General Cyber Exchange Announcements

Supplemental Automation Content has been updated for July 2020

This content leverages Configuration Management tools to enforce STIG requirements. These tools allow for customization and use a STIG-centric approach.

The Supplemental Automation Content can be found on the Cyber Exchange website on the Supplemental Automation Content tab located at:
https://cyber.mil/stigs/supplemental-automation-content/

For users who do not have a CAC that has DoD Certificates, the Supplemental Automation Content is also available from:
https://public.cyber.mil/stigs/supplemental-automation-content/

McAfee Home Use Solutions

McAfee has announced a “Work from Home (WFH)” program that provides free access to their Total Protection solution for 60-days. Under McAfee WFH, anyone can download their premier anti-virus and secure virtual private networking solutions to better protect their systems in response to the heightened mission need to support telework requirements. Click here to learn more about McAfee’s corporate Work from Home program.

The DoD Home Use program provides an annual subscription to McAfee’s Internet Security product for approved DoD employees via this website: https://www.disa.mil/Cybersecurity/Network-Defense/Antivirus/Home-Use.

SRGs/STIGs Announcements

DISA releases revised Microsoft Windows STIGs

The Defense Information Systems Agency has released the following out-of-cycle Security Technical Implementation Guide (STIG) and benchmark updates, which become effective immediately upon release:

Microsoft Defender Antivirus STIG – Ver 2, Rel 4
Microsoft Windows 10 STIG – Ver 2, Rel 4
Microsoft Windows 2012 and 2012 R2 DC STIG – Ver 3, Rel 4
Microsoft Windows 2012 and 2012 R2 MS STIG – Ver 3, Rel 4
Microsoft Windows 2012 Server Domain Name System (DNS) STIG – Ver 2, Rel 5
Microsoft Windows Privileged Access Workstation (PAW) STIG – Ver 2, Rel 2
Microsoft Windows Server 2016 STIG – Ver 2, Rel 4
Microsoft Windows Server 2019 STIG – Ver 2, Rel 4

Microsoft Defender Antivirus STIG Benchmark – Ver 2, Rel 3
Microsoft Windows 10 STIG Benchmark – Ver 2, Rel 4
Microsoft Windows Server 2012 and 2012 R2 DC STIG Benchmark – Ver 3, Rel 3
Microsoft Windows Server 2012 and 2012 R2 MS STIG Benchmark – Ver 3, Rel 3
Microsoft Windows Server 2016 STIG Benchmark – Ver 2, Rel 2
Microsoft Windows Server 2019 STIG Benchmark – Ver 2, Rel 2

The Group Policy Objects file also reflects these STIG updates.

Customers who possess a Common Access Card (CAC) that has valid Department of Defense (DOD) certificates can obtain the files from the DOD Cyber Exchange website at https://cyber.mil/stigs/downloads/. The files are also available on the Cyber Exchange public site at https://public.cyber.mil/stigs/downloads/.

Users who are unable to find and download the files can report their issue to the Cyber Exchange web team at dod.cyberexchange@mail.mil. Individuals who have further questions related to STIG content should email the DISA STIG customer support desk at disa.stig_spt@mail.mil.

DISA releases the Oracle Linux 8 STIG SCAP benchmark

The Defense Information Systems Agency recently released the automated benchmark for the Oracle Linux 8 Security Technical Implementation Guide (STIG) Security Content Automation Protocol (SCAP) benchmark, which is effective immediately upon release.

Customers who possess a Common Access Card (CAC) that has valid Department of Defense (DOD) certificates can obtain the benchmark from the DOD Cyber Exchange website at https://cyber.mil/stigs/downloads/. The benchmark is also available on the Cyber Exchange public site at https://public.cyber.mil/stigs/downloads/.

Users who are unable to find and download the benchmark or other content can report their issue to the Cyber Exchange web team at dod.cyberexchange@mail.mil. Individuals who have further questions related to STIG content should email the DISA STIG customer support desk at disa.stig_spt@mail.mil.

DISA has released updates to the SRG/STIG Library Compilations

These updates include the latest quarterly SRG/STIG update and newly released SRGs and STIGs published since the last quarterly update.

GPO Update

Group Policy Objects (GPOs) have been updated for April 2022. See the Change Log document included in the zip file for additional information.

DISA Risk Management Executive posted the GPOs for use by system administrators to ease the burden in securing systems within their environment.

The GPOs can be found on Cyber Exchange website on the Group Policy Objects tab located at https://cyber.mil/stigs/gpo/. For users who do not have a CAC that has DOD certificates, the GPO is also available from https://public.cyber.mil/stigs/gpo/.

List of GPOs currently in the package:

Office Products
Access 2013
Access 2016
Excel 2013
Excel 2016
InfoPath 2013
Lync 2013
Office System 2013
Office System 2016
Office 2019-MS 365 Apps
OneDrive for Business 2016
Outlook 2013
Outlook 2016
PowerPoint 2013
PowerPoint 2016
Project 2013
Project 2016
Publisher 2013
Publisher 2016
Visio 2013
Visio 2016
Word 2013
Word 2016

Browsers
Google Chrome
Internet Explorer 11
MS Edge

Antivirus
Windows Defender AV

Adobe Acrobat
Adobe Acrobat Pro DC Continuous
Adobe Acrobat Reader DC Continuous

Operating Systems
Windows 8 and 8.1
Windows 10
Windows Firewall
Windows 2012 R2 DC
Windows 2012 R2 MS
Windows Server 2016 (MS and DC)
Windows Server 2019 (MS and DC)

DISA releases the following updated Security Guidance, Security Readiness Review Scripts, Supplemental Automation Content, and Benchmarks

Unclassified Application STIGs:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security
https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=app-security

Google Chrome STIG – Ver 2, Rel 6
Kubernetes STIG – Ver 1, Rel 5
Microsoft Office 365 ProPlus STIG – Ver 2, Rel 5
Microsoft Outlook 2016 STIG – Ver 2, Rel 3
Microsoft SharePoint 2013 STIG – Ver 2, Rel 3
MongoDB Enterprise Advanced 3.x STIG – Ver 2, Rel 1
Mozilla Firefox STIG – Ver 6, Rel 2
MS SQL Server 2016 STIG
Oracle Database 12c STIG – Ver 2, Rel 4
Google Chrome STIG – Ver 2, Rel 6
Kubernetes STIG – Ver 1, Rel 5
Microsoft Office 365 ProPlus STIG – Ver 2, Rel 5
Microsoft Outlook 2016 STIG – Ver 2, Rel 3
Microsoft SharePoint 2013 STIG – Ver 2, Rel 3
MongoDB Enterprise Advanced 3.x STIG – Ver 2, Rel 1
Mozilla Firefox STIG – Ver 6, Rel 2
MS SQL Server 2016 STIG
Oracle Database 12c STIG – Ver 2, Rel 4

Unclassified Network STIGs and SRGs:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=network-perimeter-wireless
https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=network-perimeter-wireless

Cisco ASA Firewall STIG
Cisco IOS-XE Router STIG
Cisco ISE STIG
Firewall SRG – Ver 2, Rel 2
Juniper Router STIG
Network Infrastructure Policy STIG – Ver 10, Rel 2
Network WLAN STIG
Palo Alto Networks STIG
Splunk Enterprise 8.0 for Linux STIG – Ver 1, Rel 2
Cisco ASA Firewall STIG
Cisco IOS-XE Router RTR STIG
Cisco ISE STIG
Firewall SRG – Ver 2, Rel 2
Juniper Router STIG
Network Infrastructure Policy STIG – Ver 10, Rel 2
Network WLAN STIG
Palo Alto Networks STIG
Splunk Enterprise 8.0 for Linux STIG – Ver 1, Rel 2

Unclassified Operating System STIGs and Overviews:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems
https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems

Apple macOS 11 (Big Sur) STIG – Ver 1, Rel 6
Apple macOS 12 STIG – Ver 1, Rel 2
Apple macOS 10.15 STIG – Ver 1, Rel 8
Canonical Ubuntu 18.04 LTS STIG – Ver 2, Rel 7
Canonical Ubuntu 20.04 LTS STIG – Ver 1, Rel 4
General Purpose Operating System SRG – Ver 2, Rel 3
IBM AIX 7.x STIG – Ver 2, Rel 5
IBM z/OS STIG
Oracle Linux 7 STIG – Ver 2, Rel 7
Oracle Linux 8 STIG – Ver 1, Rel 2
Red Hat Enterprise Linux 7 STIG – Ver 3, Rel 7
Red Hat Enterprise Linux 8 STIG – Ver 1, Rel 6
SUSE Linux Enterprise Server (SLES) 15 STIG – Ver 1, Rel 6
VMware vSphere 6.7 STIG
z/OS ACF2 Products – Ver 6, Rel 53
z/OS RACF Products – Ver 6, Rel 53
z/OS TSS Products – Ver 6, Rel 53
z/OS SRR Scripts – Ver 6, Rel 53
Apple macOS 11 (Big Sur) STIG – Ver 1, Rel 6
Apple macOS 12 STIG – Ver 1, Rel 2
Apple macOS 10.15 STIG – Ver 1, Rel 8
Canonical Ubuntu 18.04 LTS STIG – Ver 2, Rel 7
Canonical Ubuntu 20.04 LTS STIG – Ver 1, Rel 4
General Purpose Operating System SRG – Ver 2, Rel 3
IBM AIX 7.x STIG – Ver 2, Rel 5
IBM z/OS STIG
Oracle Linux 7 STIG – Ver 2, Rel 7
Oracle Linux 8 STIG – Ver 1, Rel 2
Red Hat Enterprise Linux 7 STIG – Ver 3, Rel 7
Red Hat Enterprise Linux 8 STIG – Ver 1, Rel 6
SUSE Linux Enterprise Server (SLES) 15 STIG – Ver 1, Rel 6
VMware vSphere 6.7 STIG
z/OS ACF2 Products – Ver 6, Rel 53
z/OS RACF Products – Ver 6, Rel 53

Supplemental Automation Content:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=supplemental-automation-content
https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=supplemental-automation-content

Canonical Ubuntu 18.04 LTS STIG for Ansible – Ver 2, Rel 7
Canonical Ubuntu 20.04 LTS STIG for Ansible – Ver1, Rel 4
Red Hat Enterprise Linux 7 STIG for Ansible – Ver 3, Rel 7
Red Hat Enterprise Linux 7 STIG for Chef – Ver 3, Rel 7
Red Hat Enterprise Linux 8 STIG for Ansible – Ver 1, Rel 6
Canonical Ubuntu 18.04 LTS STIG for Ansible – Ver 2, Rel 7
Canonical Ubuntu 20.04 LTS STIG for Ansible – Ver1, Rel 4
Red Hat Enterprise Linux 7 STIG for Ansible – Ver 3, Rel 7
Red Hat Enterprise Linux 7 STIG for Chef – Ver 3, Rel 7

Sunset:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=sunset
https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=sunset

Apple macOS 10.13 STIG – Ver 2, Rel 5
Apple macOS 10.14 STIG – Ver 2, Rel 6
Enclave Test and Development STIG – Ver 1, Rel 6

Benchmarks:
https://cyber.mil/stigs/downloads/?_dl_facet_stigs=scap
https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=scap

Canonical Ubuntu 18.04 LTS STIG Benchmark – Ver 2, Rel 6
Canonical Ubuntu 20.04 LTS STIG Benchmark – Ver 1, Rel 2
Google Chrome STIG Benchmark – Ver 2, Rel 6
Oracle Linux 7 STIG Benchmark – Ver 2, Rel 7
RHEL 7 STIG Benchmark – Ver 3, Rel 7
RHEL 8 STIG Benchmark – Ver 1, Rel 5

DISA releases the Rancher Government Solutions Multi-Cluster Manager Security Technical Implementation Guide 

The Defense Information Systems Agency recently released the Rancher Government Solutions Multi-Cluster Manager Security Technical Implementation Guide (STIG), which is effective immediately upon release. 

 

Customers who possess a Common Access Card (CAC) that has valid Department of Defense (DOD) certificates can obtain the STIG from the DOD Cyber Exchange website at https://cyber.mil/stigs/downloads/. The STIG is also available on the Cyber Exchange public site at https://public.cyber.mil/stigs/downloads/. 

 

Users who are unable to find and download the guide or other content can report their issue to the Cyber Exchange web team at dod.cyberexchange@mail.mil. Individuals who have further questions related to STIG content should email the DISA STIG customer support desk at disa.stig_spt@mail.mil. 

STIG Update - DISA releases the Zebra Android 11 COBO Security Technical Implementation Guide

The Defense Information Systems Agency recently released the Zebra Android 11 COBO Security Technical Implementation Guide (STIG), which is effective immediately upon release.

Customers who possess a Common Access Card (CAC) that has valid Department of Defense (DOD) certificates can obtain the STIG from the DOD Cyber Exchange website at https://cyber.mil/stigs/downloads/. The STIG is also available on the Cyber Exchange public site at https://public.cyber.mil/stigs/downloads/.

Users who are unable to find and download the guide or other content can report their issue to the Cyber Exchange web team at dod.cyberexchange@mail.mil. Individuals who have further questions related to STIG content should email the DISA STIG customer support desk at disa.stig_spt@mail.mil.

DISA releases the VMware NSX-T Data Center Security Technical Implementation Guide

The Defense Information Systems Agency recently released the VMware NSX-T Data Center Security Technical Implementation Guide (STIG), which is effective immediately upon release.

Customers who possess a Common Access Card (CAC) that has valid Department of Defense (DOD) certificates can obtain the STIG from the DOD Cyber Exchange website at https://cyber.mil/stigs/downloads/. The STIG is also available on the Cyber Exchange public site at https://public.cyber.mil/stigs/downloads/.

Users who are unable to find and download the guide or other content can report their issue to the Cyber Exchange web team at dod.cyberexchange@mail.mil. Individuals who have further questions related to STIG content should email the DISA STIG customer support desk at disa.stig_spt@mail.mil.

Request for comments - DISA releases draft Mozilla Firefox STIG

The Defense Information Systems Agency recently released the draft Mozilla Firefox Security Technical Implementation Guide (STIG) Security Content Automation Protocol (SCAP) benchmark for review.

Customers who possess a Common Access Card (CAC) that has valid Department of Defense (DOD) certificates can submit comments and/or recommended changes to the draft benchmark by 18 April 2022 on the comment matrix spreadsheet, which is located with the benchmark at https://cyber.mil/stigs/downloads/.

The draft benchmark and comment matrix are also available on the Cyber Exchange public site at https://public.cyber.mil/stigs/downloads/.

Please email comments to disa.stig_spt@mail.mil and include the title and version of the benchmark in the subject line.

Users who are unable to find and download these files or other content can report their issue to the Cyber Exchange web team at dod.cyberexchange@mail.mil.

STIG Update- DISA releases Canonical Ubuntu 20.04 LTS V1R3 STIG with Ansible

The Defense Information Systems Agency recently released the Canonical Ubuntu 20.04 LTS V1R3 Security Technical Implementation Guide (STIG) with Ansible. This content is published as a resource to assist in the application of security guidance to systems.

Customers who possess a Common Access Card (CAC) that has valid Department of Defense (DOD) certificates can obtain the file from the DOD Cyber Exchange website at https://cyber.mil/stigs/supplemental-automation-content/. The file is also available on the Cyber Exchange public site at https://public.cyber.mil/stigs/supplemental-automation-content/.

Users who are unable to find and download the content can report their issue to the Cyber Exchange web team at dod.cyberexchange@mail.mil. Individuals who have further questions related to STIG content should email the DISA STIG customer support desk at disa.stig_spt@mail.mil.

DISA releases the HPE Nimble Storage Array Security Technical Implementation Guide

The Defense Information Systems Agency recently released the Hewlett Packard Enterprise (HPE) Nimble Storage Array Security Technical Implementation Guide (STIG), which is effective immediately upon release.

DISA releases the IBM Aspera Platform 4.2 Security Technical Implementation Guide

The Defense Information Systems Agency recently released the IBM Aspera Platform 4.2 Security Technical Implementation Guide (STIG), which is effective immediately upon release.

Customers who possess a Common Access Card (CAC) that has valid Department of Defense (DOD) certificates can obtain the STIG from the DOD Cyber Exchange website at https://cyber.mil/stigs/downloads/. The STIG is also available on the Cyber Exchange public site at https://public.cyber.mil/stigs/downloads/.

Users who are unable to find and download the guide or other content can report their issue to the Cyber Exchange web team at dod.cyberexchange@mail.mil. Individuals who have further questions related to STIG content should email the DISA STIG customer support desk at disa.stig_spt@mail.mil.

PKI/PKE Announcements

New WCF CAs released - Certificate Bundle v5.13

The WCF PKI has recently deployed updated WCF Signing CAs 1-10. These new certificates are now available in the WCF PKI PKCS#7 Certificate Bundle v5.13.