On 3/2/22 07:43, Paul Tagliamonte wrote:
STIGs are maintained by DISA, not by Debian
Paul
On Wed, Mar 2, 2022 at 9:42 AM Stephanie Hall <shall@oteemo.com
<mailto:shall@oteemo.com>> wrote:
Good morning,
Do you have an excel version of a STIG for Debian 9 & 10 that you
would be willing to share?
Thank you in advance!
The DISA STIGviewer (a Java app that runs just find on Debian), can
import a STIG file and export to CSV
https://public.cyber.mil/stigs/srg-stig-tools/
However, there is no STIG specific to Debian that i'm aware of.
Your best bet is referencing the Ubuntu ones:
U_CAN_Ubuntu_{18-04,20-04}_LTS_V......_STIG.zip
Cannot speak for it's provenance, but there's this; https://github.com/hardenedlinux/STIG-4-Debian
Thank you everyone! We found a SCAP Security Guide (SSG) for each of the 3 versions we were looking at. 9-11. It's not a STIG, but SCAP is a DoD industry standard so they should look favorably on it. <fingers crossed>
All three had the same line items. We broke it out into an excel
spreadsheet that I wanted to share with you since not everyone uses SCAP.
Thanks for the help!
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 486 |
Nodes: | 16 (3 / 13) |
Uptime: | 141:22:55 |
Calls: | 9,658 |
Calls today: | 6 |
Files: | 13,708 |
Messages: | 6,167,526 |