NIST 800-53 Rev 5 Compliance Checklist for RHEL

Hello BigFix Community,

We are pleased to announce the release of a new compliance checklist within BigFix Compliance, designed to support the NIST Special Publication 800-53 Revision 5 framework.

As organizations, particularly in the US federal space, defense contracting, and regulated industries, work to align with NIST SP 800-53 Rev 5, we are expanding our compliance library to help you automate and audit technical security controls effectively across your RHEL environment.

What is the NIST 800-53 Rev 5 Compliance Checklist?

The NIST 800-53 Rev 5 Compliance Checklist is a new Checklist designed to assess and enforce compliance against the security and privacy controls defined in NIST 800-53 Revision 5 for RHEL.

This checklist maps technical controls directly to NIST 800-53 Rev 5 control families, allowing you to monitor, enforce, and report on your RHEL security posture against one of the most comprehensive federal security frameworks available.

Technical Snapshot

Here is a quick overview of the coverage provided in this release:

Total Fixlets: 867

Fixlets with Remediation: 698

Framework: NIST SP 800-53 Rev 5

Applies To: RHEL 8, 9, 10

Scope of Coverage

This checklist focuses on the technical controls that can be monitored and enforced via BigFix, mapped to NIST 800-53 Rev 5 control families. We currently support controls across 7 control families:

Access Control (AC) (Check Count: 123)

Account Management, Least Privilege, Access Enforcement, Access Control for Mobile Devices, System Use Notification, Remote Access

Audit and Accountability (AU) (Check Count: 183)

Protection of Audit Information, Event Logging, Audit Log Storage Capacity, Audit Record Generation, Time Stamps

Configuration Management (CM) (Check Count: 311)

Policy and Procedures, Configuration Settings, Software Usage Restrictions, User-Installed Software

Identification and Authentication (IA) (Check Count: 114)

Authenticator Management

Media Protection (MP) (Check Count: 7)

Media Use

System and Communications Protection (SC) (Check Count: 98)

Boundary Protection, Session Authenticity, Information in Shared System Resources, Transmission Confidentiality and Integrity, Least Functionality

System and Information Integrity (SI) (Check Count: 31)

Malicious Code Protection, System Monitoring, Memory Protection, Vulnerability Monitoring and Scanning

How to Get Started

The NIST 800-53 Rev 5 Checklist for RHEL is available now. To get started, subscribe to the content from the NIST 800-53 Rev 5 Checklist for RHEL external site and deploy it to your desired endpoints.

  1. Enable and gather the NIST 800-53 Rev 5 Checklist for RHEL external site from the License Overview Dashboard.
  2. Create a custom site using the Create Custom Checks wizard.
  3. Change the default parameters if required.
  4. If you use custom sites, update them accordingly to use the latest content. You can synchronize your content by using the Synchronize Custom Checks wizard. For more information, see Using the Synchronize Custom Checks wizard.
  5. Subscribe all the relevant RHEL (8/9/10) endpoints.
  6. Run SCA import to get the compliance status reports.

More information: To know more about the BigFix Compliance SCM checklists, please see the following resources:

BigFix Forum: https://forum.bigfix.com/c/release-announcements/compliance

BigFix Compliance SCM Checklists: https://forum.bigfix.com/c/release-announcements/scm-checklists/86

We are committed to helping you stay compliant with the latest regulatory frameworks. If you have questions regarding specific checks or need assistance with implementation, please feel free to reply to this thread.

– The BigFix Compliance Team