U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Microsoft Windows Server 2016 STIG Version 2, Release 9 Checklist Details (Checklist Revisions)

SCAP 1.2 Content:

Supporting Resources:

Target:

Target CPE Name
Microsoft Windows Server 2016 cpe:/o:microsoft:windows_server_2016:- (View CVEs)

Checklist Highlights

Checklist Name:
Microsoft Windows Server 2016 STIG
Checklist ID:
753
Version:
Version 2, Release 9
Type:
Compliance
Review Status:
Final
Authority:
Governmental Authority: Defense Information Systems Agency
Original Publication Date:
01/21/2017

Checklist Summary:

The Windows Server 2016 Security Technical Implementation Guide (STIG) is published as a tool to improve the security of Department of Defense (DoD) information systems. The requirements were developed by DoD Consensus as well as Windows security guidance by Microsoft Corporation. This document is meant for use in conjunction with other applicable STIGs including such topics as Active Directory Domain, Active Directory Forest, and Domain Name Service (DNS). The Windows Server 2016 STIG includes requirements for both domain controllers and member servers/standalone systems. Requirements specific to domain controllers have “DC” as the second component of the STIG IDs. Requirements specific to member servers have “MS” as the second component of the STIG IDs. All other requirements apply to all systems.

Checklist Role:

  • Desktop and Server Operating System

Known Issues:

Not provided.

Target Audience:

This checklist is primarily for IT generalists, security specialists, network architects, and other IT professionals and consultants who plan application or infrastructure development and deployments of Windows 8 and BitLocker for both desktop and laptop client computers in an enterprise environment.

Target Operational Environment:

  • Managed
  • Specialized Security-Limited Functionality (SSLF)

Testing Information:

Not provided.

Regulatory Compliance:

DoD Instruction (DoDI) 8500.01

Comments/Warnings/Miscellaneous:

Not provided.

Disclaimer:

Not provided.

Product Support:

disa.stig_spt@mail.mil

Point of Contact:

disa.stig_spt@mail.mil

Sponsor:

Not provided.

Licensing:

Not provided.

Change History:

Updated to FINAL - 03/13/2017
null
Updated URL to reflect change to the DISA website - http --> https
Updated - 11/01/2017
Updated to FINAL - 12/02/2017
corrected resource title - 1/24/2018
Updated to Version 1, Release 3 - 02/16/2018
Updated to FINAL - 3/18/2018
updated to v1,r4 - 4/25/18
Updated to FINAL - 5/27/18
updated to Version 1, Release 5 - 7/24/18
Added GPOs - 8/6/18
Updated to FINAL - 9/6/2018
Updated to Version 1, Release 6 - 10/25/18
Updated to FINAL - 11/26/18
Updated GPO Resource - 11/29/2018
Corrected SHA for GPO file - 12/19/2018
Resource Title Update - 12/21/2018
null
updated to Version 1, Release 7- 1/28/19
updated benchmark - 1/29/19
updated GPO file - 2/8/19
Status Updated to FINAL - 3/8/19
updated to Version 1, Release 8 - 4/30/19
Updated GPO resource - 5/2/19
Updated to FINAL  - 6/4/19
Updated URLs - 6/12/19
Updated URLs - 8/12/2019
Updated GPO file - 10/31/19
updated URLs - 11/1/19
updated to V1, R12 - removed reference link per DISA - 1/17/2020
Updated GPO file per DISA - 1/29/2020

Dependency/Requirements:

URL Description

References:

Reference URL Description

NIST checklist record last modified on 01/29/2020