-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
speak to DISA STIGs #20
Comments
Should probably also mention the CIS Benchmarks. Is there a generic term for these? |
The generic term for these would probably be configuration baselines or just baselines. The guidance provided by USGCB/STIGs/CIS Benchmarks is what you use to determine your baseline configuration settings. Different baselines might be prescribed based on the scenario. For FedRAMP in CM-6(a) it prescribes using USGCB if available, then CIS benchmarks. STIGs come into play when you add the DISA SRG The SRG has a well written overview on page 5 section 1.4. The thing I do not know and would be curious to learn where the requirement is for agencies and subcontractors. I'm guessing it's in 800-171 3.4.1 where it says to follow NIST 800-128 which says:
But I'd love some correction if I'm totally off base. |
Thanks for all of that!
Yeah, the former is better, as there are also control baselines, which are a different thing. |
...and how they relate to controls.
https://public.cyber.mil/stigs/
The text was updated successfully, but these errors were encountered: