Harden

These open source community-based hardening baselines help to securely configure common system components. MITRE is helping to provide stewardship over these hardening baselines, hosted here and at other community vendor sites. If you are interested in new hardening baselines, please contact us at saf@groups.mitre.org.

Usage

The Hardening Library contents are hardening scripts that can be used in conjunction with orchestration tools such as Ansible or Chef recipes to harden system components against baselines. Specific usage instructions for each piece of hardening content can be found in their repository README files.

Cloud Service Providers
AWS CIS Benchmark | v2.0.0
Azure CIS Benchmark | v1.2.0
Virtual Platforms
Docker CIS Benchmark | v1.1.0
Docker CIS Benchmark | v1.1.0
Docker Enterprise 2.x STIG | v1r1
VMware VCSA 6.7 STIG | v1r2
VMware VCSA 7.0 STIG Readiness Guide | v1r4
VMware vSphere 6.5 STIG | v1r2
VMware vSphere 7.0 STIG Readiness Guide | v4r1
Operating Systems
Red Hat 7 STIG | v3r5
Red Hat 7 STIG | v3r5
Red Hat 8 CIS Benchmark | v2.0.0
Red Hat 8 STIG | v1r13
Red Hat 8 STIG | v1r13
SUSE 15 STIG | v1r9
Ubuntu 16.04 STIG | v1r1
Ubuntu 18.04 CIS Benchmark | v2.1.0
Ubuntu 18.04 LTS STIG | v2r10
Ubuntu 18.04 STIG | v2r10
Ubuntu 20.04 CIS Benchmark | v1.1.0
Ubuntu 20.04 LTS STIG | v1r6
Windows 10 STIG | v1r19
Windows 2008 Server CIS Benchmark | v3.3.0
Windows 2012 Domain Controller CIS Benchmark
Windows 2012 STIG | v12r2
Windows 2012 Server CIS Benchmark
Windows 2016 CIS Benchmark | v1.2.0
Windows 2016 STIG | v1r7
Windows 2016 STIG | v1r7
Windows 2016 STIG | v1r7
Windows 2019 CIS Benchmark | v1.3.0
Windows 2019 STIG | v2r1
Windows Server 2016 STIG | v1r3
Windows Server 2019 STIG | v1r2
Databases
MongoDB STIG | v1r2
PostgreSQL 12.x CIS Benchmark | v1.0.0
PostgreSQL 9.x STIG | v1r6
Network
Cisco IOS XE NDM/RTR STIG | v2r3
Cisco IOS XE Router STIG | v2r1
Juniper SRX SG STIG | v1r1
Application Logic
Elasticsearch
JRE 8 STIG | v1r3
Keycloak Custom Modules | v3r2
Web Servers
Apache CIS Benchmark | v2.0.0
Apache STIG | v2r2
IIS Server STIG | v1r5
IIS Sites STIG | v1r5
NGINX STIG Ready | v3r1
NGINX [WIP] | v1r9
Tomcat 9 STIG | v1r3
Tomcat CIS Benchmark | v1.0.1
Tomcat CIS Benchmark | v1.0.1
Tomcat CIS Benchmark | v1.0.1
Deploys by Netlify

Copyright © 1997-2026, The MITRE Corporation. All rights reserved.

MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.