#STIG

2026-01-07

Security shouldn't be a black box. πŸ“¦

We chatted with @AaronLippold from @MITREcorp about why SAF is open source: "It was built to solve a problem for everybody, not just us."

Read why collabs beat monetization in our latest blog: anchore.com/blog/stig-in-actio

#STIG #DevSecOps

λ‚¨μ •ν˜„rkttu@hackers.pub
2025-12-23

ν˜Ήμ‹œ μ—¬λŸ¬λΆ„μ€ .NET이 λ―Έ κ΅­λ°©λΆ€(DoD)의 κ°€μž₯ κΉŒλ‹€λ‘œμš΄ λ³΄μ•ˆ κ°€μ΄λ“œλΌμΈμΈ STIGλ₯Ό 100% μΆ©μ‘±ν•˜λŠ” κΈ°μˆ μ΄λΌλŠ” 사싀을 μ•Œκ³  κ³„μ…¨λ‚˜μš”?

κ·Έλ™μ•ˆ 'ꡰ용 μˆ˜μ€€μ˜ ν•˜λ“œλ‹'은 μ†Œμˆ˜μ˜ μ „λ¬Έκ°€λ§Œμ΄ λ§‰λŒ€ν•œ λ¦¬μ†ŒμŠ€λ₯Ό νˆ¬μž…ν•΄ ꡬ좕할 수 μžˆλŠ” 높은 성벽과도 κ°™μ•˜μŠ΅λ‹ˆλ‹€. ν•˜μ§€λ§Œ 이제 Docker와 .NET의 ν˜‘μ—…μœΌλ‘œ νƒ„μƒν•œ Docker Hardened Images(DHI)κ°€ κ·Έ μž₯벽을 ν—ˆλ¬Όμ—ˆμŠ΅λ‹ˆλ‹€.

πŸ›‘οΈ μ™œ .NET κ°œλ°œμžμ™€ 기업이 DHI에 μ£Όλͺ©ν•΄μ•Ό ν• κΉŒμš”?

κ²€μ¦λœ 기술의 정점: .NET은 이미 μ „ 세계 금육과 곡곡, κ΅­λ°© λΆ„μ•Όμ—μ„œ μ‹ λ’°λ°›λŠ” ν”Œλž«νΌμž…λ‹ˆλ‹€. DHIλŠ” 이 μ‹ λ’°λ₯Ό '인증'의 ν˜•νƒœλ‘œ κ°κ΄€ν™”ν–ˆμŠ΅λ‹ˆλ‹€.

λ³΄μ•ˆμ˜ λ―Όμ£Όν™”: STIG 100% μ€€μˆ˜, FIPS μ•”ν˜Έν™” 인증과 같은 졜고 λ“±κΈ‰μ˜ λ³΄μ•ˆ 섀정을 이제 λ³„λ„μ˜ λ³΅μž‘ν•œ κ³Όμ • 없이 베이슀 이미지 ꡐ체만으둜 μ¦‰μ‹œ μ μš©ν•  수 μžˆμŠ΅λ‹ˆλ‹€.

νƒ€ν˜‘ μ—†λŠ” μ™„κ²°μ„±: λ‹¨μˆœνžˆ 취약점을 μ€„μ΄λŠ” μˆ˜μ€€μ„ λ„˜μ–΄, 섀계 단계뢀터 λ³΄μ•ˆμ΄ λ‚΄μž¬λœ(Secure-by-Design) μ΅œμƒμ˜ 인프라λ₯Ό ν‘œμ€€ν™”λœ λ°©μ‹μœΌλ‘œ κ³΅κΈ‰λ°›κ²Œ λ©λ‹ˆλ‹€.

이제 .NET κ°œλ°œνŒ€μ€ "우리 μ„œλΉ„μŠ€κ°€ μ–Όλ§ˆλ‚˜ μ•ˆμ „ν•œκ°€?"λΌλŠ” μ§ˆλ¬Έμ— λŒ€ν•΄, "λ―Έ κ΅­λ°©λΆ€ ν‘œμ€€μ„ 100% μ€€μˆ˜ν•˜λŠ” ν•˜λ“œλ‹ κΈ°μˆ μ„ μ‚¬μš©ν•˜κ³  μžˆλ‹€"λŠ” κ°€μž₯ κ°•λ ₯ν•œ 닡변을 내놓을 수 μžˆμŠ΅λ‹ˆλ‹€.

κΈ€λ‘œλ²Œ μˆ˜μ€€μ˜ λ³΄μ•ˆ 경쟁λ ₯을 ν™•λ³΄ν•˜κ³  싢은 .NET 리더와 κ°œλ°œμžλΆ„λ“€μ„ μœ„ν•΄ μƒμ„Έν•œ κ°€μ΄λ“œμ™€ μΈμ‚¬μ΄νŠΈλ₯Ό κ³΅μœ ν•©λ‹ˆλ‹€.

πŸ”— 상세 λ‚΄μš© 보기: https://forum.dotnetdev.kr/t/docker-hardened-image-dhi-net/14171

#dotNET #λ‹·λ„· #λ³΄μ•ˆ #CyberSecurity #DHI #STIG #FIPS #μ—”ν„°ν”„λΌμ΄μ¦ˆ #λ””μ§€ν„ΈνŠΈλžœμŠ€ν¬λ©”μ΄μ…˜ #DevSecOps

Kushal Das :python: :tor: πŸ‡ΈπŸ‡ͺkushal@toots.dgplug.org
2025-11-04

Is there any good #opensource
Security Technical Implementation Guide #STIG viewer for #Linux? #security

2025-09-26

Tired of manual STIG compliance? 😩 Our on-demand webinar shows how to automate security validation for VMs and containers, saving you from paper checklists and endless audits.

Watch it here πŸ‘‰ go.anchore.com/webinar-stig-in #DevSecOps #STIG #Cybersecurity

2025-09-16

Tired of manual STIG compliance? 😩 Our on-demand webinar shows how to automate security validation for VMs and containers, saving you from paper checklists and endless audits.

Watch it here πŸ‘‰ go.anchore.com/webinar-stig-in #DevSecOps #STIG #Cybersecurity

Lexmilian S. R. B. de MelloPercarus@mastodon.au
2025-07-12
2025-06-18

Today we're excited to announce new investments in the πŸ‡ΊπŸ‡Έ U.S. Public Sector to enhance protection of #OT, #IoT, #IoMT and Facility-related control systems/Building Management Systems...

Introducing our enhanced #ExposureManagement and #Federal Information Security Modernization Act support with Security Technical Implementation Guide (#STIG)-hardened configuration management controls. These πŸ†• capabilities within Claroty Continuous Threat Detection (CTD) will enable greater efficiency and operational improvements across U.S. Federal Departments and Agencies, State, Local and Education, and the #defense industrial base, when protecting increasingly vulnerable CPS assets.

πŸ“° Read more: claroty.com/press-releases/cla

#PublicSector #PubSec #ClarotyFederal #BMS #FRCS #FISMA #SLED #DoD

2025-06-09

This episode of #OpenSourceSecurity I chat with Aaron Lippold from MITRE about #STIG automation (it's one big open source project)

STIG has historically been incredibly difficult and a bit of a niche space. Thanks to #FedRAMP it's getting more attention than ever before, and the work Aaron has been doing makes it a lot easier

opensourcesecurity.io/2025/202

2025-06-09

Stig's Iranian cousin!

#TopGear #Stig

Stig's Iranian cousin, dressing as an ayatollah.
2025-03-18

πŸ“’ T-30 MINUTES πŸ“’ Join our live webinar "STIG in Action with MITRE" where we'll dive deep with real-time demos on #STIG in real-world scenarios. Learn how Anchore and MITRE can help automate #compliance for #security and operations teams.

2025-03-17

πŸ“’ TOMORROW πŸ“’ Join our live webinar "STIG in Action with MITRE" where we'll dive deep with real-time demos on #STIG in real-world scenarios. Learn how Anchore and MITRE can help automate #compliance for #security and operations teams. Register now: get.anchore.com/webinar-stig-i

2025-03-14

⚑ Tech teams: Struggling with #STIG compliance? Join our webinar with MITRE and learn about the latest NIST and FedRAMP protocol and how to automate #STIG requirements and compliance in a live demo. Save your seat: get.anchore.com/webinar-stig-i

2025-03-10

πŸ” How are leading organizations implementing #STIG requirements at scale? Join our technical #webinar and live demo with Anchore and MITRE experts to see compliance automation in action. Reserve your spot: get.anchore.com/webinar-stig-i #SecurityCompliance #STIG

2025-03-07

πŸ“’ WEBINAR ALERT: Join us for "STIG in Action with MITRE" where we'll dive deep with real-time demos on #STIG in real-world scenarios. Learn how Anchore and MITRE can help automate compliance for security and operations teams. Register now: get.anchore.com/webinar-stig-i

2025-02-21

FYI, it looks like DISA released a new version of STIG viewer, if you use it grab it while you can.

public.cyber.mil/stigs/srg-sti
#stig #risk

2025-01-28

And we are live at #WEST2025 in San Diego. See us at booth #4227 where our team looks forward to discussing your #DevSecOps, #SBOMs, #STIG and #vulnerability scanning needs and show you the latest features of Anchore. Book time with us get.anchore.com/2025-01-afcea-

2025-01-27

T-1 for WEST 2025. If you are heading to San Diego - make sure to stop by our booth #4227 and learn more about our #SBOM powered #SCA solution. If you are running #containers - let's get you a live demo on how we secure them. Meet our experts on #DevSecOps, SBOMs, #STIG and compliance. Book time with us get.anchore.com/2025-01-afcea-

2025-01-18

Joining WEST 2025 in person? You will find us at booth #4227 where our team looks forward to discussing your #DevSecOps, #SBOMs, #STIG and v#ulnerability scanning needs and show you the latest features of Anchore. Book time with us today! get.anchore.com/2025-01-afcea-

2024-11-04

Ready to build security into your software from the ground up? See how @MITREcorp SAF helps you automate #STIG guidance and achieve #compliance efficiently. Full story here: anchore.com/blog/automate-stig #DevSecOps

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst