DISA STIG - Defense Information Security Agency Security Technical Implementation Guide

Summary

The United States Defense Information Systems Agency (DISA) publishes Security Technical Implementation Guides (STIGs) as cybersecurity guidelines and best practices. STIGs provide a standard configuration baseline for components of information systems owned by the Department of Defense (DoD) and other federal agencies, supporting these systems in satisfying strict security standards.

STIGs contain technical guidance on how to configure software and applications securely. Guides include settings related to the least functionality, access control, patch management, encryption, and auditing. They also provide recommendations for mitigating specific vulnerabilities, which include reducing the attack surface of systems, and supporting satisfaction of United States Federal Government requirements, such as FIPS-200 and FISMA metrics. DISA works with other DoD entities, industry partners, and cybersecurity experts to develop and maintain these guidelines.

Although STIGs are primarily intended for National Security Systems systems, they are widely used by other federal agencies, contractors, and even private sector organizations within the United States and internationally to enhance their security practices.

The comprehensive list of STIGs is available from DISA on the DoD Cyber Exchange.

Built-in compliance capabilities

Red Hat products have built-in capabilities that help you to align with the DISA STIG policy. By using integrations with the system management solutions available in our portfolio, you can align the configuration of the machine with the requirements. However, the result is not full compliance - you always need to review the results and take the context of your specific deployment into account.

Red Hat Enterprise Linux

To configure RHEL systems, use only the profiles provided in the particular minor release of RHEL. This is because the hardening components and Security Content Automation Protocol (SCAP) content might not be compatible with earlier versions.

RHEL release

Current baseline

10.1

vendor

10.0

vendor

9.7

V2R5

9.6

V2R5

9.4

V2R5

9.2

V2R5

9.0

V2R5

8.10

V2R4

Use the following profile ID to align your RHEL system with DISA STIG: 

xccdf_org.ssgproject.content_profile_stig or 

xccdf_org.ssgproject.content_profile_stig_gui for the Server with GUI package set.

This profile requires a system that is installed in FIPS mode. See the Switching RHEL to FIPS mode chapter in the Security hardening document for more information.

You can install the system already pre-configured to DISA STIG by using RHEL image builder:

Note that this is integrated also in the Red Hat Insights, linked below.

If you prefer a kickstart-based installation, the method is described in the RHEL security guide:

You can build and deploy hardened bootable images pre-configured to DISA STIG for RHEL Image mode:

You can check the system configuration during runtime by using the OpenSCAP command-line tool:

Red Hat Satellite

You can plan and configure compliance policies, deploy the policies to hosts, and monitor the compliance of your hosts in Red Hat Satellite. For more information, see the product documentation:

Red Hat Insights for RHEL

You can create and manage your custom security policies entirely within the compliance service UI, as well as monitor the compliance state of your systems, remediate any discrepancies, and use the custom security policies in image builder to deploy additional systems:

Red Hat OpenShift

You can automate the inspection of numerous technical implementations and compare them against certain aspects of industry standards, benchmarks, and baselines.

Products in Scope

  • Red Hat Enterprise Linux
    • 9
    • 8
    • 7
    • 6
  • Red Hat Ansible Automation Platform
    • 2
  • Red Hat JBoss Enterprise Application Platform
    • 6
    • 5
  • Red Hat OpenShift
    • 4

Additional Resources

Meta Data

Products

Red Hat Enterprise Linux
Red Hat Ansible Automation Platform
Red Hat JBoss Enterprise Application Platform
Red Hat OpenShift

Regions

NA

Industries

Public Sector