Windows Server 2019 STIG Implementation Checklist
21 items · Security · Hard difficulty · 4 hours
Step-by-step tasks to apply the Windows Server 2019 STIG and maintain compliance.
-
Inventory target servers and roles
List domain controllers, member servers, standalone systems, and their OS builds.
-
Download official STIG resources from DISA
Obtain authoritative files before making changes.
-
Download SCAP 1.3 content (STIG SCAP Benchmark Ver 3, Rel 7)
Get the SCAP 1.3 package used for automated scanning.
-
Download Standalone XCCDF files (Chef/XCCDF releases)
Grab XCCDF artifacts for manual or tool-based assessment.
-
Download GPO package and latest GPO updates
Retrieve Group Policy Objects provided by DISA for deployment.
-
Verify SHA checksums for downloaded resources
Confirm file integrity before use.
-
Apply latest Windows updates and security patches
Install OS and security updates before hardening.
-
Baseline systems using a SCAP-capable scanner
Run SCAP scans with the downloaded content to identify deviations.
-
Review SCAP/XCCDF scan findings and map to STIG IDs
Triage findings by severity and STIG identifier.
-
Remediate high-severity vulnerabilities
Prioritize fixes for critical findings first.
-
Implement STIG Group Policy Objects on domain or local GPOs
Apply DISA-provided GPOs or map STIG settings to existing policies.
-
Test GPOs in a non-production lab
Validate effects and user impact before wide deployment.
-
Deploy GPOs to a pilot OU and monitor
Roll out to a small group, verify logs and functionality.
-
Configure account and authentication policies per STIG
Set password, lockout, and MFA recommendations where applicable.
-
Enable and configure Windows Firewall and network protections
Enforce inbound/outbound rules and secure RDP/management ports.
-
Harden audit and logging settings and forward logs to SIEM
Ensure audit policies capture needed events and centralize logs.
-
Create backups of GPOs and system configurations
Export GPOs and snapshot configurations before changes.
-
Document changes and record resource versions and SHA
Track applied fixes, GPO versions, SCAP/SHA values, and dates.
-
Subscribe to DISA STIG updates and review change history monthly
Monitor DISA releases, SHA updates, and GPO revisions.
-
Schedule regular rescans and compliance checks
Plan periodic scans to detect regressions or drift.
-
Train administrators on STIG requirements and change procedures
Ensure staff know how to test, deploy, and roll back changes.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.