Jamf Pro governance & compliance security checks
Policy, ownership, financial and data-quality controls that regulators and auditors expect to see evidenced, not just declared.
On Jamf Pro, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Jamf Pro connector needs.
Checks (3)
severity: info Configuration Profile Scoped To All Computers fix difficulty: easy #
Review configuration profiles scoped to all computers for blast radius
- Confirm the broad scope is intentional for this profile
- Narrow the scope to a smart group if only a subset of computers is needed
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Policy Disabled fix difficulty: easy #
Review disabled policies that may leave a security gap
- Confirm the policy is intentionally disabled
- Re-enable or delete the policy as appropriate
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4
severity: low Policy Scoped To All Computers fix difficulty: easy #
Review script-running policies scoped to all computers for blast radius
- Confirm the broad scope is intentional for this policy
- Narrow the scope to a smart group if only a subset of computers is needed
Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4