From 30e4b252aa892222bbb9eb637bcdadeac9dbdfe5 Mon Sep 17 00:00:00 2001 From: Dave Herder <27025660+dherder@users.noreply.github.com> Date: Wed, 12 Jun 2024 08:19:51 -0700 Subject: [PATCH] adding a subset of cis benchmarks policies to canary workstations team (#19572) Co-authored-by: Luke Heath --- it-and-security/lib/macos-cis.policies.yml | 105 +++++++++++++++++++ it-and-security/lib/windows-cis.policies.yml | 58 ++++++++++ it-and-security/teams/workstations.yml | 4 +- 3 files changed, 166 insertions(+), 1 deletion(-) create mode 100644 it-and-security/lib/macos-cis.policies.yml create mode 100644 it-and-security/lib/windows-cis.policies.yml diff --git a/it-and-security/lib/macos-cis.policies.yml b/it-and-security/lib/macos-cis.policies.yml new file mode 100644 index 0000000000..71cd37efb8 --- /dev/null +++ b/it-and-security/lib/macos-cis.policies.yml @@ -0,0 +1,105 @@ +- name: CIS - Ensure Auto Update Is Enabled (MDM Required) + critical: false + platform: darwin + description: Checks that the system is configured via MDM to automatically install updates. + resolution: "Ask your system administrator to deploy an MDM profile that enables automatic updates." + query: | + SELECT 1 WHERE + EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='AutomaticCheckEnabled' AND + (value = 1 OR value = 'true') AND + username = '' + ) + AND NOT EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='AutomaticCheckEnabled' AND + (value != 1 AND value != 'true') + ); +- name: CIS - Ensure Download New Updates When Available Is Enabled (MDM Required) + critical: false + platform: darwin + description: Checks that the system is configured via MDM to automatically download updates. + resolution: "Ask your system administrator to deploy an MDM profile that enables automatic update downloads." + query: | + SELECT 1 WHERE + EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='AutomaticDownload' AND + (value = 1 OR value = 'true') AND + username = '' + ) + AND NOT EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='AutomaticDownload' AND + (value != 1 AND value != 'true') + ); +- name: CIS - Ensure Install of macOS Updates Is Enabled (MDM Required) + critical: false + platform: darwin + description: Ensure that macOS updates are installed after they are available from Apple. + resolution: "Ask your system administrator to deploy an MDM profile that enables automatic install of macOS updates." + query: | + SELECT 1 WHERE + EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='AutomaticallyInstallMacOSUpdates' AND + (value = 1 OR value = 'true') AND + username = '' + ) + AND NOT EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='AutomaticallyInstallMacOSUpdates' AND + (value != 1 AND value != 'true') + ); +- name: CIS - Ensure Install Application Updates from the App Store Is Enabled (MDM Required) + critical: false + platform: darwin + description: Ensure that application updates are installed after they are available from Apple. + resolution: Ask your system administrator to deploy an MDM profile that enables automatic updates of Apple apps. + query: | + SELECT 1 WHERE + EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='AutomaticallyInstallAppUpdates' AND + (value = 1 OR value = 'true') AND + username = '' + ) + AND NOT EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='AutomaticallyInstallAppUpdates' AND + (value != 1 AND value != 'true') + ); + +- name: CIS - Ensure Install Security Responses and System Files Is Enabled (MDM Required) + critical: false + platform: darwin + description: | + Ensure that system and security updates are installed after they are available from + Apple. This setting enables definition updates for XProtect and Gatekeeper. With this + setting in place, new malware and adware that Apple has added to the list of malware or + untrusted software will not execute. + resolution: "Ask your system administrator to deploy an MDM profile that enables automatic critical system and security updates." + query: | + SELECT 1 WHERE + EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='CriticalUpdateInstall' AND + (value = 1 OR value = 'true') AND + username = '' + ) + AND NOT EXISTS ( + SELECT 1 FROM managed_policies WHERE + domain='com.apple.SoftwareUpdate' AND + name='CriticalUpdateInstall' AND + (value != 1 AND value != 'true') + ); diff --git a/it-and-security/lib/windows-cis.policies.yml b/it-and-security/lib/windows-cis.policies.yml new file mode 100644 index 0000000000..acb8ec3f13 --- /dev/null +++ b/it-and-security/lib/windows-cis.policies.yml @@ -0,0 +1,58 @@ +- name: CIS - Ensure 'Enforce password history' is set to '24' or more passwords + critical: false + platform: windows + description: | + This policy check determines the number of renewed, unique passwords that have to be associated with a user account before you can reuse an old password. + resolution: | + Automatic method: + Ask your system administrator to establish the recommended configuration via GP, set the following UI path to 24 or more passwords: + 'Computer Configuration\Policies\Windows Settings\Security Settings\Account Policies\Password Policy\Enforce password history' + query: | + SELECT 1 FROM security_profile_info WHERE password_history_size >= 24; +- name: CIS - Ensure 'Maximum password age' is set to '365 or fewer days, but not 0' + critical: false + platform: windows + description: | + This policy setting defines how long a user can use their password before it expires. + resolution: | + Automatic method: + Ask your system administrator to establish the recommended configuration via GP, set the following UI path to 365 or fewer days, but not 0: + 'Computer Configuration\Policies\Windows Settings\Security Settings\Account Policies\Password Policy\Maximum password age' + query: | + SELECT 1 FROM security_profile_info WHERE (maximum_password_age <= 365 AND maximum_password_age != 0); +- name: CIS - Ensure 'Minimum password age' is set to '1 or more days' + critical: false + platform: windows + description: | + This policy setting determines the number of days that you must use a password before you can + change it. The range of values for this policy setting is between 1 and 999 days. + resolution: | + Automatic method: + Ask your system administrator to establish the recommended configuration via GP, set the following UI path to 1 or more days: + 'Computer Configuration\Policies\Windows Settings\Security Settings\Account Policies\Password Policy\Minimum password age' + query: | + SELECT 1 FROM security_profile_info WHERE minimum_password_age >= 1; +- name: CIS - Ensure 'Minimum password length' is set to '14 or more characters' + critical: false + platform: windows + description: | + This policy setting determines the least number of characters that make up a password for a user account. + resolution: | + Automatic method: + Ask your system administrator to establish the recommended configuration via GP, set the following UI path to 14 or more characters + 'Computer Configuration\Policies\Windows Settings\Security Settings\Account Policies\Password Policy\Minimum password length' + query: | + SELECT 1 FROM security_profile_info WHERE minimum_password_length >= 14; +- name: CIS - Ensure 'Password must meet complexity requirements' is set to 'Enabled' + critical: false + platform: windows + description: | + This policy setting checks all new passwords to ensure that they meet basic requirements for + strong passwords. Passwords that contain only alphanumeric characters are extremely easy to + discover with several publicly available tools. + resolution: | + Automatic method: + Ask your system administrator to establish the recommended configuration via GP, set the following UI path to 'Enabled': + 'Computer Configuration\Policies\Windows Settings\Security Settings\Account Policies\Password Policy\Password must meet complexity requirements' + query: | + SELECT 1 FROM security_profile_info WHERE password_complexity = 1; diff --git a/it-and-security/teams/workstations.yml b/it-and-security/teams/workstations.yml index 6e28a28f6f..ee8d50e96c 100644 --- a/it-and-security/teams/workstations.yml +++ b/it-and-security/teams/workstations.yml @@ -61,8 +61,10 @@ policies: - path: ../lib/macos-device-health.policies.yml - path: ../lib/windows-device-health.policies.yml - path: ../lib/linux-device-health.policies.yml + - path: ../lib/macos-cis.policies.yml + - path: ../lib/windows-cis.policies.yml - name: macOS - Check if latest version - query: SELECT 1 FROM os_version WHERE major = '14' AND minor = '5'; + query: SELECT 1 FROM os_version WHERE major = '14' OR major = '15'; critical: false description: Using an outdated macOS version risks exposure to security vulnerabilities and potential system instability. resolution: We will update your macOS to the latest version.