Oracle Linux 7 STIG Checklist (Ver 3, Rel 4)
16 items · Security · Medium difficulty · 2 hours
Essential STIG steps to secure and maintain Oracle Linux 7 compliance.
-
Download Oracle Linux 7 STIG benchmark (Ver 3, Rel 4)
Obtain the official STIG from DISA or the NIST checklist repository.
-
Download SCAP and XCCDF content
Get SCAP 1.3 content, standalone XCCDF, and SCC automated content for OL7.
-
Download Standalone XCCDF (Ver 3, Rel 5) from DISA/NIST
Use XCCDF for manual review and tools that accept XCCDF inputs.
-
Download Automated SCC content for Oracle Linux 7 (SCC 5.14)
Use SCC/SCC-compliant content for automated scanners and tools.
-
Verify system CPE and Oracle Linux 7 version
Confirm cpe:/o:oracle:linux:7.0 (or later) to ensure STIG applicability.
-
Backup current system and configuration files
Snapshot system and copy /etc, /var/log, and key config files before changes.
-
Apply all available security patches and updates
Use yum/dnf and reboot if required to bring system up to date.
-
Run SCAP/XCCDF compliance scan using downloaded content
Run an oscap/SCC scan with the downloaded SCAP/XCCDF content to produce a report.
-
Review scan results and prioritize findings
Focus remediation on critical and high-severity findings first.
-
Implement STIG remediations for critical/high findings
Apply configuration changes, packages, or settings required and retest.
-
Harden services: disable unnecessary daemons and close open ports
Examples: remove/disable telnet, rsh, unused network services, and unneeded packages.
-
Enable and configure auditd and centralized logging
Ensure audit rules are set and logs are retained and forwarded to a central collector.
-
Enforce password and account policies per GPOS SRG
Set complexity, lockout, expiration, and minimum age policies as required.
-
Schedule regular compliance scans and maintenance windows
Automate scans and plan remediation windows to maintain continuous compliance.
-
Document changes, maintain change control, and record evidence
Keep tickets, config snapshots, and screenshots as proof of remediation.
-
Track DISA updates and refresh SCC resources regularly
Subscribe to DISA/NIST updates and update local STIG/SCC content when released.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.