diff --git a/ee/cis/macos-13/cis-policy-queries.yml b/ee/cis/macos-13/cis-policy-queries.yml
index aeb0080e8b..a817f3be44 100644
--- a/ee/cis/macos-13/cis-policy-queries.yml
+++ b/ee/cis/macos-13/cis-policy-queries.yml
@@ -2075,4 +2075,28 @@ spec:
AND value = 1;
purpose: Informational
tags: compliance, CIS, CIS_Level1, CIS6.3.7
- contributors: sharon-fdm
\ No newline at end of file
+ contributors: sharon-fdm
+---
+ apiVersion: v1
+ kind: policy
+ spec:
+ name: CIS - Ensure Secure Keyboard Entry Terminal.app Is Enabled (MDM Required)
+ platforms: macOS
+ platform: darwin
+ description: |
+ Secure Keyboard Entry prevents other applications on the system and/or network from detecting and recording what is typed into Terminal. Unauthorized applications and malicious code could intercept keystrokes entered in the Terminal.
+ Enabling Secure Keyboard Entry minimizes the risk of a key logger from detecting what is entered in Terminal.
+ resolution: |
+ Profile Method:
+ Create or edit a configuration profile with the following information:
+ 1. The PayloadType string is com.apple.Terminal
+ 2. The key to include is SecureKeyboardEntry
+ 3. The key must be set to
+
+ query: |
+ SELECT 1 from managed_policies WHERE domain = 'com.apple.Terminal'
+ AND name = 'SecureKeyboardEntry'
+ AND value == 1;
+ purpose: Informational
+ tags: compliance, CIS, CIS_Level1, CIS6.4.1
+ contributors: sharon-fdm
\ No newline at end of file
diff --git a/ee/cis/macos-13/test/profiles/6.4.1.mobileconfig b/ee/cis/macos-13/test/profiles/6.4.1.mobileconfig
new file mode 100644
index 0000000000..9aca882491
--- /dev/null
+++ b/ee/cis/macos-13/test/profiles/6.4.1.mobileconfig
@@ -0,0 +1,37 @@
+
+
+
+
+ PayloadContent
+
+
+ PayloadDisplayName
+ test
+ PayloadType
+ com.apple.Terminal
+ PayloadIdentifier
+ com.fleetdm.cis-6.4.1.check
+ PayloadUUID
+ E8D36749-D7F8-4280-9B17-D6224B67B63B
+ SecureKeyboardEntry
+
+
+
+ PayloadDescription
+ test
+ PayloadDisplayName
+ Ensure Secure Keyboard Entry Terminal.app Is Enabled
+ PayloadIdentifier
+ com.fleetdm.cis-6.4.1
+ PayloadRemovalDisallowed
+
+ PayloadScope
+ System
+ PayloadType
+ Configuration
+ PayloadUUID
+ D4C0B4CC-D39A-4F0F-AF8A-AB5A73D02B3F
+ PayloadVersion
+ 1
+
+