U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Windows Firewall STIG Version 1, Release 2 Checklist Details (Checklist Revisions)

Supporting Resources:

Target:

Target CPE Name
Microsoft Windows Server 2008 cpe:/o:microsoft:windows_server_2008:- (View CVEs)
Microsoft Windows Vista cpe:/o:microsoft:windows_vista (View CVEs)
Microsoft Windows Vista Firewall cpe:/a:microsoft:windows_firewall (View CVEs)

Checklist Highlights

Checklist Name:
Windows Firewall STIG
Checklist ID:
478
Version:
Version 1, Release 2
Type:
Compliance
Review Status:
Archived
Authority:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:
01/24/2014

Checklist Summary:

The Windows Firewall with Advanced Security Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DoD) information systems. Starting with Windows Vista and Windows Server 2008, Microsoft included the Windows Firewall with Advanced Security which provides significant enhancements over the previous Windows Firewall. This document provides guidance specifically for Windows Firewall with Advanced Security. Other firewall products that may be used will be addressed elsewhere. This document is meant for use in conjunction with the appropriate operating system (OS) STIGs.

Checklist Role:

  • Enterprise Firewall
  • Firewall

Known Issues:

Not provided.

Target Audience:

This document is a requirement for all DoD administered systems and all systems connected to DoD networks. These requirements are designed to assist Security Managers (SMs), Information Assurance Managers (IAMs), Information Assurance Officers (IAOs), and System Administrators (SAs) with configuring and maintaining security controls. This guidance supports DoD system design, development, implementation, certification, and accreditation efforts.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

DoD Directive (DoDD) 8500.1

Comments/Warnings/Miscellaneous:

Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.stig_spt@mail.mil. DISA Field Security Operations (FSO) will coordinate all change requests with the relevant DoD organizations before inclusion in this document.

Disclaimer:

Not provided.

Product Support:

Not provided.

Point of Contact:

disa.stig_spt@mail.mil

Sponsor:

Not provided.

Licensing:

Not provided.

Change History:

Changed status from "Under Review" to "Final" - 03 June 2015
Version 1, Release 1 - 24 January 2014
Updated URL to reflect change to the DISA website - http --> https
updated GPO file - 2/8/19
Status Updated to FINAL - 3/8/19

Dependency/Requirements:

URL Description

References:

Reference URL Description

NIST checklist record last modified on 12/12/2019