This release refines the default personal baseline after an end-to-end review on a personally administered Mac. It reduces organization-specific noise, checks more effective local state, and fixes result-contract mismatches that could misclassify a passing check as a finding.
Highlights
- Excludes traditional
auditd, forensic logging, global CIS password-policy, fixed organization time-server, and selected privacy-choice controls from the default personal scope. - Uses effective local state for App Store updates, Terminal Secure Keyboard Entry, Bluetooth Sharing, password hints, Remote Apple Events, and SMB.
- Accepts Firewall Block All as enabled and checks screen locking in the active user's context.
- Accepts a sudo credential-cache timeout from zero through two minutes.
- Validates mSCP numeric result contracts to prevent false findings.
The personal profile remains a security-posture audit, not a CIS Benchmark assessment. Excluded rules are outside scope, not passes.
Validation
Shell syntax, interface tests, full preparation smoke testing, signed archive verification, and an authorized read-only macOS 26 Apple Silicon audit passed. The audit completed with 48 applicable checks passed, zero findings, and one architecture-appropriate N/A for Power Nap.