Skip to content

CIS Benchmarks: Update macOS benchmarks #45644

Description

@noahtalerman

Goal

User story
As an endpoint engineer,
I want Fleet to support the latest macOS 14, 15, and 26 CIS Benchmarks
so that I can be sure I'm using the latest version of the benchmarks to meet compliance needs.

Changes

Product

  • CIS policies changes:
    • Update macOS 14 to cover v3.1.0.
    • Update macOS 15 to cover v2.1.0.
    • Update macOS 26 to cover v1.1.0.
      • @noahtalerman: This link requires the "CIS Benchmarks" shared login in 1Password.
  • UI changes: No changes.
  • CLI (fleetctl) usage changes: No changes.
  • YAML changes: No changes.
  • REST API changes: No changes.
  • Fleet's agent (fleetd) changes: No changes.
  • GitOps mode changes: No changes.
  • Activity changes: No changes.
  • Permissions changes: No changes.
  • Changes to paid features or tiers: Fleet Premium
  • Transparency changes: No changes.
  • First draft of test plan added
  • Other reference documentation changes: TODO: Update respective the READMEs to say the correct versions. For example, for macOS 14:
  • Once shipped, requester has been notified
  • Once shipped, dogfooding issue has been filed

Engineering

  • Test plan is finalized
  • Contributor API changes: TODO
  • Feature guide changes: TODO
  • Database schema migrations: TODO
  • Load testing: TODO

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

QA

Risk assessment

  • Requires load testing: No
  • Risk level: Low
  • Risk description: Risk is limited to the modified queries.

Test plan

Make sure to go through the list and consider all events that might be related to this story, so we catch edge cases earlier.

  • Open the PR that updated the CIS policies for Windows 11. For every policy that changed, run this policy on a Windows workstation and verify that the policy passes and fails when expected.
  • Create and link an Google sheet here of all changed and tested benchmarks.

Testing notes

Confirmation

  1. Engineer: Added comment to user story confirming successful completion of test plan.
  2. QA: Added comment to user story confirming successful completion of test plan.

Metadata

Metadata

Assignees

Labels

#g-supply-chainSupply Chain product groupstoryA user story defining an entire feature

Type

No type

Projects

Status
No status
Status
✔️Awaiting QA

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions