Skip to content

STIG for Debian ? #7745

Answered by ggbecker
mdedonno1337 asked this question in Q&A
Oct 14, 2021 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

Sure you can have a STIG profile for debian in this project that's not a problem, but it won't have any legal liability. Nor other STIG profiles have any liability as well. Profiles developed in this project are merely to support institutions to assess their systems for a STIG compliance that should follow benchmarks (usually manual) provided by DISA.

The formal process to start developing an official STIG for a product is to follow their vendor process here: https://public.cyber.mil/stigs/vendor-process/

If you come up with a STIG profile in this project, it must have a disclaimer stating that the profile is a draft and should not be considered an official profile.

I hope that helps.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@mdedonno1337
Comment options

Answer selected by marcusburghardt
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
Debian Debian product related. STIG STIG Benchmark related.
2 participants
Converted from issue

This discussion was converted from issue #7744 on October 14, 2021 12:01.