Look at RHEL6/input/auxiliary/stig_overlay.xml. It has the latest mappings between DISA STIG IDs and SSG Rule IDs.
Regards, -- Leland Steinke, Security+ DISA FSO Technical Support Contractor tapestry technologies, Inc 717-267-5797 (DSN 570) [email protected] (gov't) [email protected] (com'l) > -----Original Message----- > From: [email protected] [mailto:scap- > [email protected]] On Behalf Of > [email protected] > Sent: Tuesday, December 17, 2013 1:12 PM > To: [email protected] > Subject: Cross DISA STIG to the SCAP Profiles > > Can anyone suggest a way I can cross the tests in the SCAP profiles > (specifically the stig-rhel6-server) with the tests in the official > DISA > STIG? I've looked through the various xml files as well as this > catalog > (http://people.redhat.com/swells/scap-security- > guide/RHEL6/output/rhel6-guide-custom.html). > I don't see any numbers that correspond between the two. The only way > I > can see to do it is read every test narrative and try to correlate the > two. > > The reason, I have an automated tool that has the full DISA stig loaded > that I'd like to modify to resemble the stig-rhel6-serve profile. The > tool can not import the SCAP content yet (should be able to soon > though), so in the meantime I'd like to make the DISA STIG look like > the > stig-rhel6-server profile as much as I can. Any suggestions? > _______________________________________________ > scap-security-guide mailing list > [email protected] > https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ scap-security-guide mailing list [email protected] https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide
