<div dir="ltr"><p class="MsoNormal" style="margin:0in 0in 14pt;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Product:</span></b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"><br>
BigFix Compliance</span></p>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Title:</span></b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"><br>
<span style="background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">Updated </span></span><span lang="EN" style="font-size:12pt;font-family:"Helvetica Neue";color:rgb(41,42,46);background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">DISA STIG Checklist for Oracle Linux 8</span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">.</span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"></span></p>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Security Benchmark:</span></b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"><br>
Disa Oracle Linux 8 STIG SCAP Benchmark, V2R7</span></p>
<p class="MsoNormal" style="margin:14pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Published Sites:</span></b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"><br>
</span><span lang="EN" style="font-size:10.5pt;font-family:"Helvetica Neue";color:rgb(41,42,46);background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">DISA STIG Checklist for
Oracle Linux 8</span><span lang="EN" style="font-size:12pt;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">, site version 12.</span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"><br>
<span style="background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial">(The site version is
provided for air-gap customers.)</span></span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Details:</span></b></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Total New Fixlets: 2</span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Total Updated Fixlets: 4</span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Total Deleted Fixlets: 1</span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Total Fixlets in Site: 366</span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">New Fixlets:</span></b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"></span></p>
<p class="MsoNormal" style="margin:0in 0in 0in 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">OL
8 must automatically exit interactive command shell user sessions after 10
minutes of inactivity.</span></p>
<p class="MsoNormal" style="margin:0in 0in 0in 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">OL
8 must not install packages from the Extra Packages for Enterprise Linux (EPEL)
repository</span></p>
<p class="MsoNormal" style="margin:0in 0in 0in 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"> </span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Updated Fixlets:</span></b></p>
<p class="MsoNormal" style="margin:0in 0in 12pt 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">The
OL 8 SSH server must be configured to use only Message Authentication Codes
(MACs) employing FIPS 140-3 validated cryptographic hash algorithms to protect
the confidentiality of SSH server connections</span></p>
<p class="MsoNormal" style="margin:0in 0in 12pt 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">The
OL 8 SSH server must be configured to use only DOD-approved encryption ciphers
employing FIPS 140-3 validated cryptographic hash algorithms to protect the
confidentiality of SSH server connections.</span></p>
<p class="MsoNormal" style="margin:0in 0in 12pt 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">The
OL 8 operating system must implement DOD-approved encryption in the OpenSSL
package.</span></p>
<p class="MsoNormal" style="margin:0in 0in 12pt 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">The
OL 8 file system automounter must be disabled.</span></p>
<p class="MsoNormal" style="margin:0in 0in 12pt;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"> </span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Deleted Fixlets:</span></b></p>
<p class="MsoNormal" style="margin:0in 0in 12pt 0.5in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">●<span style="font-variant-numeric:normal;font-variant-east-asian:normal;font-variant-alternates:normal;font-size-adjust:none;font-kerning:auto;font-feature-settings:normal;font-stretch:normal;font-size:7pt;line-height:normal;font-family:"Times New Roman"">
</span></span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Local
OL 8 initialization files must not execute world-writable programs.</span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"> </span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Additional details:</span></b></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif"><br>
</span></b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">● Both analysis and remediation
checks are included<br>
● Some of the checks allow you to use the parameterized setting to enable
customization for compliance evaluation. Note that parameterization and
remediation actions require the creation of a custom site.<br>
Improved a few checks by adding the pending restart feature to them. The
pending restart feature works in the following ways:<br>
● The action results will show “Pending Restart” instead of “Fixed” for those
checks which require OS reboot.<br>
● The check will show relevant for those endpoints until they are rebooted.<br>
<b>● </b>Post reboot of the endpoint the action results will show as “Fixed”
and the check will be compliant.</span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Actions to take:<br>
</span></b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">● To subscribe to the above
site, you can use the License Overview Dashboard to enable and gather the site.
Note that you must be entitled to the BigFix Compliance product and you must be
using BigFix version 10.0.2 and later.<br>
●If you use custom sites, update your custom sites accordingly to use the
latest content. You can synchronize your content by using the Synchronize
Custom Checks wizard. For more information, see </span><span lang="EN" style="color:black"><a href="https://help.hcltechsw.com/bigfix/11.0/compliance/Compliance/SCM_Users_Guide/c_using_synchronize_custom_checks_wiz.html"><span style="font-size:12pt;font-family:Calibri,sans-serif;color:rgb(0,136,204);text-decoration-line:none">Using the
Synchronize Custom Checks wizard</span></a></span><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif;color:rgb(0,136,204)"></span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">More information:<br>
</span></b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">To know more about the BigFix
Compliance SCM checklists, please see the following resources:</span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">● BigFix Forum:<br>
</span></b><span lang="EN" style="color:black"><a href="https://forum.bigfix.com/c/release-announcements/compliance"><b><span style="font-size:12pt;font-family:Calibri,sans-serif;color:rgb(0,136,204);text-decoration-line:none">https://forum.bigfix.com/c/release-announcements/compliance</span></b></a></span><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif;color:rgb(0,136,204)"></span></b></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">● BigFix Compliance SCM Checklists:<br>
</span></b><span lang="EN" style="color:black"><a href="https://bigfix-wiki.hcltechsw.com/wikis/home?lang=enus#!/wiki/BigFix%20Wiki/page/SCM%20Checklists"><b><span style="font-size:12pt;font-family:Calibri,sans-serif;color:rgb(0,136,204);text-decoration-line:none">Welcome to
Wikis</span></b></a></span><b><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif;color:rgb(0,136,204)"></span></b></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">We hope you find this latest release of SCM content
useful and effective.</span></p>
<p class="MsoNormal" style="margin:12pt 0in;line-height:normal;background-image:initial;background-position:initial;background-size:initial;background-repeat:initial;background-origin:initial;background-clip:initial;font-size:11pt;font-family:Arial,sans-serif"><span lang="EN" style="font-size:12pt;font-family:Calibri,sans-serif">Thank you!<br>
<i>– The BigFix Compliance team</i></span><span lang="EN" style="font-family:Calibri,sans-serif"></span></p></div>