# nsacyber/Windows-Secure-Host-Baseline

Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber

Repository: https://github.com/nsacyber/Windows-Secure-Host-Baseline
Canonical: https://ross.abutalabs.com/products/windows-secure-host-baseline
Language: HTML
License: NOASSERTION
License Family: other
Topics: windows, windows-10, group-policy, nessus, windows-server, windows-server-2016, chrome-browser, adobe-reader, applocker, certificates, compliance, auditing, internet-explorer, microsoft-office, windows-firewall, audit
Archived: true
Last push: 2022-12-24T16:24:21+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3841, "days_push": 1348, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, archived, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1588, forks 288 (observed 2026-08-28T04:05:08.021209+00:00)

## What it is
NSA's Windows Secure Host Baseline provides configuration guidance and automation for deploying hardened Windows 10 and Windows Server 2016 per DoD security requirements. It includes Group Policy objects, compliance tooling, and settings for applications like Chrome, Adobe Reader, and Microsoft Office.

## Use cases
- harden windows 10 with group policy
- apply DoD secure host baseline settings
- audit windows server 2016 compliance
- configure applocker and windows firewall policies
- generate nessus audit files for windows compliance

## When to choose
- deploying Windows 10/Server 2016 in DoD or government environments
- needing authoritative hardening baselines with GPOs and audit content
- building organizational Windows security configuration from a proven framework

## When to avoid
- hardening Windows 11 or newer Windows Server versions
- non-Windows operating systems
- needing actively updated baselines for modern Windows releases

## Facets
- artifact type: infra-config
- maturity: maintenance
- function: configuration-management, security
- domain: security, windows, legal, developer-tools
- platform: windows
- tags: group-policy, dod, hardening, windows-10, windows-server-2016, applocker, nessus, compliance-guidance, auditing

## Member repositories
- nsacyber/Windows-Secure-Host-Baseline (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:08.021209+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:55:04.524421+00:00, confidence not recorded.
  - readme: https://github.com/nsacyber/Windows-Secure-Host-Baseline (fetched 2026-08-28T04:05:08.021209+00:00, sha ba7e5954a3e5)
- Data as of 2026-08-30T08:39:29.467469+00:00.
