---
title: DISA publishes STIG for Ubuntu 22.04 LTS
description: The Defense Information Systems Agency (DISA) has published their STIG
  for Ubuntu 22.04 LTS, free to download from the DOD Cyber Exchange.
url: https://canonical.com/blog/disa-stig-ubuntu-22-04-lts?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Henry Coggill](https://canonical.com/blog/author/henrycoggill "More about Henry Coggill")

18 April 2024

# DISA publishes STIG for Ubuntu 22.04 LTS

[DISA STIG](https://canonical.com/blog/tag/disa-stig)
[Ubuntu](https://canonical.com/blog/tag/ubuntu)
[USG](https://canonical.com/blog/tag/usg)

---

Share the article

## Introduction

DISA, the Defense Information Systems Agency, has [published](https://public.cyber.mil/announcement/disa-releases-the-canonical-ubuntu-22-04-lts-security-technical-implementation-guide/) their Security Technical Implementation Guide (STIG) for Ubuntu 22.04 LTS. The STIG is free for the public to download from the DOD [Cyber Exchange](https://public.cyber.mil/stigs/downloads/). Canonical has been working with DISA since we published Ubuntu 22.04 LTS to draft this STIG, and we are delighted that it is now finalised and available for everyone to use.

We’re pleased to now release the [Ubuntu Security Guide profile](https://ubuntu.com/blog/disa-stig-ubuntu-22-04-lts) to enable customers to automatically harden and audit their Ubuntu 22.04 LTS systems for the STIG.

## What is a STIG?

A STIG is a set of guidelines for how to configure an application or system in order to harden it. Hardening means reducing the system’s attack surface: removing unnecessary software packages, locking down default values to the tightest possible settings and configuring the system to run only what you explicitly require. System hardening guidelines also seek to lessen collateral damage in the event of a compromise.

STIGs are intended to be applied with judgement and common sense. Each mission or deployment is going to be different: where a piece of guidance doesn’t make sense for your specific needs, you can choose your own path forward whilst keeping the overall intentions of the STIG in mind.

The STIGs have been primarily developed for use within the US Department of Defense. However, because they are based on universally-recognised security principles, they can be used by anyone who wants a robust system hardening framework. As a result, STIGs are being more widely adopted across the US government and numerous industries, such as financial services and online gaming.

## When will Canonical publish a DISA-STIG USG profile?

The STIG that DISA has published is primarily composed of a manual XCCDF XML document that describes in human-readable words how to configure Ubuntu 22.04 LTS. This XML file contains nearly 200 individual pieces of guidance, which can be quite a daunting prospect to tackle from scratch. To simplify this process, Canonical produces the Ubuntu Security Guide (USG), an automation tool that handles both the checking and remediation of the STIG rules. USG is available as part of Ubuntu Pro, and can be enabled through the Pro client.

We’re pleased to now release the [Ubuntu Security Guide profile](https://ubuntu.com/blog/disa-stig-ubuntu-22-04-lts) to enable customers to automatically harden and audit their Ubuntu 22.04 LTS systems for the STIG.

## Conclusion

The STIG for Ubuntu 22.04 LTS will allow any users or administrators to harden their systems in accordance with this rigorous standard. Doing this by hand is a time-consuming proposition, so we recommend taking advantage of automated tooling to speed up the hardening and auditing process.

## Further resources

* [Maximizing security and compliance in the US public sector with Ubuntu Pro](https://ubuntu.com/engage/security-compliance-US-public-sector-FIPS-DISASTIG)
* [A guide to Infrastructure Hardening](https://ubuntu.com/engage/a-guide-to-infrastructure-hardening)
* [The Ubuntu Security Guide documentation](https://ubuntu.com/security/certifications/docs/usg)
* [Contact us](https://ubuntu.com/security/certifications#get-in-touch)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Arduino® VENTUNO™ Q is available for pre-order with Ubuntu pre-installed](https://canonical.com/blog/arduino-ventuno-q-is-available-for-pre-order-with-ubuntu-pre-installed)

London, UK – August 25, 2026 – Following our initial collaboration announcement in March 2026, Canonical and Arduino (a subsidiary of Qualcomm Technologies, Inc.) are excited...

[Canonical](https://canonical.com/blog/author/canonical)

25 August 2026

[### Canonical becomes Gold Sponsor of Trifecta Tech Foundation](https://canonical.com/blog/canonical-becomes-gold-sponsor-of-trifecta-tech-foundation)

Canonical is pleased to announce it is now a Gold Sponsor of the Trifecta Tech Foundation, a non-profit that creates open source building blocks for critical infrastructure...

[Canonical](https://canonical.com/blog/author/canonical)

30 June 2026

[### Ubuntu Summit 26.04: connected by open source](https://canonical.com/blog/ubuntu-summit-26-04-connected-by-open-source)

What an incredible experience! Ubuntu Summit 26.04 has officially drawn to a close, but the energy from our global community is still buzzing – in the comments section, on...

[ilvipero](https://canonical.com/blog/author/ilvipero)

22 June 2026

[### A decade of Ubuntu on IBM Z and IBM LinuxONE](https://canonical.com/blog/a-decade-of-ubuntu-on-ibm-z-and-ibm-linuxone)

This year we celebrate a decade of Ubuntu Server support on the s390x architecture: marking a long-standing collaboration between Canonical and IBM that began at LinuxCon 2015....

[Pedro Lazzarotto](https://canonical.com/blog/author/pedro-lazzarotto)

12 June 2026
