Skip to main content
Public Sector

STIGs at Omnissa

STIGs are proscriptive hardening guides that map directly to NIST 800-53 and are authoritative for all DoD entities.

Products in scope 

In partnership with DISA, Omnissa develops and maintains STIGs for our flagship offerings, Workspace ONE UEM and Horizon with UAG. These products are well established in the U.S. DoD, and demand for them is high enough to warrant DISA prioritizing time and resources for STIG development. Because DISA cannot prioritize all products for a formal STIG, products that do not have a STIG will receive Omnissa-developed hardening content. These hardening guides will be similar to an official STIG in form and function in order to support customer configuration requirements.   

Workspace ONE UEM 

The Workspace ONE UEM STIG can be downloaded from www.cyber.mil. Enter “Omnissa” in the search box and download the latest version and revision of the STIG. This STIG was developed against the FedRAMP offering of UEM and is only directly applicable there. Older, on-premises UEM installations are not addressed by this STIG but may be able to make it work with some manipulations.

The publication of the Workspace ONE UEM STIG demonstrates the commitment Omnissa has to the needs of our US Federal customer base, specifically, but also more broadly to security-conscious customers everywhere. STIGs are public documents available for anyone to use. They are commonly implemented across security-conscious market segments like financial/banking, state/local, foreign governments, healthcare and more. A STIG is a detailed answer to the question “How can I deploy and operate this product securely?”.

Importantly, development of this STIG included verification that the properly STIG-configured UEM environment is fully functional with properly STIG-configured endpoints. With this publication, customers can STIG harden their full MDM enterprise from the Workspace ONE application to managed endpoints on iOS, Android, Windows, MacOS, and iPadOS.

Horizon 

The Horizon STIG is in process with DISA. It is projected to be published on www.cyber.mil in September 2026. The Horizon STIG will apply to version 8, circa 2026 releases, and will be kept forward-compatible. It will include component STIGs for the Connection Server, Client, Agent, and the Unified Application Gateway (UAG) as deployed in a Horizon configuration. This website will be updated when the STIG is finalized and posted.

Frequently asked questions about FIPS 140-3 at Omnissa

As mentioned above, the primary roadblock to new STIGs for other products is government prioritization and resourcing. If you have a strong need for a STIG for an Omnissa product or service, please contact your Omnissa account representatives and DISA.

DISA updates STIGs on a quarterly basis, outside of some critical need. Not every STIG gets an update, but if an update is needed, it is generally done four times a year.

You are now being redirected to an external domain. This is a temporary redirect while we build our new infrastructure and rebrand our legacy content.

This message will disappear in 10 seconds

CONTINUE