Security

Any update on STIG guidance for current Splunk versions?

aoliver
Engager

Hello,

I’m a Splunk admin supporting a government environment. We’ve historically used both the STIGs and the SRGs to help meet compliance requirements.

With Splunk  STIGs 7.x and 8.x now sunset, I’m trying to understand whether Cisco plans to publish an updated set of STIGs for newer Splunk versions. At the moment, the SRG appears to reference a Centralized Log Server rather than Splunk specifically, which leaves some room for interpretation.

I’m interested in whether anyone has seen official guidance, an updated roadmap, or any discussion around compliance support for current Splunk Enterprise releases.

A few specific questions:

  • Is Cisco planning to release updated STIGs for supported Splunk versions?
  • If not, is the expectation that organizations should map current Splunk deployments to the existing Centralized Log Server SRG?
  • Has anyone successfully navigated compliance or accreditation for newer Splunk versions using the SRG alone?
  • Are there any accepted best practices, overlays, or compensating control approaches the community is using in the absence of updated Splunk-specific STIGs?
Labels (1)
Tags (1)

i_abreu7
Engager

I second this - Any guidance or information surrounding this exact issue would be greatly appreciated!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...