DISA Security Technical Implementation Guides
The Defense Information Systems Agency (DISA) develops Security Technical Implementation Guides (STIG) for the US Department of Defense (DoD). These STIGs are security configuration guides for hardening systems, intended for both civilian agencies and military organizations throughout the DoD. Once released by DISA their implementation is mandatory for DoD users, and their application is also relevant for private commercial applications.
SUSE Security Technical Implementation Guides
DISA has developed with SUSE a formal STIG for the following:
| Release | STIG | Date |
|---|---|---|
SUSE Linux Enterprise Server 12 |
01/22/2026 |
|
SUSE Linux Enterprise Server 12 STIG Benchmark |
01/22/2026 |
|
SUSE Linux Enterprise Server 15 |
01/22/2026 |
|
SUSE Linux Enterprise Server 15 with Ansible |
01/22/2026 |
|
SUSE Linux Enterprise Micro 5 |
01/22/2026 |
If you have any trouble downloading from this page, SUSE Linux Enterprise Server STIGs are also available directly from the DISA File Server. Simply enter "SUSE" in the search field.
Security Content Automation Protocols
SUSE also works collaboratively with DISA to produce Security Content Automation Protocols (SCAP) or Benchmarks. These permit organizations to automate vulnerability management and policy compliance evaluation.
DISA has developed with SUSE a formal SCAP for the following:
| Release | STIG | Date |
|---|---|---|
SUSE Linux Enterprise Server 12 |
01/22/2024 |
|
SUSE Linux Enterprise Server 15 |
01/21/2026 |
SUSE is also working to extend the STIG content with further roles. For more: https://documentation.suse.com/external-tree/en-us/suma/4.0/suse-manager/reference/audit/audit-openscap-overview.html