DISA: Windows Server 2022


This topic provides information about the Defense Information Systems Agency (DISA) STIG template for Windows Server 2022, Version 1 release 3 published on June 7, 2023. This template contains implementation for 274 rules that can be installed on TrueSight Server Automation 20.x or later.

  • The existing customized template is renamed before you import the new one (by performing the steps given below).

Before you begin

Before you import this template, make sure that the following requirements are met:

  • Check the default values for the template's local and global properties and make sure that they meet the organization standards.
  • Rename any existing customized template before you import the latest template.
  • Back up the extended_objects folder located in the <APPRSERVER_INSTALL_DIR>/share/sensors directory on all the Application Servers in a multiple Application Server environment. This folder contains the extended object scripts.
  • Perform the following tasks before you run the compliance checks or perform remediation: 
    • When you run compliance jobs on domain controller targets, set the DOMAIN property of the target server to DC. 
    • Leave the DOMAIN property blank for member servers (non-domain systems) and standalone systems.
  • Copy the SecGuide custom templates (SecGuide.admx and SecGuide.adml) on all the target servers under the \Windows\PolicyDefinitions and the \Windows\PolicyDefinitions\en-US directories respectively.

    Important

    Some policy settings require the installation of the SecGuide custom templates included with the STIG package. These files can be downloaded from the Microsoft site. For more information, see How to create and manage the Central Store for Group Policy Administrative Templates in Windowson the Microsoft Learn website.

  • Copy the MSS-Legacy custom templates (MSS-Legacy.admx and MSS-Legacy.adml) on all the target servers under the \Windows\PolicyDefinitions and the \Windows\PolicyDefinitions\en-US directories respectively.

    Important

    Some policy settings require the installation of MSS-Legacy custom templates included with the STIG package. These files can be downloaded from the Microsoft site. For more information, see How to create and manage the Central Store for Group Policy Administrative Templates in Windowson the Microsoft Learn website.

Step 1: Download the files

  1. Access the following EPD link and click TSSA 23.2.00 DISA STIG Updates for Windows 2022 to download the DISA - Windows Server 2022 package:
    You must log in or register to view this page
  2. Expand to view the checksum-related information

    Verify the downloaded content by using checksums:

    S.No

    File Name

    MD5SUM

    1

    DISA - Windows Server 2022.zip

    a76fa54f562bab505288b6dc6694bab9

    2

    ExtendedObjects.zip

    45d12dab1ae76dac7adabb21bf514b57

  3. Extract the contents of the ExtendedObjects.zip file to a temporary directory and copy the extracted files to the existing <APPRSERVER_INSTALL_DIR>/share/sensors directory on all the Application Servers.
  4. Move the DISA_Windows_2022_V1R3_STIG.zip file to the server where the TrueSight Server Automation console is installed.

Step 2: Import the compliance content

  1. Log in to the TrueSight Server Automation console.
  2. Right-click Component Templates and select Import.
    component_templates.png
  3. Select the Import (Version-neutral) option and click OK.
    import_version_neutral.png
  4. Select the DISA - Windows Server 2022.zip package from the temporary location and click Next.
    The DISA template for DISA - Windows Server 2022 is available in the DISA - Windows Server 2022.zip  package.

    disa_windows_2022_zip.png

  5. Select the Update objects according to the imported package and Preserve template group path options, and click Next.
    template_selection.png
  6. Navigate to the last screen of the wizard and then click Finish.
    finish.png
  7. After the template is imported successfully, Click OK.
    The imported template is displayed under DISA Compliance Content > DISA STIG Revised.
    successful.png

Rules within the template

The 274 rules provided in the zip package contain the following types of rules:

  • Rules that check for compliance (audit) and provide remediation—192
  • Rules that check for compliance (audit) but do not provide remediation—36
  • Rules that do not check for compliance and do not provide remediation—46

The following are the details of the rules that are divided into parts:

  • Rules not divided into parts = 272
  • Rules divided into two parts (1 Rule) so (1* 2) = 2

The current rule count according to DISA Windows 2022 template after running the compliance job is 274 (272+2).

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*