Back
🔒
Oracle Linux 9 STIG (Ver 1, Rel 3) Checklist
Medium
19 items
·
4 hours
testuser
Published 1 month ago
A practical checklist to implement Oracle Linux 9 STIG (Ver 1, Rel 3) controls on servers. Ideal for system administrators and security teams preparing DoD compliance or hardening OL9 hosts.
Progress
0 / 19
- Read the Oracle Linux 9 STIG overview and scope — Note key objectives, applicability, and version (Ver 1, Rel 3).
- Download official STIG resources — Get SCAP, XCCDF and automated content from DISA.
- Download SCAP 1.3 content — Use SCAP 1.3 benchmark for automated scanning.
- Download Standalone XCCDF and automated content (Ansible/Chef/SCC) — Grab XCCDF for Ansible/Chef and SCC automated content as needed.
- Verify system CPE and applicability — Confirm target matches Oracle Linux 9.0 (cpe:/o:oracle:linux:9.0).
- Backup system and relevant configurations — Take full system or config backups before making changes.
- Apply all available OS updates and patches — Install latest errata to remediate known CVEs.
- Enable and enforce SELinux — Set SELinux to enforcing and confirm policies are active.
- Enable and configure auditd with persistent logs — Ensure audit rules capture authentication and admin actions.
- Harden SSH configuration — Disable root login, enforce key auth, and restrict ciphers.
- Configure firewall and restrict open ports — Use firewalld to allow only required services and zones.
- Enforce password and account policies — Set complexity, expiration, lockout, and minimum length rules.
- Remove or disable unnecessary packages and services — Uninstall unused daemons to reduce attack surface.
- Set secure file permissions and check SUID/SGID files — Restrict sensitive files and remediate unsafe permissions.
- Install and run SCAP/XCCDF scanner — Execute scans using the downloaded SCAP/XCCDF content.
- Review scan findings and remediate high-severity issues — Prioritize fixes, apply remediations, and retest.
- Document exceptions and obtain approvals — Record accepted deviations and approval rationale.
- Schedule recurring compliance scans and patch cycles — Automate regular scans and updates to maintain compliance.
- Submit comments or change requests to DISA — Email DISA at [email protected] for feedback or proposed revisions.
Your Stats
🏆
0
Completed
📅
—
Last Done
⏱️
—
Last Time
Completion Rate
Items checked per run
⚡
—
Fastest Run
🔥
0
Streak
🚫
—
Most Skipped Step
🔄
0
Resets
📝 My Notes