Asked by:
How to import current STIGs into SCCM

Question
-
All replies
-
Hi,
Based on my research, we can use the SCAP extensions or Security Compliance Manager tool.
Here is the link of SCAP extensions for your reference. https://docs.microsoft.com/en-us/configmgr/compliance/plan-design/scap/install-configure-scap#bkmk_convert-and-import
Best Regards,
TinaPlease remember to mark the replies as answers if they help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.
-
Check also the below blog
https://yeahsccmcandoit.blogspot.com/2016/11/scap-extensions-for-configuration.html
-
Hi,
How are things going? I just checked in to see if there are any updates. Please feel free to feedback and if the reply is helpful, please kindly click “Mark as answer”. It would make the reply to the top and easier to be found for other people who has the similar question.
Thank you for your kindly support.Best Regards,
TinaPlease remember to mark the replies as answers if they help. If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.
-
i have had success converting the 1.1 SCAP content using the SCAP extensions using the info found at the link you provided. That was because they had both the Benchmark-xccdf.xml and the Benchmark-cpe-dictionary.xml files.
However, when i go to https://iase.disa.mil/stigs/scap/Pages/index.aspx and download the new SCAP benchamarks they only have the STIG_SCAP_1-2_Benchmark.xml.
I have also tried using the Security Compliance Manager tool with no luck.
What am i misssing?
Mark Wood