3 ms·
I don't believe Microsoft contributes to this project. There are STIGs available for Windows but presumably any automated hardening by Microsoft is proprietary.
by cipherboy 3y ago
I don't believe Microsoft contributes to this project. There are STIGs available for Windows but presumably any automated hardening by Microsoft is proprietary. Likely a new Powershell automation backend would be necessary. The scanner might work, though.
I think part of the dichotomy comes from the general acceptance of these recommendations. STIGs are only really applicable to the US Govt and perhaps a few select groups that do business with them. Even major banks haven't typically adopted them wholesale (like they have with higher FIPS levels for instance).
The broader security community has largely written it off as security theater. For the most part the amount of data generated by these recommendations (which is hard to prove and identify concrete threats in real time -- at best for postmortem understanding) and the impact to usability is substantial enough that I agree. Though, having met with many authors of STIG and other benchmarks, their intentions are well-meaning.