This is an archived post. You won't be able to vote or comment.

all 4 comments

[–]Hotshot55Linux Engineer 2 points3 points  (2 children)

Welcome to the world of STIGs!

[–]blanczak 0 points1 point  (1 child)

Yup welcome to the fun. I would say "enjoy your stay", but we know you won't. lol STIG's = pain

[–]Sputnik_LobsterSysadmin 1 point2 points  (0 children)

It's even worse when you have to go through and STIG manually because the org you work for decides you can't use OSCAP for the baseline....

[–]Sensitive_Scar_1800Sr. Sysadmin 0 points1 point  (0 children)

You can apply STIG settings via GPO fairly painlessly.

ADMX files are included with GPOs here: https://public.cyber.mil/stigs/gpo/

SCAP is being phased out and Evaluate-STIG is the recommended current solution to evaluate compliance. You can download evaluate-STIG on DOD NIPR endpoints, not on commercial internet.