LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Can't find CentOS STIG referenced in DISA STIG security profile (https://www.linuxquestions.org/questions/linux-security-4/cant-find-centos-stig-referenced-in-disa-stig-security-profile-4175625689/)

Chantillian 03-16-2018 08:35 AM

Can't find CentOS STIG referenced in DISA STIG security profile
 
So in the CentOS installer, I click "SECURITY POLICY" and scroll down to the bottom profile entitled, "DISA STIG for CentOS Linux 7".

Two questions...

We read, "This profile contains configuration checks that align to the DISA STIG for CentOS Linux V1R1". But where is this STIG? I don't see it at https://iase.disa.mil/stigs/Pages/a-z.aspx .

If this CentOS STIG is gone now, then what has DISA said should be used to harden CentOS? I realize many people use RHEL STIGs instead, and I realize CentOS is a near-clone of RHEL, but I'm looking for a paper trail. I mean, in which document does DISA come out and officially recognize the effectiveness of RHEL STIGs upon CentOS?

Chantillian 03-16-2018 09:37 AM

Ummm...so... maybe I should've sent these questions to DISA.


All times are GMT -5. The time now is 09:01 AM.