macOS Security Checks
30 checks Pareto Security runs on your Mac
Each check covers a common security misconfiguration on macOS, with links to step-by-step fixes.
| Check | Description | Required in frameworks |
|---|---|---|
| AirDrop is secured | Learn about AirDrop on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| AirPlay receiver is off | Learn about AirPlay Receiver on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| App Store updates are automatic | Learn about App Store Updates and how they should be configured. Aligned with CIS, ISO, NIST, Essentials, SOC compliance frameworks. | CIS ISO NIST CSF Essentials SOC |
| Application updates | Learn about updating apps on macOS. Aligned with CIS, ISO, NIST, Essentials, SOC compliance frameworks. Compatible with the latest macOS. | CIS ISO NIST CSF Essentials SOC |
| Automatic Login is off | Learn about Automatic Login on macOS and how it should be configured. Aligned with CIS, ISO, NIST, Essentials, SOC compliance frameworks. | CIS ISO NIST CSF Essentials SOC |
| Boot is secure | Learn about securing the boot on macOS and how it should be configured. Aligned with CIS, ISO, NIST, Essentials, SOC compliance frameworks. | CIS ISO NIST CSF Essentials SOC |
| File Sharing is off | Learn about File Sharing on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| FileVault is on | Filevault Check on Mac. Aligned with CIS, ISO, NIST, SOC compliance frameworks. Run this check automatically with the free Pareto Security app for macOS. | CIS ISO NIST CSF SOC |
| Firewall is on and configured | Learn about Firewall on macOS and how it should be configured. Aligned with CIS, ISO, NIST, SOC compliance frameworks. Compatible with the latest macOS. | CIS ISO NIST CSF SOC |
| Gatekeeper is on | Learn about Gatekeeper on macOS and how it should be configured. Aligned with CIS, ISO, NIST, Essentials, SOC compliance frameworks. | CIS ISO NIST CSF Essentials SOC |
| Internet Sharing is off | Learn about Internet Sharing on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| macOS updates | Learn about macOS Updates and how they should be configured. Aligned with CIS, ISO, NIST, Essentials, SOC compliance frameworks. | CIS ISO NIST CSF Essentials SOC |
| Media Sharing is off | Learn about Media Sharing on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| No unused user accounts are present | Learn about unused user accounts and how to remove them. Aligned with CIS, ISO, Essentials compliance frameworks. Compatible with the latest macOS. | CIS ISO Essentials |
| Not using Administrator account | Learn about unused why you should not use an administrator account as your primary user. Aligned with CIS, Essentials compliance frameworks. | CIS Essentials |
| Pareto Cloud is receiving reports | Learn how to ensure your device is reporting to Pareto Cloud. Run this check automatically with the free Pareto Security app for macOS. | |
| Pareto Security is up-to-date | Learn about Pareto Security updates. Run this check automatically with the free Pareto Security app for macOS. Compatible with the latest macOS. | |
| Password after inactivity | Learn about Password After Inactivity on macOS and how it should be configured. Aligned with CIS, ISO, NIST, Essentials, SOC compliance frameworks. | CIS ISO NIST CSF Essentials SOC |
| Password hints are off | Learn about Password Hints on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| Password manager is installed | Learn about why you should use password manager. Aligned with NIST, Essentials, SOC compliance frameworks. Compatible with the latest macOS. | NIST CSF Essentials SOC |
| Password to unlock Preferences | Learn about Password to Unlock Preferences on macOS and how it should be configured. Run this check automatically with the free Pareto Security app for macOS. | |
| Printer Sharing is off | Learn about Printer Sharing on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| Remote Login is off | Learn about Remote Login on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| Remote Management is off | Learn about Remote Management on macOS and how it should be configured. Aligned with CIS, Essentials compliance frameworks. Compatible with the latest macOS. | CIS Essentials |
| Screen Saver shows after 20 min | Learn about Screensaver on macOS and how it should be configured. Aligned with CIS, ISO, NIST, SOC compliance frameworks. Compatible with the latest macOS. | CIS ISO NIST CSF SOC |
| SSH keys require a password | Learn about SSH Keys and how they should be protected. Run this check automatically with the free Pareto Security app for macOS. | |
| SSH keys use strong encryption | Verify your SSH keys use strong encryption (RSA 3072+ or Ed25519) to resist brute-forcing. Runs automatically with the free Pareto Security macOS app. | |
| Terminal apps use secure entry | Learn about Terminal app secure keyboard entry. Run this check automatically with the free Pareto Security app for macOS. Compatible with the latest macOS. | |
| Time Machine is on and encrypted | Learn about Time Machine on macOS and how it should be configured. Aligned with CIS, ISO, NIST, Essentials, SOC compliance frameworks. | CIS ISO NIST CSF Essentials SOC |
| WiFi connection is secure | Learn about WiFi security on macOS. Aligned with ISO compliance frameworks. Run this check automatically with the free Pareto Security app for macOS. | ISO |