17 hours ago
Hi Jamf Nation,
we're thrilled to announce that compliance benchmarks capability in Jamf Pro is now generally available! This release transforms how your organization manage compliance across Apple devices, making compliance validation and enforcement simpler than ever before.
Benefits
At the heart of this new capability is a streamlined approach to security compliance:
Why it matters
Getting started
After ensuring your Jamf Pro instance is upgraded to 11.16 and has SSO in Jamf Account enabled, you'll find the compliance benchmarks under the Compliance page in your sidebar. Creating your first compliance benchmark is remarkably straightforward:
For detailed setup instructions and best practices, visit our documentation portal for more details.
Considerations
Upcoming features
We're listening to your feedback and are actively working to make compliance benchmarks even better. We're excited to share some features we're considering and developing, though we want to be transparent that these plans may evolve:
Rule Reporting
Device-level compliance status reporting on each rule provides detailed visibility into individual device compliance states, enabling targeted remediation efforts and simplified compliance management.
Exports
Sharing of comprehensive compliance status data with stakeholders and auditors, supporting compliance verification and reporting requirements.
Editing
Post-creation editing of compliance benchmark configurations will enable flexible adjustments to scoping and enforcement modes, ensuring benchmarks can adapt to changing organizational needs.
mSCP Updates
Streamlining the adoption of new compliance benchmark definitions, particularly during major macOS releases, reducing the administrative overhead of maintaining compliance standards.
Share Your Experience
Your feedback is crucial in shaping the future of compliance benchmarks. We encourage you to share your experiences and suggestions through multiple channels:
16 hours ago
Any plans to implement any of the other rules such as DISA Stig?
16 hours ago
Hi @Jason33 .
Yes, we are planning to iteratively implement all rules. Specifically NIST 800-53, DISA STIG and CNSSI 1253 later this year.
16 hours ago
Sounds good (I completely missed that sentence above). Are these ever going to be available for all environments?
15 hours ago
We have no current plan to extend these features to these environments.
Jamf Cloud’s architecture allows us to be more agile in delivering new features and updates to customers, enabling faster, more iterative rollouts, including those powered by Apple’s Declarative Device Management. We are continuously evaluating the needs of our customers and exploring ways to provide services that meet the security requirements of high-compliance environments for customers in cloud environments. We appreciate your understanding as we continue to improve and expand our solutions.
16 hours ago
Any plans for existing rule detection (uploaded via Jamf Compliance Editor)? 😊
16 hours ago
Hi @Jordy-Thery .
Currently we do not plan to add any automated rule detection. The recommended approach is to iteratively migrate from rules added manually to rules managed by compliance benchmarks. You can e.g.
We think, this approach adds minimal risk to your operation even though it is manual. Would this work for you?
16 hours ago
Thanks, Tomas!
12 hours ago
Hi @Jordy-Thery
another thing that might help is creating a benchmark that includes all rules in monitor only mode. This will give you a continuous overview of the compliance status while not pushing any configuration. You can then observe the effect of any changes you make, taking the approach Tomas suggested (have another benchmark in enforce mode where you gradually add rules - these two benchmarks can live next to each other with no issues).
Looking forward to hear about your experience with the new capability!