Validate

These open source community-based InSpec profiles validate the security of common system components. MITRE is helping to provide stewardship over these profiles, hosted here and at other community vendor sites. If you are interested in new profiles, please contact us at saf@groups.mitre.org. If you are interested in developing and contributing your own profiles, please see our training material. All assessment tests under MITRE SAF © are associated with NIST SP 800-53 Security Controls.

Usage

The Validation Library contents are collections of test definitions that can be used in conjunction with testing tools such as Progress Chef recipes to validate system components against baselines. Specific usage instructions for each piece of validation content can be found in their repository README files.

Cloud Service Providers
AWS CIS | v2.0.0
AWS RDS Best Practices Benchmark
AWS RDS CIS | v1.0.0
AWS S3 Best Practices Benchmark | n/a
GCP CIS Benchmark | v1.2.0
GCP PCI-DSS 3.2.1 | v3.2.1
GKE CIS Benchmark | v1.1.0
Virtual Platforms
Docker CE CIS | v1.1.0
K3s Cluster STIG | v1r1
K3s Node STIG | v1r1
Kubernetes CIS | v1.1.0
Kubernetes Cluster STIG | v1r1
Kubernetes Node STIG | v1r1
VMware ESXI 6.5 STIG | v1r1
VMware ESXI 6.7 STIG | v1r2
VMware VCSA 6.7 STIG | v1r2
VMware VCSA 7.0 STIG Readiness Guide | v1r4
VMware vSphere 7.0 STIG Readiness Guide | v4r1
VMware vSphere VM 6.7 STIG | v1r2
Operating Systems
Red Hat 6 STIG | v1r21
Red Hat 7 STIG | v3r5
Red Hat 8 STIG | v1r13
Red Hat CVE Scan | n/a
Ubuntu 16.04 STIG | v1r1
Ubuntu 20.04 STIG | v1r6
Windows 10 STIG | v1r19
Windows 2012 STIG | v12r2
Windows 2016 STIG | v1r7
Windows 2019 STIG | v2r1
Databases
AWS MSQL 2014 STIG | v1r9
AWS RDS MySQL 5.7 CIS | v1.0.0
AWS RDS Oracle Database 12c STIG | v2r1
AWS RDS PostgreSQL 10+ STIG | v1r1
AWS RDS PostgreSQL 9.x STIG | v1r6
MSQL 2014 Database STIG | v1r6
MSQL 2014 Instance STIG | v1r9
MongoDB STIG | v1r2
Oracle Database 12c STIG | v1r12
Oracle Database 19c CIS | v1.0.0
Oracle MySQL 5.7 CIS | v1.0.0
Oracle MySQL 8.0 STIG | v1r1
PostgreSQL 10+ STIG | v1r1
PostgreSQL 9.x STIG | v1r6
Network
Application Logic
JRE 7 STIG | v1r6
JRE 8 STIG | v1r3
RSA Archer 6 SCG | 6.x
Red Hat Jboss EAP 6.3 STIG | v1r3
Web Servers
Apache Server 2.2 STIG | v1r10
Apache Server 2.4x STIG | v2r2
Apache Site 2.2 STIG | v1r10
Apache Site 2.4x STIG | v2r1
Apache Tomcat 9.x STIG | v2r1
DRAFT: Tomcat 7 CIS | v1.0.1
DRAFT: Tomcat 8 CIS | v1.0.1
IIS 8.5 Server STIG | v1r5
IIS 8.5 Site STIG | v1r5
NGINX Baseline | v1r9
NGINX STIG Ready Baseline | v3r1
Deploys by Netlify

Copyright © 1997-2026, The MITRE Corporation. All rights reserved.

MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.