One system, three hardening guides

A system follows the NIST SP 800-53 Revision 5 High baseline and hardening guides for Ubuntu, PostgreSQL and Microsoft 365. The three approaches model the same requirements, using every OSCAL model except the plan of action and milestones.

1. System and requirements

The comparison holds the system, baseline and hardening guides constant. Counts derive from the published source files and OSCAL schema constraints.

Framework
NIST SP 800-53 Revision 5, High baseline. 370 controls: 188 base and 182 enhancements, across 18 families.
Ubuntu
CIS Ubuntu 24.04 LTS Benchmark. 308 requirements in 53 sections.
PostgreSQL
DISA STIG PostgreSQL 16. 111 requirements in 111 activities, one per requirement.
Microsoft 365
CISA BOD 25-01 SCuBA. 128 requirements in 7 services.
Total requirements
547 hardening requirements alongside 370 regulatory controls, for 917 requirements across one system.

2. Files produced by each approach

Each tile represents one file. All three diagrams use the same tile size and grid to compare file counts. An unused model appears as a dashed line labelled none. File counts do not measure overall implementation effort.

Files by model, ordered by OSCAL layer from controls to assessment.
ModelCatalog-firstComponent-firstAssessment-first
catalog411
profile511
mapping-collection3nonenone
component-definition36none
system-security-plan111
assessment-plan114
assessment-results114
Total files181111
Models used7 of 76 of 75 of 7

2.1 Catalog-first, 18 files

Each guide becomes a catalog with a selection profile and a mapping collection linking guidance to the framework. The system security plan addresses every control in the merged set.

The system security plan addresses 917 controls: 370 from the framework and 547 from the guides. See Catalog-first for roles, tradeoffs and references.

2.2 Component-first, 11 files

Each guide becomes rules on the component being configured. Each checking engine becomes a separate validation component. The framework catalog and baseline profile remain unchanged.

The system security plan addresses 370 controls and contains 547 desired-state rules in components. See Component-first for roles, tradeoffs and references.

2.3 Assessment-first, 11 files

Each guide becomes an assessment plan with a separate assessment results document. The framework catalog and baseline profile remain unchanged.

The system security plan addresses 370 controls; all three guides remain in assessment plans. See Assessment-first for roles, tradeoffs and references.