Security Hardening & Compliance (STIGs/CIS)
14 chapters
1. 2 Functional Testing
[Verse 1]
When data flows from start to end
We need to test what we defend
Kafka streams and Kube deployments
Every layer needs enforcement
Producer sends a message out
Consumer pulls without a doubt
But can we trust this round trip works
When failure in the system lurks
[Chorus]
Test the flow, test the load
Every path in our code
Round trip, rollout, rebalance right
Exactly once through day and night
Schema valid, pods deployed
Network policies can't be toyed
End to end we verify
Defense systems never die
[Verse 2]
Schema registry holds the truth
Validation gives us solid proof
Consumer groups must rebalance clean
When members join the streaming scene
Exactly once semantics mean
No duplicates in our machine
Idempotent keys protect the state
When retries come but not too late
[Chorus]
Test the flow, test the load
Every path in our code
Round trip, rollout, rebalance right
Exactly once through day and night
Schema valid, pods deployed
Network policies can't be toyed
End to end we verify
Defense systems never die
[Bridge]
Deployment rolling update starts
New pods spinning, old departs
Scheduler finds the perfect node
Resource limits bear the load
Network policies block the bad
Allow the good, keep data glad
Integration tests will prove
Every component makes its move
[Verse 3]
From message born to data stored
Across the clusters, through each ward
Kubernetes orchestrates the dance
While Kafka gives us second chance
Resource quotas keep in line
CPU and memory combine
Pod scheduling finds the way
To keep our systems up all day
[Chorus]
Test the flow, test the load
Every path in our code
Round trip, rollout, rebalance right
Exactly once through day and night
Schema valid, pods deployed
Network policies can't be toyed
End to end we verify
Defense systems never die
[Outro]
Functional testing is the key
To infrastructure running free
Every feature, every flow
Tested well before we go
2. 3 Failover and Resilience Testing
[Verse 1]
When regions fall and brokers break down
Controllers lose their quorum crown
Network partitions split the ground
Active-active keeps us sound
We test the paths when systems fail
Document each recovery trail
[Chorus]
RTO RPO measure the time
Recovery Target Objective in line
Recovery Point Objective defined
Test the failover every time
No messages lost in the switch
Data integrity without a glitch
Document results for compliance needs
Failover testing succeeds
[Verse 2]
Region failure hits us hard
But active-active stands on guard
Multiple zones keep data flowing
Backup systems always knowing
When the primary can't respond
Failover creates a backup bond
[Chorus]
RTO RPO measure the time
Recovery Target Objective in line
Recovery Point Objective defined
Test the failover every time
No messages lost in the switch
Data integrity without a glitch
Document results for compliance needs
Failover testing succeeds
[Verse 3]
Broker failure breaks the chain
But redundancy handles the strain
Controller quorum needs majority vote
When it's lost the system won't float
Network partitions split the mesh
But planning keeps the data fresh
[Bridge]
Instrument the recovery flow
Measure metrics that you need to know
How long until the system's back
Verify there's nothing that you lack
No duplicates unless expected
Every message gets protected
[Chorus]
RTO RPO measure the time
Recovery Target Objective in line
Recovery Point Objective defined
Test the failover every time
No messages lost in the switch
Data integrity without a glitch
Document results for compliance needs
Failover testing succeeds
[Verse 4]
Post-failover verification starts
Check the data in all parts
Count the messages received
Make sure none were misconceived
Document findings for the audit trail
Contingency planning will not fail
[Outro]
When disaster strikes your infrastructure
Resilience testing is your cure
Evidence documented clear and bright
Incident response done right
Failover ready, systems strong
Defense delivery all along
3. 1 Hardening Approaches
[Verse 1]
When you build a fortress, start with solid ground
Gold images are templates, security-bound
Pre-hardened operating systems, STIGs applied with care
Deploy them as your baseline, protection everywhere
[Chorus]
Four ways to harden, keep your systems tight
Gold images, IaC, policies that bite
Group management, config tools so bright
G-I-C-G hardening done right
[Verse 2]
Infrastructure as Code now, automation's key
Ansible and Chef cooking recipes
Puppet pulls the strings while Terraform builds the land
STIG configurations written by your hand
[Chorus]
Four ways to harden, keep your systems tight
Gold images, IaC, policies that bite
Group management, config tools so bright
G-I-C-G hardening done right
[Bridge]
Windows domains need Group Policy Objects
Map those STIG requirements, security projects
Centralized enforcement across your whole domain
Making sure compliance flows through every lane
[Verse 3]
Configuration management keeps the watch at night
SCCM and Satellite, Ansible Tower's might
Ongoing compliance, never standing still
Centralized tools bending systems to your will
[Chorus]
Four ways to harden, keep your systems tight
Gold images, IaC, policies that bite
Group management, config tools so bright
G-I-C-G hardening done right
[Outro]
Template, code, policy, manage
Four approaches for security's advantage
Gold, Infrastructure, Group, Config flow
That's how hardening approaches go
4. 4 STIGs ↔ CIS Benchmarks
[Verse 1]
Two frameworks guide security's way
CIS Benchmarks and STIGs today
They overlap on common ground
Where platform hardening can be found
CIS starts broad then gets more tight
Level One for general sight
[Chorus]
STIGs and CIS, they work together
Building defense through any weather
Level One broad, Level Two strong
But STIGs go further all along
Overlap and layer, that's the key
Security frameworks in harmony
[Verse 2]
CIS Level One applies to most
Basic security coast to coast
Level Two cranks up the heat
Higher security more complete
But when DoD needs protection true
STIGs go beyond what CIS can do
[Chorus]
STIGs and CIS, they work together
Building defense through any weather
Level One broad, Level Two strong
But STIGs go further all along
Overlap and layer, that's the key
Security frameworks in harmony
[Bridge]
Organizations start with CIS as base
Then layer STIG controls in place
DoD environments need the most
STIGs provide that stronger post
Common platforms share the load
Both frameworks light the road
[Verse 3]
Windows, Linux, network gear
Both frameworks make requirements clear
Start with CIS for foundational ground
Add STIG controls where threats are found
Stringent standards for defense
Maximum security makes sense
[Chorus]
STIGs and CIS, they work together
Building defense through any weather
Level One broad, Level Two strong
But STIGs go further all along
Overlap and layer, that's the key
Security frameworks in harmony
[Outro]
From commercial grade to military might
These frameworks keep your systems tight
Choose your level, know your need
Both together help you succeed
5. 2 STIGs ↔ FedRAMP
[Verse 1]
NIST eight hundred fifty-three sets the foundation
Both FedRAMP and STIGs draw from this creation
Cloud providers want that government connection
But DoD needs more than baseline protection
[Chorus]
STIGs and FedRAMP dancing hand in hand
Both from NIST but different demands
FedRAMP starts you off but it's not the end
DoD needs more controls to defend
Two frameworks working where security matters
NIST eight hundred fifty-three is what scatters
Into baselines and guides across the land
[Verse 2]
Cloud Service Providers seeking DoD gold
FedRAMP Provisional won't complete the goal
STIG requirements go beyond what's baseline
Additional controls to keep systems in line
[Chorus]
STIGs and FedRAMP dancing hand in hand
Both from NIST but different demands
FedRAMP starts you off but it's not the end
DoD needs more controls to defend
Two frameworks working where security matters
NIST eight hundred fifty-three is what scatters
Into baselines and guides across the land
[Bridge]
Cloud Computing SRG defines the way
Impact Levels two four five and six today
Higher levels mean stronger requirements
Security posture needs those alignments
[Verse 3]
When the mission's critical and data's at stake
Standard baselines won't cover the intake
STIG requirements fill in all the gaps
Comprehensive security that never snaps
[Chorus]
STIGs and FedRAMP dancing hand in hand
Both from NIST but different demands
FedRAMP starts you off but it's not the end
DoD needs more controls to defend
Two frameworks working where security matters
NIST eight hundred fifty-three is what scatters
Into baselines and guides across the land
[Outro]
Same source different purpose in the cloud
NIST controls making security proud
STIGs and FedRAMP working as planned
Defense in depth across the federal land
6. 4 STIG Assessment Workflow
[Verse 1]
When security assessment time arrives
We need a workflow to keep systems alive
Eight steps to follow, each one has its place
From scope to reporting, we'll set the right pace
Start with the boundary, what's in our domain
Every system matters, nothing left unnamed
[Chorus]
Scope and Baseline, Scan then Review
Document findings, make them come through
Remediate problems, Validate twice
Report the results, security's nice
S-B-S-M-D-R-V-R, STIG workflow takes us far
[Verse 2]
Baseline comes next, we determine what's right
Which STIGs and SRGs will guide us tonight
Match every technology with proper controls
Security requirements to reach all our goals
SCAP automation makes scanning so clean
Finding vulnerabilities in the machine
[Chorus]
Scope and Baseline, Scan then Review
Document findings, make them come through
Remediate problems, Validate twice
Report the results, security's nice
S-B-S-M-D-R-V-R, STIG workflow takes us far
[Bridge]
Manual review for what scans can't see
Human eyes catching what automation missed free
Document in checklists with dot-C-K-L files
Evidence matters, go that extra mile
POA and Ms when fixes can't wait
Justify reasons, don't leave it to fate
[Verse 3]
Remediation fixes what we found wrong
Validate changes, make security strong
Re-scan and re-assess, confirm every change
Report to stakeholders across the whole range
Authorization package needs our complete view
STIG assessment workflow sees us through
[Chorus]
Scope and Baseline, Scan then Review
Document findings, make them come through
Remediate problems, Validate twice
Report the results, security's nice
S-B-S-M-D-R-V-R, STIG workflow takes us far
[Outro]
Eight steps together make systems secure
DISA STIG workflow, tested and sure
7. 1 Windows Server STIG
[Verse 1]
Password policies set the stage
Complex characters, minimum age
Lockout thresholds keep hackers out
Inactive accounts, clean them out
History remembered, can't repeat
Security foundation, strong and neat
[Chorus]
Windows Server locked down tight
STIG compliance done right
Audit, assign, and authenticate
Least privilege, don't hesitate
Defender up, legacy down
STIG protection all around
[Verse 2]
Advanced audit policies track
Every login, every attack
Event forwarding sends the logs
Security monitoring through the fog
User rights assigned with care
Only what they need to share
[Chorus]
Windows Server locked down tight
STIG compliance done right
Audit, assign, and authenticate
Least privilege, don't hesitate
Defender up, legacy down
STIG protection all around
[Verse 3]
SMB signing, LDAP too
Authentication levels new
LAN Manager set to high
Legacy protocols say goodbye
SSL two and three are done
TLS one-zero, time to run
[Bridge]
PowerShell logs every block
Constrained language, transcript clock
Credential Guard protects the keys
Device Guard brings you ease
Virtualization security
HVCI technology
[Chorus]
Windows Server locked down tight
STIG compliance done right
Audit, assign, and authenticate
Least privilege, don't hesitate
Defender up, legacy down
STIG protection all around
[Verse 4]
Windows Defender real-time shield
Exploit Guard makes malware yield
Signature updates, behavior watch
Advanced threats, it's gonna stop
Application control in place
STIG hardening sets the pace
[Outro]
From accounts to TLS
STIG compliance, nothing less
Windows Server standing strong
Security done right, not wrong
8. 6 Lab 6 — Ansible STIG Automation
[Verse 1]
Time to clone that Ansible role today
From the lockdown repo we'll pull it down our way
RHEL Eight STIG automation's what we need
Infrastructure as Code will help us succeed
Review the variables, customize them right
Make them fit your environment, get ready for the fight
[Chorus]
Clone Review Run Validate Deploy
C-R-R-V-D that's how we automate with joy
Clone Review Run Validate Deploy
STIG compliance flowing through our CI joy
Ansible playbooks dancing through the night
Making systems secure and running right
[Verse 2]
Variables dot yaml holds the configuration keys
Tweak the settings for your network's needs
Security controls mapped to every line
CAT One CAT Two CAT Three all defined
Test system ready for our playbook run
Watch the automation magic get things done
[Chorus]
Clone Review Run Validate Deploy
C-R-R-V-D that's how we automate with joy
Clone Review Run Validate Deploy
STIG compliance flowing through our CI joy
Ansible playbooks dancing through the night
Making systems secure and running right
[Bridge]
SCAP scanner running through the night
Validating every control is right
Green lights flashing, compliance achieved
Security baseline now we can believe
Pipeline triggers on every commit
Enforcement automatic bit by bit
[Verse 3]
CI CD pipeline's where the magic flows
Every deployment through security goes
Jenkins GitLab Actions whatever you choose
Automated STIG means you cannot lose
Test and prod environments stay in line
Security by design every single time
[Chorus]
Clone Review Run Validate Deploy
C-R-R-V-D that's how we automate with joy
Clone Review Run Validate Deploy
STIG compliance flowing through our CI joy
Ansible playbooks dancing through the night
Making systems secure and running right
[Outro]
From clone to deploy we've learned the way
Ansible STIG automation saves the day
Infrastructure as Code keeps us secure
DISA standards we can now ensure
9. 4 Database STIGs
[Verse 1]
In the world of data where secrets lie
Four database shields protect and fortify
Authentication first, control who gets inside
Least privilege rules, keep permissions tight
Role separation is the golden way
DBA, application, audit - each has their say
Never mix the powers, keep them clean and clear
Security through boundaries we hold dear
[Chorus]
Auth and Audit, Encrypt and Validate
Four database STIGs we must not forget
DDL and DML, log every change
TDE protects data, SQL injection's strange
Auth and Audit, Encrypt and Validate
Database security, seal up every gate
[Verse 2]
Auditing comes second in our security song
Track every action, log what goes wrong
Privileged operations need a paper trail
Protect those audit logs or security will fail
DDL changes, DML too
Every database action needs a review
Store those records where they can't be changed
Accountability perfectly arranged
[Chorus]
Auth and Audit, Encrypt and Validate
Four database STIGs we must not forget
DDL and DML, log every change
TDE protects data, SQL injection's strange
Auth and Audit, Encrypt and Validate
Database security, seal up every gate
[Verse 3]
Encryption third, transparent and strong
TDE at rest keeps data where it belongs
In transit protection, SSL the way
Scrambled bits and bytes throughout the day
Input validation stops the SQL attack
Injection attempts just bounce right back
Sanitize the queries at the database door
Malicious code can't hurt us anymore
[Bridge]
Backup and recovery, encrypted and tested
Patch management, never let it rest-ed
Four pillars standing, database security
DISA STIG compliance, our priority
[Chorus]
Auth and Audit, Encrypt and Validate
Four database STIGs we must not forget
DDL and DML, log every change
TDE protects data, SQL injection's strange
Auth and Audit, Encrypt and Validate
Database security, seal up every gate
[Outro]
From Oracle to SQL Server too
These four standards will see you through
Authentication, Auditing, Encryption, Validation
Database STIGs across the nation
10. 3 Zero Trust Architecture and STIGs
[Verse 1]
Never trust, always verify the way
Every user, every device today
STIGs provide the hardened foundation
Zero Trust needs for our nation
Identity checked at every door
Access granted, nothing more
[Chorus]
I-M-E-C-M, that's the way
Identity, Micro, Endpoint, Crypto, Monitor every day
Zero Trust with STIGs aligned
Never trust, always verify in mind
Granular controls in every zone
Trust nothing, verify what's known
[Verse 2]
Identity management leads the charge
Multi-factor auth, permissions large
Microsegmentation breaks the walls
Network zones where data calls
East-west traffic gets inspected
No lateral moves go undetected
[Chorus]
I-M-E-C-M, that's the way
Identity, Micro, Endpoint, Crypto, Monitor every day
Zero Trust with STIGs aligned
Never trust, always verify in mind
Granular controls in every zone
Trust nothing, verify what's known
[Verse 3]
Endpoint hardening locks it down
STIG baselines wear the crown
Encryption flows through every stream
Data protected, living the dream
Continuous monitoring never sleeps
Watching over what we keep
[Bridge]
DISA's reference architecture shows
How Zero Trust implementation grows
Five domains working hand in hand
Securing our digital land
From perimeter to core defense
Zero Trust makes perfect sense
[Chorus]
I-M-E-C-M, that's the way
Identity, Micro, Endpoint, Crypto, Monitor every day
Zero Trust with STIGs aligned
Never trust, always verify in mind
Granular controls in every zone
Trust nothing, verify what's known
[Outro]
STIG hardened infrastructure stands
Zero Trust across all lands
Never trust and always see
That's our cybersecurity
11. 2 STIG for DevSecOps Pipelines
[Verse 1]
Build your pipeline strong and true
STIG compliance starts with you
Don't wait for runtime to detect
Shift-left scanning to protect
Every commit gets reviewed
Security gates can't be subdued
When violations come to light
Your build will fail before it flies
[Chorus]
Scan early, scan often, make it automated
STIG checks in CI, never be frustrated
Shift-left hardening, catch it at the source
Compliance gates will keep you on course
DevSecOps flowing, security's the key
Build it right the first time, that's how it should be
[Verse 2]
Infrastructure as Code awaits
Terraform templates at the gates
CloudFormation stacks in line
Every resource must align
Validate before deploy
STIG requirements can't destroy
Your architecture when it's planned
With scanning tools close at hand
[Chorus]
Scan early, scan often, make it automated
STIG checks in CI, never be frustrated
Shift-left hardening, catch it at the source
Compliance gates will keep you on course
DevSecOps flowing, security's the key
Build it right the first time, that's how it should be
[Bridge]
Container images in the pipeline flow
Hardening layers as they grow
Base OS configs locked down tight
Registry scanning through the night
Failed builds mean compliance missed
Add your fixes to the list
Green builds only make it through
Security first in all you do
[Verse 3]
Continuous integration learns
When STIG violations return
Automated checks won't let you pass
Until your code meets standard class
Pipeline stages gate by gate
Security cannot wait
From development to production line
STIG compliance by design
[Chorus]
Scan early, scan often, make it automated
STIG checks in CI, never be frustrated
Shift-left hardening, catch it at the source
Compliance gates will keep you on course
DevSecOps flowing, security's the key
Build it right the first time, that's how it should be
[Outro]
DISA standards guide the way
DevSecOps every single day
Pipeline security here to stay
STIG compliance is the way
12. 5 Lab 5 — Gold Image Hardening
[Verse 1]
Start with a server fresh and clean
Windows or Red Hat on the screen
Before we let it join the fleet
Our hardening task must be complete
[Chorus]
Gold image baseline, secure and strong
STIG compliant all along
Deploy, apply, scan and verify
Document findings, then we certify
Gold image baseline, that's our way
Building security day by day
[Verse 2]
Apply the STIGs with careful hands
Manual steps or automation plans
Every control and every check
Makes our foundation bulletproof and spec
[Chorus]
Gold image baseline, secure and strong
STIG compliant all along
Deploy, apply, scan and verify
Document findings, then we certify
Gold image baseline, that's our way
Building security day by day
[Bridge]
SCAP scanner runs its thorough test
Every setting put to the quest
Open findings get their review
Document why and what to do
[Verse 3]
When compliance numbers look just right
And all our findings shine so bright
Snapshot the image, save the state
This golden master seals our fate
[Chorus]
Gold image baseline, secure and strong
STIG compliant all along
Deploy, apply, scan and verify
Document findings, then we certify
Gold image baseline, that's our way
Building security day by day
[Outro]
From fresh install to hardened gold
Our baseline story has been told
DISA standards guide our hand
Secure foundations across the land
13. 1 Official Resources
[Verse 1]
When you need the official guide to keep your systems secure
DISA Cyber Exchange is the place that's tried and pure
Public dot cyber dot mil, that's your gateway to the truth
STIGs and SRGs and tools, documentation bulletproof
[Chorus]
Four resources you need to know, memorize them as you go
DISA Exchange leads the way, NIST frameworks guide your play
DoD CIO sets the rules, STIG Viewer gives you tools
Official sources, trust no other, cybersecurity's true mother
[Verse 2]
NIST publications hold the frameworks that you'll need
Eight hundred fifty-three controls, security standards guaranteed
Thirty-seven for the process, seventy-one for contractors too
Risk management framework building what the experts always knew
[Chorus]
Four resources you need to know, memorize them as you go
DISA Exchange leads the way, NIST frameworks guide your play
DoD CIO sets the rules, STIG Viewer gives you tools
Official sources, trust no other, cybersecurity's true mother
[Bridge]
DoD CIO Library holds instructions and directives clear
Department governance written down for cybersecurity here
STIG Viewer and STIG Manager help you track your compliance state
Assessment tools that keep you current, never running late
[Verse 3]
Don't go searching random places when official sources shine
These four pillars hold together our security design
From the technical guidelines to the governance above
Official resources are the ones that cybersecurity loves
[Chorus]
Four resources you need to know, memorize them as you go
DISA Exchange leads the way, NIST frameworks guide your play
DoD CIO sets the rules, STIG Viewer gives you tools
Official sources, trust no other, cybersecurity's true mother
[Outro]
When compliance calls your name, these resources win the game
Official sources, official sources, always official sources
14. 3 Continuous Monitoring and STIGs
[Verse 1]
After authorization's granted and your system's live
The work's not over, compliance must survive
Post-ATO monitoring keeps your status green
Through automated scanning and procedures clean
[Chorus]
SCAP scans scheduled, monthly they run
Updates quarterly when new STIGs come
Drift detection catches systems that stray
Vulnerability management shows the way
Continuous monitoring every single day
Keeps your authorization here to stay
[Verse 2]
Scheduled SCAP scans are your faithful friend
Running automated checks that never end
Monthly or quarterly, they sweep your domain
Finding non-compliance before it brings pain
[Chorus]
SCAP scans scheduled, monthly they run
Updates quarterly when new STIGs come
Drift detection catches systems that stray
Vulnerability management shows the way
Continuous monitoring every single day
Keeps your authorization here to stay
[Verse 3]
STIG update management keeps you current and true
When DISA releases guidelines that are new
Quarterly reviews of every fresh release
Apply the changes to maintain your peace
[Bridge]
Configuration drift will try to creep in
Systems falling out of compliance again
Detection tools will sound the alarm
Before any deviation can cause you harm
[Verse 4]
Vulnerability management integration's key
Correlating STIG findings helps you see
When compliance gaps and security holes align
Fix them both and keep your systems fine
[Final Chorus]
SCAP scans scheduled, running on time
Updates quarterly in your paradigm
Drift detection keeps compliance tight
Vulnerability correlation makes it right
Continuous monitoring through day and night
Keeps your ATO burning bright
[Outro]
Post-ATO success through monitoring's power
Ongoing authorization hour by hour
Back to Home