DISA recently released the following updated Security Guidance, Security Readiness Review Scripts, and Benchmarks.
Note: The STIGs converted to NIST SP 800-53 Rev. 5 CCIs in previous quarters have been updated to include the deprecated Rev. 4 CCIs to ensure all vulnerabilities are captured in eMASS.
Unclassified Application STIGs:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security
Apache Server 2.4 Unix STIG
Apache Server 2.4 Windows STIG
Apache Tomcat Application Server 9 STIG – Ver 3, Rel 2
Application Security and Development STIG – Ver 6, Rel 3
Application Server SRG – Ver 4, Rel 3
IBM WebSphere Liberty Server STIG – Ver 2, Rel 2
JBoss Enterprise Application Platform 6.3 STIG – Ver 2, Rel 6
Kubernetes STIG – Ver 2, Rel 3
Microsoft DotNet Framework 4.0 STIG – Ver 2, Rel 6
Microsoft IIS 10.0 STIG
Microsoft Office 365 ProPlus STIG – Ver 3, Rel 3
Microsoft SQL Server 2016 STIG
Oracle Database 12c STIG – Ver 3, Rel 4
Tanium 7.x TanOS STIG
Tanium 7.x STIG – Ver 2, Rel 2
Web Server SRG – Ver 4, Rel 3
Unclassified Mobility STIGs and SRGs:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=mobility
Apple iOS/iPadOS 18 STIG – Ver 1, Rel 3
Unclassified Network STIGs and SRGs:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=network-perimeter-wireless
Arista MLS EOS 4.X STIG
Cisco IOS Router STIG
Cisco IOS Switch STIG
Cisco IOS XE Router STIG
Cisco IOS XE Switch STIG
Cisco IOS XR Router STIG
Cisco NX OS Switch STIG
Infoblox 8.x DNS STIG – Ver 1, Rel 2
Juniper EX Series Switches STIG
Layer 2 Switch SRG – Ver 3, Rel 2
Microsoft Windows Server Domain Name System STIG – Ver 2, Rel 3
Mozilla Firefox STIG – Ver 6, Rel 6
Network Device Management SRG – Ver 5, Rel 3
Palo Alto Networks STIG
Splunk Enterprise 8.x for Linux STIG – Ver 2, Rel 2
Trend Micro TippingPoint STIG
Unclassified Operating System STIGs:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems
Apple macOS 15 (Sequoia) STIG – Ver 1, Rel 3
Canonical Ubuntu 20.04 LTS STIG – Ver 2, Rel 2
Canonical Ubuntu 22.04 LTS STIG – Ver 2, Rel 4
CloudLinux AlmaLinux OS 9 STIG – Ver 1, Rel 2
IBM z/OS STIG
IBM zSecure Suite STIG – Ver 1, Rel 3
Microsoft Windows 10 STIG – Ver 3, Rel 4
Microsoft Windows 11 STIG – Ver 2, Rel 3
Microsoft Windows Server 2019 STIG – Ver 3, Rel 4
Microsoft Windows Server 2022 STIG – Ver 2, Rel 4
Oracle Linux 7 STIG – Ver 3, Rel 2
Oracle Linux 8 STIG – Ver 2, Rel 4
Red Hat Enterprise Linux 8 STIG – Ver 2, Rel 3
Red Hat Enterprise Linux 9 STIG – Ver 2, Rel 4
SUSE Linux Enterprise Server 15 STIG – Ver 2, Rel 4
VMware vSphere 7.0 STIG
VMware vSphere 8.0 STIG
z/OS ACF2 Products
z/OS RACF Products
z/OS SRR Scripts
z/OS TSS Products STIG
Sunset STIGs:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=sunset
Sunset – Microsoft SCOM STIG – Ver 1, Rel 2
Sunset – Tanium 7.0 STIG – Ver 2, Rel 1
Sunset – Tanium 7.3 STIG – Ver 2, Rel 3
Benchmarks:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=scap
Canonical Ubuntu 20.04 LTS STIG SCAP Benchmark – Ver 2, Rel 3
Canonical Ubuntu 22.04 LTS STIG SCAP Benchmark – Ver 2, Rel 2
Kubernetes STIG SCAP Benchmark – Ver 2, Rel 3
Microsoft DotNet Framework 4.0 STIG SCAP Benchmark – Ver 2, Rel 6
Microsoft Office 365 ProPlus STIG SCAP Benchmark – Ver 3, Rel 4
Microsoft Windows 10 STIG SCAP Benchmark – Ver 3, Rel 4
Microsoft Windows 11 STIG SCAP Benchmark – Ver 2, Rel 3
Microsoft Windows Server 2019 STIG SCAP Benchmark – Ver 3, Rel 4
Microsoft Windows Server 2022 STIG SCAP Benchmark – Ver 2, Rel 4
Mozilla Firefox for Linux STIG SCAP Benchmark – Ver 6, Rel 5
Mozilla Firefox for Windows STIG SCAP Benchmark – Ver 6, Rel 6
Oracle Linux 8 STIG SCAP Benchmark – Ver 2, Rel 4
Red Hat Enterprise Linux 8 STIG SCAP Benchmark – Ver 2, Rel 3
Red Hat Enterprise Linux 9 STIG SCAP Benchmark – Ver 2, Rel 4
SUSE Linux Enterprise Server 15 STIG SCAP Benchmark – Ver 2, Rel 4
Supplemental Automation Content:
https://cyber.mil/stigs/supplemental-automation-content/
Oracle Linux 8 STIG for Ansible – Ver 2, Rel 4
Red Hat Enterprise Linux 8 STIG for Ansible – Ver 2, Rel 3
Red Hat Enterprise Linux 9 STIG for Ansible – Ver 2, Rel 4
SUSE Linux Enterprise Server 15 for Ansible – Ver 2, Rel 4
CUI ESS STIGs:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=ess
ESS ePO 5.x STIG – Ver 3, Rel 4
Trellix ENS 10.x STIG – Ver 3, Rel 4