United States (Department of Defense; used by other federal agencies and adopters)

DISA Security Technical Implementation Guides (STIGs)

72 controls. 3 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

72 controls 3 frameworks share controls with it United States (Department of Defense; used by other federal agencies and adopters) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
STIG-ASSESS-IVIndependent validation of STIG findings0
STIG-ASSESS-SCAPSCAP automated benchmark scanning1
STIG-ASSESS-VIEWERSTIG Viewer checklist execution0
STIG-GOV-CCICCI and NIST SP 800-53 traceability1
STIG-GOV-EMASSeMASS integration and reporting0
STIG-GOV-EXCException and risk acceptance (POA&M)1
STIG-GOV-TRAINSTIG-aware personnel training0
STIG-PGM-1STIG/SRG applicability determination and baseline2
STIG-PGM-2STIG and SRG currency and release management0
STIG-PGM-3Change control and configuration-drift prevention1
STIG-SEV-CAT1Category I (high severity) finding remediation0
STIG-SEV-CAT2Category II (medium severity) finding remediation0
STIG-SEV-CAT3Category III (low severity) finding remediation0
STIG-SRG-APPApplication and application server STIG0
STIG-SRG-BROWBrowser STIG0
STIG-SRG-CLDCloud, virtualization and container STIG0
STIG-SRG-DBDatabase STIG0
STIG-SRG-EPPEndpoint protection (antivirus/EDR) STIG0
STIG-SRG-MOBMobility and mobile device STIG0
STIG-SRG-NETNetwork device STIG hardening0
STIG-SRG-OSOperating system STIG hardening3
STIG-SRG-WEBWeb server STIG0
ASSESSAssessment with STIG Viewer checklists, automated results and the Applicability Guide0
ASSESS-1ASSESS-1 STIGs are consumed as XCCDF; STIG Viewer loads, searches, compares and exports them0
ASSESS-2ASSESS-2 A checklist per target with each rule set to Not a Finding, Open, Not Applicable or Not Reviewed0
ASSESS-3ASSESS-3 Severity overrides require a recorded reason and are marked0
ASSESS-4ASSESS-4 Import automated SCAP or XCCDF results, matched on Rule ID and revision, then complete the manual portion0
ASSESS-5ASSESS-5 The SRG/STIG Applicability Guide: an asset collection that determines the SRGs, STIGs and policy documents to apply0
DEVVendor STIG development, validation, approval and publication0
DEV-1DEV-1 Vendor STIG intent form, introductory meeting and DISA's decision point0
DEV-10DEV-10 The STIG overview document: executive summary, authority, severity codes, distribution, revisions, considerations, disclaimer, assessment considerations, terminology and gen0
DEV-2DEV-2 Orientation: resources, applicable SRGs and the requirements cheat sheet; six-month deferral if resources are unavailable0
DEV-3DEV-3 Stage 1: ten requirements across all four statuses within two weeks0
DEV-4DEV-4 Stages 2 and 3: work-in-progress submissions at 30 and 60 days0
DEV-5DEV-5 Stage 4: the completed initial draft within 90 days and DISA's four possible actions0
DEV-6DEV-6 Validation: DISA SME review, transition to a technology SME, and STIG simulation on the product0
DEV-7DEV-7 Access to the product for simulation and the product loan agreement0
DEV-8DEV-8 Review and approval: internal reviews, style guide, decision brief and DISA AO approval with any use restrictions0
DEV-9DEV-9 Publication: Configurable requirements published with an overview; the other statuses and the compliance report go to AOs as CUI0
PGMProgram authority, applicability, distribution and release cycle0
PGM-0The DISA SRG/STIG program: what it is, what is held and what is not modelled0
PGM-1PGM-1 Authority: DODI 8500.01 tasks DISA to develop SRGs, STIGs and CCIs and components to comply0
PGM-2PGM-2 NIST SP 800-53 controls per CNSSI 1253 apply beside the STIGs0
PGM-3PGM-3 All applicable SRGs and STIGs apply to a system, and product STIGs take precedence over the SRG0
PGM-4PGM-4 Test in a representative environment before production; unapplied settings need AO approval0
PGM-5PGM-5 The existence of a STIG is not DOD approval of the product0
PGM-6PGM-6 Distribution: unclassified content on public.cyber.mil, CUI content on cyber.mil with a CAC0
PGM-7PGM-7 Quarterly maintenance releases, out-of-cycle changes and the STIG Summary0
PGM-8PGM-8 The library compilation excludes drafts and sunset STIGs; mid-cycle releases are downloaded individually0
PGM-9PGM-9 Signed release memorandum for each STIG version0
REQThe STIG requirement record: identifiers, wording, status, severity, Check, Fix, mitigation and evidence0
REQ-1REQ-1 Every STIG requirement carries its IA control, CCI, SRG ID and, once finalised, its STIG ID0
REQ-10REQ-10 Status justification for Not Applicable, Does Not Meet and Inherently Meets rows0
REQ-11REQ-11 Additional rows: one row per setting or attack vector, and CCI-000366 for best practice0
REQ-2REQ-2 Requirement wording: must, the product's name, and 'must be configured to'0
REQ-3REQ-3 Vulnerability discussion: the risk of the requirement unmet, adapted to the product0
REQ-4REQ-4 Status: Applicable-Configurable, Applicable-Inherently Meets, Applicable-Does Not Meet or Not Applicable0
REQ-5REQ-5 Check text: exact validation steps ending in 'If ..., this is a finding'0
REQ-6REQ-6 Fix text: complete, specific, idempotent configuration steps with no finding statement0
REQ-7REQ-7 Severity: CAT I, II or III by the DISA category code definitions, verified by DOD SMEs0
REQ-8REQ-8 Mitigation for Does-Not-Meet requirements, with a residual-risk summary0
REQ-9REQ-9 Artifact description and evidence for Inherently-Meets claims0
SRGSecurity Requirements Guides: the CCI to SRG to STIG hierarchy and the general requirements of a technology SRG0
SRG-1SRG-1 CCIs are the discrete, measurable items sourced from NIST SP 800-53; SRGs sit between CCIs and STIGs0
SRG-2SRG-2 Four core SRGs, technology SRGs beneath them, product STIGs beneath those0
SRG-3SRG-3 SRG naming standard: core SRG, technology SRG and a five- or six-digit sequence0
SRG-4SRG-4 SRG compliance reporting: requirements a product cannot meet go to AOs as a CUI report0
SRG-5SRG-5 NDM SRG scope: the management plane of every network device, applied with the device's function SRG0
SRG-6SRG-6 NDM general requirements: out-of-band or leak-free management network, SNMPv3, logging to syslog, AAA, authenticated NTP, secure image and configuration storage0
SRG-7SRG-7 ASD STIG scope: all networked enterprise applications, DOD-developed and third-party, with the companion STIGs0
SRG-8SRG-8 ASD assessment inputs: application and system documentation, the SSP and the functionality review0
SRG-9SRG-9 ASD general requirements: code scanners whenever possible, application scanners regularly, mobile code by category0

Tell me when DISA Security Technical Implementation Guides (STIGs) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • VM hardening baselines
  • Golden image inventory
  • Drift reports
  • CIS benchmark scans
  • Change-control records for configuration changes
  • Drift-detection results and remediation

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for DISA Security Technical Implementation Guides (STIGs), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition