The 24 Jamf Pro security checks Black Cat runs
Black Cat SSPM evaluates 24 security policies against your Jamf Pro configuration on every scan, classifies each finding by risk, and provides remediation steps. Below is the full list, grouped by category.
encryption
Enforce FileVault disk encryption on all managed Macs
Re-escrow a valid FileVault personal recovery key for the affected Mac
Enable a local account for FileVault unlock on the affected Mac
governance
Review configuration profiles scoped to all computers for blast radius
Review disabled policies that may leave a security gap
Review script-running policies scoped to all computers for blast radius
hardening
Re-enable System Integrity Protection on Macs reporting SIP disabled
Re-enable Gatekeeper to block unsigned applications
Enable the application firewall via a Security configuration profile
Review Macs with Apple Remote Desktop / Screen Sharing enabled
Set a Recovery Lock on Apple silicon Macs to protect recoveryOS
Restore full Secure Boot security on Macs reporting reduced or no security
Make security configuration profiles non-removable by end users
Reduce the access token lifetime for API integrations issuing long-lived tokens
lifecycle
Investigate or retire Macs that have not checked in for 30+ days
Review Macs with Activation Lock enabled to avoid wipe/reuse lockout
Review disabled API integrations that may be stale
management
Bring unsupervised mobile devices under supervision for full management
Re-establish MDM management on mobile devices reporting unmanaged
patching
Update Macs running macOS below the supported major version floor
Update mobile devices running an OS below the supported major version floor
privilege
Review standing local administrator accounts on managed Macs
Review user-triggered Self Service policies that run scripts
Review API roles granting an unusually large number of privileges