Sicura Enterprise Edition
  1. Introduction
  2. Licensing
  3. Installing SIMP EE
  4. Server install from RPM
  5. Server install from ISO
  6. Upgrade SIMP EE
  7. Server Installation via Control Repo
  8. Enable SIMP Compliance Engine
  9. Configure SIMP Compliance Engine
  10. Included Compliance Profiles
  11. Console install via Puppet
  12. Scanner Install via Puppet
  13. Simp-downloader script Reference
  14. Coverage - CIS, Windows
  15. Coverage - CIS, Linux
  16. Coverage - DISA, Windows
  17. Windows CIS module usage
  18. Linux CIS Module Usage

SIMP EE Coverage for Windows DISA STIG

JsCat scan results

The following scans were performed on a default installation of Windows with the SIMP Enterprise profile enforced.

Operating System Role Pass Fail N/A
Windows 2012 R2 Standalone 245 11 (6 false positives) 0
Windows 2012 R2 Domain Controller 258 10 (5 false positives) 0
Windows 2012 R2 Domain Member 245 11 (6 false positives) 0
Windows 2016 Standalone 173 5 25
Windows 2016 Domain Controller 187 8 12
Windows 2016 Domain Member 171 11 21
Windows 2019 Standalone 174 6 25
Windows 2019 Domain Controller 185 8 12
Windows 2019 Domain Member 172 12 21

Windows Coverage Report for DISA STIG

The following report details the status of each STIG Rule in the SIMP EE compliance data.

Summary

Operating System Unmapped Controls Paper Policy Mapped Total
Windows 2012 R2 60 (16%) 30 (8%) 284 (75%) 374
Windows 2016 11 (5%) 2 (0%) 190 (93%) 203
Windows 2019 11 (5%) 2 (0%) 192 (93%) 205

Detail

Unmapped Controls

The following controls are not currently enforced:

Windows 2012 R2 (60/374 [16%])

Windows 2016 (11/203 [5%])


Paper Policy

The following controls require policy or other administrative documentation that cannot be enforced:

Windows 2012 R2 (30/374 [8%])

Windows 2016 (2/203 [0%])

Windows 2019 (2/205 [0%])


Mapped

The following controls are mapped:

Windows 2012 R2 (284/374 [75%])

Windows 2016 (190/203 [93%])

Windows 2019 (192/205 [93%])