Canonical Ubuntu 24.04 LTS STIG Compliance Checklist
16 items · Security · Medium difficulty · 2 hours
Practical steps to prepare Ubuntu 24.04 for DISA STIG compliance.
-
Download STIG content and supporting resources
Gather official DISA STIG and related benchmark files before remediation.
-
Download SCAP 1.3 content for Ubuntu 24.04
Get the official SCAP 1.3 benchmark for automated scanning and remediation.
-
Download Standalone XCCDF benchmark and Ansible/Chef variants
Fetch XCCDF and configuration management artifacts for manual or automated use.
-
Download automated SCC/SCC content for supported architectures
Obtain SCC bundles for AMD64 and ARM64 targets if available.
-
Verify system matches target CPE (Ubuntu 24.04 LTS)
Confirm OS version and build to ensure the STIG is applicable.
-
Update system packages and apply latest security patches
Run package updates and reboot if kernel or critical packages changed.
-
Apply STIG baseline or automated remediation
Use SCAP/SCC/XCCDF or configuration management to apply recommended settings.
-
Harden SSH configuration
Disable root login, enforce Protocol 2, limit auth methods and strong ciphers.
-
Enforce password and account policies
Set complexity, expiration, lockout, and minimum password length policies.
-
Enable and configure the host firewall
Restrict inbound services to required ports and implement default-deny rules.
-
Enable and configure auditing and logging (auditd)
Enable audit rules, set log retention, and forward logs to a central server if used.
-
Harden kernel parameters (sysctl)
Apply recommended network and filesystem kernel hardening values.
-
Disable unnecessary services and remove unused packages
Stop and disable services not required for the system role.
-
Verify file and directory permissions for sensitive files
Check ownership and permissions for /etc/passwd, /etc/shadow, and key config files.
-
Document exceptions and obtain approvals for deviations
Record reasons, compensating controls, and approval for any non-compliant items.
-
Send comments or change requests to DISA
Email proposed STIG changes to [email protected].
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.