Amazon Linux 2023 Department of War (Previously Department of Defense) STIG #13885
Replies: 10 comments 2 replies
-
|
Comparison of Similarity in the Fix Text Field of the Checklists....
|
Beta Was this translation helpful? Give feedback.
-
|
Posted similarity analysis above between RHEL 9 and Amazon Linux 2023, as a lot of the STIGs are the same, just written slightly differently. I think it is all Fedora based, would be nice if all the common ones were 100% similarity, but not the case when things are hand jammed. |
Beta Was this translation helpful? Give feedback.
-
|
If you wanted to do the same analysis. Replace "rhel9" and "amazonlinux" with DISA STIG checklists converted to CSV. |
Beta Was this translation helpful? Give feedback.
-
|
I took that same approach to generate this.... I might be able to help more if guided in the right direction.... But, i copied in the highest similarity to RHEL 9 and created placeholders with "pending" status for where similarities do not exist. |
Beta Was this translation helpful? Give feedback.
-
|
I got the profile to build. I think I just need to go through each item to verify it is 100% correct. If this is not something desired here, I can create a fork, or just make a playbook for my own use. Just let me know how to proceed. @Mab879 |
Beta Was this translation helpful? Give feedback.
-
|
Thanks for for the work. Please feel free open PR to get some better feedback. Here few points I found based on a quick look:
|
Beta Was this translation helpful? Give feedback.
-
|
Hi @bordencastle , are you still working on a PR for this? I am happy to attempt it. |
Beta Was this translation helpful? Give feedback.
-
|
Good morning, has this received any progress? |
Beta Was this translation helpful? Give feedback.
-
|
@Mab879 @nessadc @ngearhart I started a PR here The profile runs, down to 12 rules coming back as N/A - still need to go through each check and make sure its doing the right thing |
Beta Was this translation helpful? Give feedback.
-
|
@Mab879 @nessadc @ngearhart @bordencastle I had to make a new PR since it was failing for having a merge request in commit... anyways I could use a hand in reviewing the rules, to test this is somewhat difficult, since AL2023 doesn't have the latest oscap, it needs to be built from source on the remote machine, and then use oscap-ssh to scan/remediate. i was able to get it to ~80%ish green
Steps to reproducePre-req
On the remote AL2023 VM
On local fedora box
|
Beta Was this translation helpful? Give feedback.

Uh oh!
There was an error while loading. Please reload this page.
-
Share the context
DISA Released Version 1 Release 1 of the Amazon Linux 2023 DoD STIG yesterday 09/04/2025
Description of problem:
It would be good to integrate this into complianceascode content.
Proposed change:
Add Amazon Linux 2023 DISA STIG to complianceascode content.
References:
Beta Was this translation helpful? Give feedback.
All reactions