected.
- Plans are made up of multiple components within the macOS Security portal, including compliance baseline reporting, action configurations, and analytic sets.
- The compliance baseline is composed of recommended security settings called rules.
-
Most rules correspond with profiles in the CIS Benchmarks®.
-
Reporting can be turned on or off for each compliance rule individually or altogether within a plan.
-
-
Analytics are used by the Jamf Protect agent to detect suspicious behavior and malicious activity on computers.
-
Many analytics are associated with techniques in the MITRE ATT&CK® Matrix.
-
Analytic sets are groups of one or more analytics that can be applied to a plan.
-
-
Action configurations determine the amount of data collected and where it is stored.
-
A plan can only contain one action configuration.
-
-
Plans are comprehensive security configurations that are deployed to computers as configuration profiles.
-
Any changes made to a plan must be downloaded and deployed as a new configuration profile.
-
Changes to a component included in a plan do not require a new configuration profile to be deployed.
-
-
Automatic updates for the Jamf Protect agent can be turned on in a plan.
-
Jamf Pro can be connected to the Jamf Protect Cloud to automatically sync plans for deployment.
-
Once connected, Jamf Pro can also perform the initial deployment of the Jamf Protect package on computers in the scope of a plan configuration profile.
-
-
Successful deployment can be confirmed on a managed computer using one of the following methods:
-
Check for the plan configuration profile in .
-
Enter the command
protectctl versionin Terminal to verify the Jamf Protect agent is installed.
-
-
Multiple plans can be created, but each computer should only have a single plan.
-
More than one plan on a computer can cause undesired behaviors and issues with communication.
-
Review
To view answers, click arrow next to each question.
Practice
-
Review the System Integrity Protection (SIP) Enabled rule.
-
Navigate to .
-
Click the System Integrity Protection (SIP) Enabled rule.
-
Read its description.
-
-
Review the Suspicious Office Activity analytic.
-
Navigate to .
-
Click the disclosure triangle to expand the Common Attacker Technique category.
-
Click the Suspicious Office Activity analytic.
-
Read its summary.
-
-
Review the Default plan.
-
Navigate to Plans.
-
Click the Default plan to review it, but do not make any changes.
-
Resources
Jamf Protect Documentation