Compliance benchmarks relies on the macOS Security Compliance Project (mSCP), an open-source framework maintained by the National Institute of Standards and Technology (NIST), to define security rules for managed computers. Each rule in the benchmark corresponds to a set of management settings, so the system automatically generates the necessary components to enforce that rule. These components work together to both enforce and monitor compliance status, addressing security requirements ranging from basic system configurations (such as login window settings and service management) to advanced security controls (such as system audit configurations and secure baseline implementations). The rules are regularly updated to align with evolving security standards and best practices for macOS security.
If a device is not compliant, a monitor and enforce enforcement type should automatically bring the device into compliance via a remediation policy, which is created automatically based on the rules set in the benchmark. Remediation policies are automatically configured to trigger upon recurring check-in, so remediation occurs on an ongoing basis. If a device is not compliant after running the remediation policy, further investigation into that device is necessary. You can click on an individual rule to view device-level adherence, which can help in investigating and remediating any failures.
A compliance score is automatically calculated for each benchmark. Every computer has an internal compliance score calculated based on the number of rules that the computer passes. If a computer passes all rules in a given benchmark, its individual compliance score is 100 and it is member of the Compliant smart group. If a computer does not pass all rules, its compliance score is determined by the percentage of rules that it does pass. If a computer is not passing all rules, it is not a member of the Compliant smart group. The overall compliance score for a benchmark is an average compliance score of all of the computers' individual compliance scores.
To view device compliance levels and compliance score for a deployed benchmark, navigate to an enabled benchmark and select the Rule report tab.
To export a rule report in CSV format, navigate to the Rule report tab and click Export rules.
Certain rules do not have an automated check or fix and will not appear in rule reports by design. These rules will still appear in auditing documents if selected in the benchmark configuration.