~kris/dots

srice

ref: a71a43ca650266b35ee4946352b54d8f7365fda7 srice/doc/networking/government-guides/disa-stigs.md -rw-r--r-- 1.3 KiB
a71a43ca — Kris Yotam profile: export ENV so interactive mksh loads ~/.mkshrc 3 months ago

#DISA STIGs (Security Technical Implementation Guides)

Gold standard for DoD configuration compliance. Machine-readable (SCAP/XCCDF format).

#Downloads

#Key STIGs for Network Security

STIG Covers
Network Infrastructure Router Cisco IOS/IOS XE/IOS XR, Juniper router hardening
Network Infrastructure L2 Switch Port security, VLAN config, DHCP snooping, dynamic ARP inspection
Network Firewall Firewall rule design, policy management, logging
Network WLAN WPA2/WPA3 Enterprise, rogue AP detection
Network VPN VPN gateway config, cipher requirements
Network IDS/IPS IDS/IPS deployment and tuning
Network DNS DNS server hardening, DNSSEC
General Purpose OS (GPOS) Linux/Unix baseline (RHEL, Ubuntu, SUSE, Oracle)
Canonical Ubuntu 24.04 Latest Ubuntu LTS hardening
Cisco ASA ASA firewall-specific config

#Automation

  • OpenSCAP: automated STIG compliance checking
  • SCAP Compliance Checker: DISA's own scanning tool
  • Ansible STIG roles: community-maintained automation for applying STIGs