The Importance of STIG Configuration
Security Technical Implementation Guides (STIGs) developed by software vendors and validated by the Defense Information Systems Agency (DISA) are critical for securing Department of War (DOW) information systems against cybersecurity vulnerabilities. STIGs provide standardized, configurable security guidance to ensure IT assets are hardened and consistent with federal cybersecurity standards including NIST 800-53.
Implementing STIG configurations helps prevent unauthorized access and safeguards system confidentiality, availability, and integrity. Many programs require STIG compliance for obtaining an Authority to Operate (ATO).
Official STIG documentation and guidance are published on the DOW Cyber Exchange at cyber.mil.
The Harvester Government STIG is Now Available
It’s been a long time coming. After close collaboration with DISA, Rancher Government Solutions (RGS) is excited to announce the official publication and general availability of the Harvester Government STIG! As a hyperconverged infrastructure (HCI) virtualization platform, Harvester Government has many essential components to configure, particularly the Operating System (OS) and Kubernetes layers of the architecture. This STIG combines several DISA Security Requirements Guides (SRGs) to ensure comprehensive coverage across the Harvester Government platform.
Why This STIG is Unique
Harvester Government is pre-configured by our product engineering team into a STIG compliant state. Exclusive to Rancher Government customers via the Carbide platform, Harvester Government builds have all the necessary OS and Kubernetes configurations implemented out of the box, simplifying the operational complexity of maintaining compliance. Instead of manually implementing fixes and ensuring they persist across the system, you can simply install Harvester Government in its default, immutable state.
Getting Started
The Harvester Government STIG has two main components, core infrastructure (OS and Kubernetes) and Container Management. For the core infrastructure, the platform is pre-configured to a STIG-compliant state. Simply run through the checks manually or utilize the provided validation script and verify the output. For the Container Management portion, configure the Rancher Manager cluster managing Harvester Government with the appropriate settings detailed in the STIG. This provides flexibility to customers, with support for integration into many third-party tools to help them meet their needs.
As always, the RGS team is here to help. If you’re an existing customer, reach out to our support team with any questions. If you’re interested in the secure Harvester Government platform, please reach out to our sales team.
