Windows 11 STIG (Ver 2, Rel 7)
21 items · Security · Hard difficulty · 1 day
Implement the Windows 11 STIG step-by-step for DISA compliance.
-
Download official STIG resources
Grab SCAP, XCCDF, GPOs, Intune policies and SCC content from DISA.
-
Download SCAP 1.3 content
Use for automated scanning and benchmark checks.
-
Download XCCDF standalone benchmarks
Get XCCDF files for your compliance tooling.
-
Download Intune policies and GPO packages
Obtain the provided Intune templates and GPO exports for deployment.
-
Review STIG requirements and change history
Read version notes, applicability, and control rationale.
-
Identify target systems and environment
Document OS editions, domain status, and managed endpoints.
-
Run a SCAP or compliance scan against targets
Use SCAP/XCCDF or your compliance tool to generate findings.
-
Review scan results and prioritize findings
Rank fixes by risk and operational impact.
-
Apply Group Policy Objects (GPOs) to domain-joined systems
Import provided GPOs and link to appropriate OUs.
-
Test GPOs in a staging OU
Validate settings on a pilot group before broad rollout.
-
Document GPO changes and rollback plan
Record settings, timestamps, and remediation steps.
-
Deploy Intune policies to managed endpoints
Apply Intune templates for non-domain or cloud-managed devices.
-
Enable and configure Windows Defender Antivirus
Verify definitions, real-time protection, and exclusions.
-
Ensure BitLocker disk encryption is enabled
Confirm encryption status and recovery key escrow.
-
Configure Windows Firewall and network profiles
Set appropriate inbound/outbound rules and domain/private/public profiles.
-
Enforce least-privilege and remove unnecessary local admin rights
Limit admin accounts and use controlled elevation.
-
Apply system patches and security updates
Install cumulative updates, drivers, and firmware fixes.
-
Enable auditing and forward logs to SIEM
Configure event logging and central collection for monitoring.
-
Test user workflows and critical applications
Confirm business apps function after hardening changes.
-
Document changes, approvals, and exception waivers
Record deviations and submit change requests to the listed DISA contact if needed.
-
Schedule periodic re-scans and STIG reviews
Plan updates aligned to DISA release and resource updates.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.