<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hardening on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/hardening/</link><description>Recent content in Hardening on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/hardening/index.xml" rel="self" type="application/rss+xml"/><item><title>CIS Benchmarks</title><link>https://lesitedefrancois.be/en/compliance/cis-benchmarks/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/cis-benchmarks/</guid><description>&lt;p&gt;&lt;strong&gt;CIS Benchmarks&lt;/strong&gt; are detailed, prescriptive security configuration guidelines published by the &lt;strong&gt;Center for Internet Security (CIS)&lt;/strong&gt;, a US-based non-profit organization. They are developed through a consensus process involving cybersecurity practitioners, vendors, and government agencies, and cover over 100 technology families — operating systems (Linux, Windows, macOS), cloud platforms (AWS, Azure, GCP), container orchestrators (Kubernetes, Docker), databases, web servers, and network devices. CIS Benchmarks are &lt;strong&gt;international&lt;/strong&gt; in applicability — they are not tied to any single jurisdiction — and are referenced by regulatory frameworks worldwide (NIST, PCI-DSS, HIPAA, FedRAMP, NIS2 national implementations). Each benchmark provides two recommendation levels: &lt;strong&gt;Level 1&lt;/strong&gt; (practical hardening that does not significantly impact functionality) and &lt;strong&gt;Level 2&lt;/strong&gt; (defense-in-depth settings for high-security environments). CIS Benchmarks are &lt;strong&gt;voluntary&lt;/strong&gt; — no law mandates CIS compliance directly — but they are frequently required by procurement contracts, industry standards, and as evidence of &amp;ldquo;reasonable security measures&amp;rdquo; in regulatory audits. The CIS also offers &lt;strong&gt;CIS Controls&lt;/strong&gt; (formerly the SANS Top 20), a prioritized set of cybersecurity best practices, and the &lt;strong&gt;CIS Hardened Images&lt;/strong&gt; program for pre-configured virtual machine images.&lt;/p&gt;</description></item><item><title>DISA STIG</title><link>https://lesitedefrancois.be/en/compliance/disa-stig/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/disa-stig/</guid><description>&lt;p&gt;&lt;strong&gt;DISA STIGs&lt;/strong&gt; (Security Technical Implementation Guides) are published by the &lt;strong&gt;Defense Information Systems Agency (DISA)&lt;/strong&gt;, the US Department of Defense (DoD) agency responsible for IT infrastructure security standards. STIGs provide extremely prescriptive, line-item security configuration requirements for specific technology products — each STIG contains hundreds of individual &amp;ldquo;findings&amp;rdquo; (rules) specifying exact settings, permissions, and configurations required to harden a system. Unlike flexible frameworks (NIST 800-53) or guideline-oriented benchmarks (CIS), STIGs are &lt;strong&gt;mandatory for all DoD information systems&lt;/strong&gt; and are referenced by the broader US federal government, defense contractors (via CMMC), and intelligence community systems. Each finding is categorized by severity: &lt;strong&gt;CAT I&lt;/strong&gt; (high — failure could directly lead to loss of confidentiality, integrity, or availability), &lt;strong&gt;CAT II&lt;/strong&gt; (medium), and &lt;strong&gt;CAT III&lt;/strong&gt; (low). Systems must achieve full CAT I compliance and substantially address CAT II/III findings to receive an Authority to Operate (ATO). DISA publishes STIGs for hundreds of products and regularly updates them (typically quarterly). STIGs are developed in collaboration with the vendor — Red Hat, for instance, works directly with DISA to produce the RHEL STIG — and are made available to the public through DoD Cyber Exchange (public.cyber.mil). STIG compliance is verified using DISA&amp;rsquo;s &lt;strong&gt;STIG Viewer&lt;/strong&gt; or automated tools like &lt;strong&gt;OpenSCAP&lt;/strong&gt; that consume the machine-readable XCCDF/SCAP content.&lt;/p&gt;</description></item></channel></rss>