As noted in a recent news announcement, to provide increased flexibility for the future, DISA is updating the systems that produce Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs). The initial modification will be to change Group and Rule IDs (Vul and Subvul IDs). The previous Group and Rule IDs will be retained through the update as “legacy” IDs, presented as XCCDF ident elements. See the example below:
<Rule id="SV-204392r85825_rule" weight="10.0" severity="high">
<title>The Red Hat Enterprise Linux operating system must be configured so that the
file permissions, ownership, and group membership of system files and commands match
the vendor values.</title>
These updates will necessitate a new version number for every STIG as it is converted to the new format. For example, if the old version/release of a STIG is V2R6, the updated version/release will be V3R1.
DISA has posted two manual STIGs (Windows Server 2019 and Red Hat Enterprise Linux 7) on DoD Cyber Exchange in the new format for review and testing, along with associated automated benchmarks. A new XSL stylesheet is included in the STIGs to handle the “legacy” identifiers. The next release of STIG Viewer will also be able to handle the “legacy” identifiers.
The STIG files each include a spreadsheet that maps the legacy Group ID, legacy Rule ID, and STIG ID to the new Rule ID.
To review the new format, go to https://public.cyber.mil/stigs/downloads/ and search for the following items:
- Microsoft Windows Server 2019 TEST STIG – Ver 2, Rel 0.3
- Microsoft Windows Server 2019 TEST STIG Benchmark – Ver 2, Rel 0.3
- Red Hat Enterprise Linux 7 TEST STIG – Ver 3, Rel 0.3
- Red Hat Enterprise Linux 7 TEST STIG Benchmark – Ver 3, Rel 0.3
If you have any comments after reviewing these samples, please email them to email@example.com and note in the subject line STIG Testing Comments.