• disa-stig-v2r3
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • To Do
    • CMP-3732 - Bump DISA STIG to V2R3
    • CMP-3732Bump DISA STIG to V2R3
    • 0% To Do, 100% In Progress, 0% Done

      Epic Goal

      Version 2 Revision 3 (V2R3) of the OpenShift STIG was released on August 7th.

      http://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RH_OpenShift_Container_Platform_4-x_V2R3_STIG.zip

      According to rh-ee-alangsto's there isn't any changes to the content of the STIG besides the version and the name, so that it's not specific to OpenShift 4.12 anymore.

      We'll need to bump the version of the STIG profiles in the ComplianceAsCode/content repository and deprecate V2R2 so that we signal that change for users (since they have a 90-day window to start using the new version from the day it was published).

      Why is this important?

      DISA has a requirement where vendors and customers need to implement guidance within 90 days of publication.

      Acceptance Criteria

      • New version of the STIG is available from CO
      • V2R2 is deprecated in CO

              lbragsta@redhat.com Lance Bragstad
              lbragsta@redhat.com Lance Bragstad
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: