Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

speak to DISA STIGs #20

Open
afeld opened this issue Jul 12, 2019 · 3 comments
Open

speak to DISA STIGs #20

afeld opened this issue Jul 12, 2019 · 3 comments

Comments

@afeld
Copy link
Member

afeld commented Jul 12, 2019

...and how they relate to controls.

https://public.cyber.mil/stigs/

@afeld
Copy link
Member Author

afeld commented Jul 12, 2019

Should probably also mention the CIS Benchmarks. Is there a generic term for these?

@brasky
Copy link

brasky commented Jul 12, 2019

The generic term for these would probably be configuration baselines or just baselines. The guidance provided by USGCB/STIGs/CIS Benchmarks is what you use to determine your baseline configuration settings.

Different baselines might be prescribed based on the scenario. For FedRAMP in CM-6(a) it prescribes using USGCB if available, then CIS benchmarks. STIGs come into play when you add the DISA SRG

The SRG has a well written overview on page 5 section 1.4.

The thing I do not know and would be curious to learn where the requirement is for agencies and subcontractors. I'm guessing it's in 800-171 3.4.1 where it says to follow NIST 800-128 which says:

Identification of common secure configurations (e.g., FDCC/USGCB, DISA STIGs,
National Checklist Program, etc.) to be used as a basis for establishing approved baseline
configurations for the information system;

But I'd love some correction if I'm totally off base.

@afeld
Copy link
Member Author

afeld commented Jul 12, 2019

Thanks for all of that!

configuration baselines or just baselines

Yeah, the former is better, as there are also control baselines, which are a different thing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants