Windows Server 2019 STIG Implementation
19 items · Security · Hard difficulty · 3 hours
Step-by-step checklist to download, test, and deploy the Windows Server 2019 STIG.
-
Review STIG overview and scope
Read the STIG intro to confirm applicability to servers and domain roles.
-
Identify target systems (domain controllers and member servers)
List hostnames, roles, and environment (test/prod) for the rollout.
-
Download STIG content
Gather official STIG resources before testing and deployment.
-
Download SCAP 1.3 content
Get Microsoft Windows Server 2019 STIG SCAP Benchmark (Ver 3, Rel 7).
-
Download Standalone XCCDF content
Obtain XCCDF packages (STIG and Chef versions) for policy checks.
-
Download Group Policy Objects (GPOs)
Download the latest GPO files (referenced GPOs include updates through 2026).
-
Download Automated SCC content
Retrieve SCC/SCC tool content for automated scanning.
-
Verify SHAs and file integrity for all downloads
Confirm checksums match published values before importing.
-
Import GPOs into Active Directory
Load downloaded GPOs into a test/isolated AD OU for evaluation.
-
Apply STIG baseline to a test server
Apply GPOs and configuration changes only in a controlled test VM first.
-
Run SCAP/SCC scan against the test server
Perform automated checks to identify non-compliant settings and CVEs.
-
Review scan findings and document exceptions
Record false positives, compensating controls, and required exceptions.
-
Remediate high-priority findings on the test server
Fix critical vulnerabilities and misconfigurations found in testing.
-
Create change request and schedule phased production deployment
Document planned changes, rollback steps, and maintenance windows.
-
Deploy the STIG baseline to production in phases
Roll out to small groups, monitor, and expand after validation.
-
Verify compliance on production servers and record results
Rescan production systems and store reports for audit evidence.
-
Subscribe to DISA updates and track change history
Monitor STIG, GPO, SCC, and SHA updates from DISA and NIST records.
-
Maintain STIG implementation log and contact DISA for issues
Keep an audit trail of changes and use the DISA contact in the STIG doc for comments.
-
Schedule quarterly STIG review and re-scan
Plan periodic reviews and scans to detect drift and new findings.
Printed from TickYouOff — the interactive version tracks your progress and can be shared with others.