Back
🔒
SUSE Linux Enterprise Server 15 STIG — Compliance Checklist
Medium
16 items
·
4 hours
testuser
Published 1 month ago
This checklist helps administrators apply, verify, and maintain DISA’s SLES 15 STIG controls. It’s intended for system administrators and compliance officers managing SLES 15 in managed or DoD-aligned environments.
Progress
0 / 16
- Download SCAP 1.3 content — Get DISA SCAP 1.3 content for the SLES 15 STIG benchmark.
- Download standalone XCCDF and automated SCC content — Obtain XCCDF and SCC resources matching your architecture (x86_64, aarch64).
- Verify CPE target matches SLES 15 — Confirm the target is cpe:/o:suse:suse_linux_enterprise_server:15.
- Apply latest SLES 15 updates and security patches — Use zypper or your update management tool to install patches.
- Run SCAP benchmark scan against target hosts — Execute the SCAP/XCCDF scan using your chosen toolset.
- Review SCAP scan results and export report — Focus first on high and critical findings; export evidence.
- Prioritize and remediate high-severity findings — Plan fixes, obtain approvals, and track remediation steps.
- Verify remediation and re-scan to confirm fixes — Re-run scans to ensure issues are resolved and closed.
- Configure system auditing (auditd) per STIG guidance — Ensure audit rules, rotation, and retention meet STIG requirements.
- Enforce secure SSH configuration (disable root login, strong ciphers) — Update /etc/ssh/sshd_config and restart sshd after changes.
- Harden password and account policies (lockouts, complexity) — Configure PAM, password expiry, and account lockout settings.
- Disable unused services and remove unnecessary packages — List services, then mask/disable or remove packages not required.
- Configure centralized logging and retain logs per DoD policy — Forward logs to a central server and set retention rules.
- Implement firewall rules to restrict inbound services — Use firewalld/iptables to limit access to required ports only.
- Document exceptions and submit change requests to DISA when needed — Send proposed revisions or comments to [email protected].
- Subscribe to DISA STIG updates and monitor resource changes — Watch for Resource Title, SCC, and SHA updates to keep content current.
Your Stats
🏆
0
Completed
📅
—
Last Done
⏱️
—
Last Time
Completion Rate
Items checked per run
⚡
—
Fastest Run
🔥
0
Streak
🚫
—
Most Skipped Step
🔄
0
Resets
📝 My Notes