RHEL 10 gains automated scanning and remediation for DISA STIG V1R2
SCAP Security Guide 0.1.82 aligns the RHEL 10 profile with the official benchmark and makes it usable across OpenSCAP, Satellite and Red Hat Lightspeed.
Red Hat has released an automated compliance profile for Red Hat Enterprise Linux 10 that follows the official Defense Information Systems Agency Security Technical Implementation Guide, replacing the earlier vendor profile with content aligned to RHEL 10 DISA STIG Benchmark V1R2.
The profile ships in scap-security-guide 0.1.82. Red Hat’s release notes say the update brings the RHEL 10 profile into line with the official benchmark; the same release also updates the RHEL 8 and RHEL 9 DISA profiles to V2R8 and V2R9, respectively.
What administrators can automate
According to Red Hat’s announcement, administrators can use the stig or stig_gui profile to evaluate and remediate RHEL 10 systems through OpenSCAP’s oscap command, Red Hat Satellite or Red Hat Lightspeed. Red Hat also points to an official RHEL 10 STIG Ansible role for applying the controls.
The same content can be used earlier in the system lifecycle. Red Hat says organizations can apply STIG hardening through Kickstart, RHEL image builder and RHEL image mode rather than treating compliance as a post-install cleanup task. For platform teams, that creates a path to put the benchmark into repeatable image pipelines and provisioning workflows.
Version 0.1.82 also improves RHEL 10 remediation scripts so that newly created files and directories receive explicit owners and permissions, and adds rationale to the rule requiring the SSSD package, according to the SCAP Security Guide notes.
Automation is not certification
The new profile automates technical checks and remediations; it does not certify a deployed environment. Red Hat explicitly says administrators and security officers still need to review findings in the context of their operational environment to establish compliance.
That distinction matters for teams pursuing an Authority to Operate. The profile can make assessment, remediation and evidence collection more repeatable, but organizations remain responsible for interpreting results, documenting exceptions and satisfying controls that cannot be reduced to host configuration.
sources
- Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2www.redhat.com
- SCAP Security Guide release notesaccess.redhat.com
comments · 0