Microsoft Windows Server 2016 STIG — Version 2, Release 10 Implementation Checklist
19 items · Security · Medium difficulty · 4 hours
Implement Windows Server 2016 STIG v2r10: essential steps for admins.
-
Download STIG content and resources
Get SCAP, XCCDF, GPO, SCC files and official resources from DISA.
-
Verify checksums (SHA) for downloaded files
Confirm file integrity matches DISA-provided SHA values.
-
Review STIG version and change history
Ensure Version 2, Release 10 applies and note recent updates.
-
Inventory servers and map roles (DC vs member)
List hostnames, FQDNs, and whether each is DC, member server, or standalone.
-
Backup system state and critical data
Create full backups and system state snapshots before changes.
-
Import DISA GPOs into Active Directory
Import provided GPO packages and confirm successful import.
-
Apply STIG baseline to domain controllers (DC)
Deploy DC-targeted baseline policies and scripts from the STIG.
-
Enable DC-specific policies
Enable policies whose STIG IDs include 'DC'.
-
Harden LDAP and Kerberos settings on DCs
Apply secure LDAP, Kerberos token lifetimes, and encryption policies.
-
Verify DC auditing and logging
Ensure auditing policies, log retention, and forwarding are configured.
-
Apply STIG baseline to member servers and standalone systems (MS)
Deploy member-server-targeted baseline settings from the STIG.
-
Configure local security options per STIG
Adjust local policies that cannot be centrally applied via GPO.
-
Disable unnecessary services and features
Stop and disable services listed as unnecessary in the STIG.
-
Validate host firewall and network access rules
Confirm Windows Firewall profiles and allowed inbound rules match STIG.
-
Run automated compliance scans (SCAP/SCC)
Scan targets with SCAP/SCC tools using the downloaded content.
-
Review scan results and remediate findings
Triage high-severity findings first and apply fixes per STIG guidance.
-
Re-run scans and confirm remediation
Verify previously identified findings are resolved after fixes.
-
Document implemented settings and update asset records
Record GPO versions, applied changes, and updated SHA values.
-
Schedule regular STIG updates and GPO refresh
Subscribe to DISA updates and plan periodic reviews.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.