- Catalina - Apply Gatekeeper Settings to Block Applications from Unidentified Developers
- Catalina - Configure Audit Failure Notification
- Catalina - Configure Audit Log Files Group to Wheel
- Catalina - Configure Audit Log Files to be Owned by Root
- Catalina - Configure Audit Log Files to Mode 440 or Less Permissive
- Catalina - Configure Audit Log Files to Not Contain Access Control Lists
- Catalina - Configure Audit Log Folder to Not Contain Access Control Lists
- Catalina - Configure Audit Log Folders Group to Wheel
- Catalina - Configure Audit Log Folders to be Owned by Root
- Catalina - Configure Audit Log Folders to Mode 700 or Less Permissive
- Catalina - Configure Gatekeeper to Disallow End User Override
- Catalina - Configure Login Window to Prompt for Username and Password
- Catalina - Configure macOS to Use an Authorized Time Server
- Catalina - Configure SSH ServerAliveInterval option set to 900 or less
- Catalina - Configure System to Audit All Administrative Action Events
- Catalina - Configure System to Audit All Authorization and Authentication Events
- Catalina - Configure System to Audit All Failed Change of Object Attributes
- Catalina - Configure System to Audit All Failed Program Execution on the System
- Catalina - Configure System to Audit All Failed Read Actions on the System
- Catalina - Configure System to Audit All Failed Write Actions on the System
- Catalina - Configure System to Audit All Log In and Log Out Events
- Catalina - Configure System to Shut Down Upon Audit Failure
- Catalina - Configure the System for Nonlocal Maintenance
- Catalina - Configure the System to Block Non-Privileged Users from Executing Privileged Functions
- Catalina - Configure the System to Implement Approved Cryptography to Protect Information
- Catalina - Configure the System to Prevent the Unauthorized Disclosure of Data via Shared Resources
- Catalina - Configure the System to Separate User and System Functionality - separate
- Catalina - Configure User Session Lock When a Smart Token is Removed
- Catalina - Control Connections to Other Systems via a Deny-All and Allow-by-Exception Firewall Policy
- Catalina - Disable Accounts after 35 Days of Inactivity