Skip to content
This repository has been archived by the owner on Jun 13, 2023. It is now read-only.

STIGs VS SHB #22

Closed
onedererer opened this issue Jan 25, 2017 · 5 comments
Closed

STIGs VS SHB #22

onedererer opened this issue Jan 25, 2017 · 5 comments
Labels

Comments

@onedererer
Copy link

Are the policies contained within the SHB a mirror of the DISA STIGs for those applications/operating system or is there additional development/tweaks that are done? Thank you in advance.

@iadgovuser1
Copy link
Contributor

Generally, they are the STIGs but sometimes there may be additional configuration settings included. For example, the IE trusted sites list is configured to trust a bunch of .gov and .mil sites. This is not in the IE STIG, but it is included in the IE GPO for the SHB.

@onedererer
Copy link
Author

onedererer commented Jan 25, 2017

I ask because in a comparison of the Adobe Acrobat Reader DC Continuous Track STIG - Ver 1, Rel 2 to the SHB policy, I find the below STIG IDs missing

ARDC-CN-000070
ARDC-CN-000115
ARDC-CN-000310
ARDC-CN-000315
ARDC-CN-000325
ARDC-CN-000330
ARDC-CN-000330
ARDC-CN-000345

Just checking if this is by design or not.

@iadgovuser1
Copy link
Contributor

iadgovuser1 commented Jan 25, 2017

My quick investigation leads me to believe that they are using the "continuous" version for the install, but are using the "classic" version of the STIG in their GPO. Originally, the SHB Framework developers were using the classic version of Adobe Reader but we got them to switch to the continuous version because of the security benefits. It may be that they never changed their GPO settings from classic to continuous. I will bring this up tomorrow during the SHB conference call.

@iadgovuser1
Copy link
Contributor

iadgovuser1 commented Jan 25, 2017

I also just checked the latest SHB 10.1 GPOs and they don't provide an Adobe Reader GPO so we will need to provide an updated GPO here.

There are a few non-security settings in the Adobe Reader STIG that shouldn't be in the STIG. DISA had said they were going to remove them, but then they never ended up removing them. I think that might account for a couple settings like the welcome screen (ARDC-CN-000115), repair dialog settings (ARDC-CN-000070), and maybe the certificate settings (ARDC-CN-000330 and ARDC-CN-000335). For ARDC-CN-000340, it isn't an actual setting.

@iadgovuser1
Copy link
Contributor

I'm closing this out since I consider #24 and #25 to be the actual work for this.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

2 participants