Rocky Linux 9 STIG-Hardened

Azure Operating Systems

Rocky Linux 9 STIG-Hardened, a free RHEL 9 compatible enterprise Linux base with the DISA STIG profile applied and measured at build time.

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

Rocky Linux is a community owned enterprise Linux distribution built by the Rocky Enterprise Software Foundation to be binary compatible with Red Hat Enterprise Linux 9. This edition takes that base further: the DISA STIG (Security Technical Implementation Guide) profile from the SCAP Security Guide project is applied at build time using the same open source oscap engine a customer would run themselves, then the machine is re-scanned cleanly, after a reboot, to produce a real, measured compliance score rather than an assumed one.

The scanner, the policy content and the machine readable evidence all ship on the image, so you start from a hardened, provably measured baseline instead of spending the first days of a project applying and re-deriving the same controls yourself.

Why the cloudimg image

The cloudimg image ships the DISA STIG remediation report, the machine readable results and the exact measured pass rate under /var/log/cloudimg/stig, generated after a full reboot so the numbers reflect what the machine actually boots into, not a pre-reboot snapshot. A scheduled, audit only re-check runs on your own instance after first boot and weekly after that, so you can see drift over time without re-deriving the baseline. Every control that would break Azure provisioning if applied blindly is documented and explained, not silently skipped: SSH stays key only so cloud-init and your own login both keep working, and the small number of excluded checks (an interactive boot loader password step, and full kernel FIPS mode, deferred rather than half-applied) are named in the guide. No baked in credential: access is by the SSH key you choose at launch, backed by 24/7 support.

Common uses

  • A pre-hardened RHEL compatible base for regulated or government-adjacent workloads that need DISA STIG controls applied and evidenced
  • A measured starting point for a compliance programme, with a real report instead of a checklist claim
  • A lean, patchable foundation for production servers where both security posture and provable evidence of it matter