Skip to content

Reference

macOS security glossary

Short, accurate definitions of the Apple platform security terms used across the guides.

Configuration Profile
A configuration profile is an XML property list (.mobileconfig) that delivers settings, restrictions and certificates to Apple devices.
Endpoint Security Framework
Endpoint Security is the macOS API that lets approved security tools monitor and authorize process, file and system events in user space.
FileVault
FileVault is the macOS full-volume encryption feature that ties access to a Mac's data volume to user credentials and a recovery key.
Gatekeeper
Gatekeeper is the macOS mechanism that checks downloaded apps for a valid Developer ID signature and notarization before they run.
Lockdown Mode
Lockdown Mode is an optional Apple protection for people facing targeted spyware, restricting features that attackers commonly exploit.
MDM (Mobile Device Management)
MDM is Apple's device management protocol that lets organizations enroll Macs and remotely deliver profiles, commands, apps and updates.
Notarization
Notarization is Apple's automated scan of Developer ID-signed software, producing a ticket that Gatekeeper checks before an app runs.
Secure Enclave
The Secure Enclave is an isolated security subsystem in Apple chips that protects keys, biometric data and FileVault secrets from the main OS.
Signed System Volume (SSV)
The Signed System Volume is a cryptographically sealed, read-only macOS system volume whose integrity is verified against an Apple signature.
System Integrity Protection (SIP)
System Integrity Protection is a macOS security layer that stops even the root user from modifying protected system files and processes.
TCC (Transparency, Consent, and Control)
TCC is the macOS privacy framework that makes apps request user consent before accessing protected data, devices and system capabilities.
XProtect
XProtect is the built-in, signature-based anti-malware technology in macOS, updated by Apple independently of regular OS releases.