Jamf Pro encryption, keys & secrets security checks
Encryption at rest and in transit, key rotation, and the API keys, tokens and credentials that outlive the people who created them.
On Jamf Pro, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Jamf Pro connector needs.
Checks (3)
severity: high Computer FileVault Disabled fix difficulty: medium #
Enforce FileVault disk encryption on all managed Macs
- In Jamf Pro go to Computers > Configuration Profiles and deploy a FileVault payload (or a Disk Encryption configuration)
- Scope the profile to all managed computers
- Confirm individual recovery keys escrow validly in Jamf
- Re-scan to confirm fileVault2Enabled is true
Satisfies: NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: medium Computer FileVault Recovery Key Invalid fix difficulty: medium #
Re-escrow a valid FileVault personal recovery key for the affected Mac
- Issue a Reissue FileVault Recovery Key command from Jamf Pro
- Confirm individualRecoveryKeyValidityStatus reports VALID after re-escrow
Satisfies: NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7
severity: low Local Account FileVault Disabled fix difficulty: medium #
Enable a local account for FileVault unlock on the affected Mac
- Confirm whether the account should be FileVault-enabled
- Add the account to the FileVault-enabled users via a configuration profile or fdesetup
Satisfies: NIS2 Directive NIS2-21.h DORA (SaaS Security) DORA-9.7