Mozilla Firefox STIG Security Checklist
20 items · Security · Medium difficulty · 2 hours
Apply and maintain the Firefox STIG for secure, managed browser deployments.
-
Download the official DISA Firefox STIG and SCAP 1.3 content
Get XCCDF/SCAP, GPO, Intune, and SCC resources from DISA before starting.
-
Validate XCCDF/SCAP files and correct ID spacing issues
Replace spaces in XML id attributes with underscores to pass XCCDF validation.
-
Test STIG settings in a representative lab environment
Verify functionality and compatibility before rolling changes to users.
-
Apply the STIG using available automation (SCC, SCAP, GPO, Intune)
Choose the automation path that matches your environment and deploy policy packages.
-
Enforce automatic updates and patch management
Configure Firefox enterprise policies, GPO, or Intune to keep builds current.
- Harden TLS and certificate validation
-
Disable TLS 1.0 and TLS 1.1
Ensure only modern protocol versions are allowed.
-
Enable and prefer TLS 1.2 and TLS 1.3
Verify cipher preferences and protocol negotiation are secure.
-
Enable strict certificate revocation checks (OCSP/CRL)
Require revocation checking to reduce risk from compromised certs.
-
Disable telemetry, data reporting, and health pings
Turn off telemetry and health-report features in enterprise policy.
-
Disable telemetry collection features
Block data submission and studies in managed configuration.
-
Disable Firefox Health Report and automated data uploads
Prevent periodic health data from leaving managed devices.
-
Disable remote debugging and remote developer features
Turn off remote debugging, devtools remote connections, and related prefs.
-
Restrict extensions to approved add-ons and block unsigned installs
Use policies to whitelist/extensions and prevent unapproved installs.
-
Configure cookie and privacy settings to block third-party tracking
Set strict cookie policies and limit cross-site tracking.
-
Disable password autofill and control password manager behavior
Force use of approved enterprise credential manager if required.
-
Enable pop-up blocking and block mixed (HTTP/HTTPS) content
Prevent insecure mixed content and unwanted pop-ups by policy.
-
Set homepage, new-tab, and search defaults to approved organizational values
Enforce approved start pages and search providers via enterprise policy.
-
Document applied STIG changes and assign a point of contact
Record configurations, dates, and responsible admins for audits.
-
Schedule regular audits and update STIG resources (GPOs, SCC, Intune)
Re-check configuration against DISA updates and apply revised resources.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.