-
Notifications
You must be signed in to change notification settings - Fork 885
Add username = '' column check on all macOS CIS queries #10602
Copy link
Copy link
Closed
Labels
#g-endpoint-opsEndpoint ops product groupEndpoint ops product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.~backendBackend-related issue.Backend-related issue.~legacy-compliance-grouphttps://fleetdm.com/handbook/company/development-groups#current-product-groupshttps://fleetdm.com/handbook/company/development-groups#current-product-groups
Metadata
Metadata
Assignees
Labels
#g-endpoint-opsEndpoint ops product groupEndpoint ops product group:releaseReady to write code. Scheduled in a release. See "Making changes" in handbook.Ready to write code. Scheduled in a release. See "Making changes" in handbook.~backendBackend-related issue.Backend-related issue.~legacy-compliance-grouphttps://fleetdm.com/handbook/company/development-groups#current-product-groupshttps://fleetdm.com/handbook/company/development-groups#current-product-groups
Type
Fields
Give feedbackNo fields configured for issues without a type.
The
managed_policiestable returns both "device level" settings and "user level" settings."Device level" settings have empty
username. All macOS 13 CIS benchmarks require checking settings at the "device level" (aka "system-wide profiles"). So we should add ausername = ''check on all 80+ macOS queries that usemanaged_policies.This finding stems from the research here: #8119 (comment)
PS: Sample note from the CIS document: