--
You received this message because you are subscribed to the Google Groups "SIMP Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to simp-users+unsubscribe@googlegroups.com.
To post to this group, send email to simp-...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/simp-users/9234f136-b60d-4b69-a9da-1a18213a8f2f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "SIMP Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to simp-users+unsubscribe@googlegroups.com.
To post to this group, send email to simp-...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/simp-users/2fef5d53-e4d9-48ed-964d-86bd427e29c3%40googlegroups.com.
Trevor,
Thank you for all of your replies. A conversation has been started today within our group that might be of interest to you and/or the community. I've copied it here:
It looks like DISA pulled the draft version of the RHEL 7 STIG off of the iase.disa.mil site. After doing some reading into the status of the RHEL 7 STIG,
I found this link (https://access.redhat.com/discussions/1295753). In short DISA, NSA, and Redhat are working on developing an official RHEL 7 STIG and the current status of the project can be found here:
(https://github.com/OpenSCAP/scap-security-guide/wiki/RHEL7-STIG-Project-Page). Unfortunately, that original post was create in December of 2014. In the developer's mailing group found in the second link, I found this post created in January 2015 by Shawn Wells (RedHat Chief Security Strategist) :
---------------------------
There are now two RHEL7 STIGS:
- One issued by NSA and Red Hat, that ships in RHEL7. It was developed under the DISA FSO Vendor STIG process, and is aligned with NIST 800-53 and NIAP regimes. This edition is supported by Red Hat, and ships natively via the scap-security-guide package. This is also the STIG configuration that is exposed in the RHEL installer. Additionally, this RHEL7 STIG is the baseline of many DoD agencies such as NSA and Army. This was released back in March 2015.
- Last week, DISA FSO quietly released what they are calling the their own RHEL7 draft STIG. This version is entirely unknown to Red Hat, and DISA FSO did not make NSA, Red Hat, NIAP or NIST aware they were publishing this edition. It appears they took Red Hat provided content, and added several hundred unknown compliance checks to it. We're working with DISA FSO to see where this came from.
---------------------------
TLDR: There was some bureaucratic inefficiencies that surfaced in January regarding the RHEL 7 STIG and as of currently there isn't an official DISA STIG for RHEL 7 and there won't be one in the foreseeable future.
To view this discussion on the web visit https://groups.google.com/d/msgid/simp-users/91aad842-9a8f-4f4d-b0ae-d4ce08cf534c%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "SIMP Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to simp-users+unsubscribe@googlegroups.com.
To post to this group, send email to simp-...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/simp-users/33511f0f-1dcb-201e-3f07-b512de8b1761%40redhat.com.
For more options, visit https://groups.google.com/d/optout.