Oracle Linux 9 STIG (Ver 1, Rel 3) Checklist
19 items · Security · Medium difficulty · 4 hours
Harden Oracle Linux 9 servers and achieve STIG compliance step-by-step.
-
Read the Oracle Linux 9 STIG overview and scope
Note key objectives, applicability, and version (Ver 1, Rel 3).
-
Download official STIG resources
Get SCAP, XCCDF and automated content from DISA.
-
Download SCAP 1.3 content
Use SCAP 1.3 benchmark for automated scanning.
-
Download Standalone XCCDF and automated content (Ansible/Chef/SCC)
Grab XCCDF for Ansible/Chef and SCC automated content as needed.
-
Verify system CPE and applicability
Confirm target matches Oracle Linux 9.0 (cpe:/o:oracle:linux:9.0).
-
Backup system and relevant configurations
Take full system or config backups before making changes.
-
Apply all available OS updates and patches
Install latest errata to remediate known CVEs.
-
Enable and enforce SELinux
Set SELinux to enforcing and confirm policies are active.
-
Enable and configure auditd with persistent logs
Ensure audit rules capture authentication and admin actions.
-
Harden SSH configuration
Disable root login, enforce key auth, and restrict ciphers.
-
Configure firewall and restrict open ports
Use firewalld to allow only required services and zones.
-
Enforce password and account policies
Set complexity, expiration, lockout, and minimum length rules.
-
Remove or disable unnecessary packages and services
Uninstall unused daemons to reduce attack surface.
-
Set secure file permissions and check SUID/SGID files
Restrict sensitive files and remediate unsafe permissions.
-
Install and run SCAP/XCCDF scanner
Execute scans using the downloaded SCAP/XCCDF content.
-
Review scan findings and remediate high-severity issues
Prioritize fixes, apply remediations, and retest.
-
Document exceptions and obtain approvals
Record accepted deviations and approval rationale.
-
Schedule recurring compliance scans and patch cycles
Automate regular scans and updates to maintain compliance.
-
Submit comments or change requests to DISA
Email DISA at [email protected] for feedback or proposed revisions.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.