STIG-ASSESS-IV | Independent validation of STIG findings | 0 |
STIG-ASSESS-SCAP | SCAP automated benchmark scanning | 1 |
STIG-ASSESS-VIEWER | STIG Viewer checklist execution | 0 |
STIG-GOV-CCI | CCI and NIST SP 800-53 traceability | 1 |
STIG-GOV-EMASS | eMASS integration and reporting | 0 |
STIG-GOV-EXC | Exception and risk acceptance (POA&M) | 1 |
STIG-GOV-TRAIN | STIG-aware personnel training | 0 |
STIG-PGM-1 | STIG/SRG applicability determination and baseline | 2 |
STIG-PGM-2 | STIG and SRG currency and release management | 0 |
STIG-PGM-3 | Change control and configuration-drift prevention | 1 |
STIG-SEV-CAT1 | Category I (high severity) finding remediation | 0 |
STIG-SEV-CAT2 | Category II (medium severity) finding remediation | 0 |
STIG-SEV-CAT3 | Category III (low severity) finding remediation | 0 |
STIG-SRG-APP | Application and application server STIG | 0 |
STIG-SRG-BROW | Browser STIG | 0 |
STIG-SRG-CLD | Cloud, virtualization and container STIG | 0 |
STIG-SRG-DB | Database STIG | 0 |
STIG-SRG-EPP | Endpoint protection (antivirus/EDR) STIG | 0 |
STIG-SRG-MOB | Mobility and mobile device STIG | 0 |
STIG-SRG-NET | Network device STIG hardening | 0 |
STIG-SRG-OS | Operating system STIG hardening | 3 |
STIG-SRG-WEB | Web server STIG | 0 |
ASSESS | Assessment with STIG Viewer checklists, automated results and the Applicability Guide | 0 |
ASSESS-1 | ASSESS-1 STIGs are consumed as XCCDF; STIG Viewer loads, searches, compares and exports them | 0 |
ASSESS-2 | ASSESS-2 A checklist per target with each rule set to Not a Finding, Open, Not Applicable or Not Reviewed | 0 |
ASSESS-3 | ASSESS-3 Severity overrides require a recorded reason and are marked | 0 |
ASSESS-4 | ASSESS-4 Import automated SCAP or XCCDF results, matched on Rule ID and revision, then complete the manual portion | 0 |
ASSESS-5 | ASSESS-5 The SRG/STIG Applicability Guide: an asset collection that determines the SRGs, STIGs and policy documents to apply | 0 |
DEV | Vendor STIG development, validation, approval and publication | 0 |
DEV-1 | DEV-1 Vendor STIG intent form, introductory meeting and DISA's decision point | 0 |
DEV-10 | DEV-10 The STIG overview document: executive summary, authority, severity codes, distribution, revisions, considerations, disclaimer, assessment considerations, terminology and gen | 0 |
DEV-2 | DEV-2 Orientation: resources, applicable SRGs and the requirements cheat sheet; six-month deferral if resources are unavailable | 0 |
DEV-3 | DEV-3 Stage 1: ten requirements across all four statuses within two weeks | 0 |
DEV-4 | DEV-4 Stages 2 and 3: work-in-progress submissions at 30 and 60 days | 0 |
DEV-5 | DEV-5 Stage 4: the completed initial draft within 90 days and DISA's four possible actions | 0 |
DEV-6 | DEV-6 Validation: DISA SME review, transition to a technology SME, and STIG simulation on the product | 0 |
DEV-7 | DEV-7 Access to the product for simulation and the product loan agreement | 0 |
DEV-8 | DEV-8 Review and approval: internal reviews, style guide, decision brief and DISA AO approval with any use restrictions | 0 |
DEV-9 | DEV-9 Publication: Configurable requirements published with an overview; the other statuses and the compliance report go to AOs as CUI | 0 |
PGM | Program authority, applicability, distribution and release cycle | 0 |
PGM-0 | The DISA SRG/STIG program: what it is, what is held and what is not modelled | 0 |
PGM-1 | PGM-1 Authority: DODI 8500.01 tasks DISA to develop SRGs, STIGs and CCIs and components to comply | 0 |
PGM-2 | PGM-2 NIST SP 800-53 controls per CNSSI 1253 apply beside the STIGs | 0 |
PGM-3 | PGM-3 All applicable SRGs and STIGs apply to a system, and product STIGs take precedence over the SRG | 0 |
PGM-4 | PGM-4 Test in a representative environment before production; unapplied settings need AO approval | 0 |
PGM-5 | PGM-5 The existence of a STIG is not DOD approval of the product | 0 |
PGM-6 | PGM-6 Distribution: unclassified content on public.cyber.mil, CUI content on cyber.mil with a CAC | 0 |
PGM-7 | PGM-7 Quarterly maintenance releases, out-of-cycle changes and the STIG Summary | 0 |
PGM-8 | PGM-8 The library compilation excludes drafts and sunset STIGs; mid-cycle releases are downloaded individually | 0 |
PGM-9 | PGM-9 Signed release memorandum for each STIG version | 0 |
REQ | The STIG requirement record: identifiers, wording, status, severity, Check, Fix, mitigation and evidence | 0 |
REQ-1 | REQ-1 Every STIG requirement carries its IA control, CCI, SRG ID and, once finalised, its STIG ID | 0 |
REQ-10 | REQ-10 Status justification for Not Applicable, Does Not Meet and Inherently Meets rows | 0 |
REQ-11 | REQ-11 Additional rows: one row per setting or attack vector, and CCI-000366 for best practice | 0 |
REQ-2 | REQ-2 Requirement wording: must, the product's name, and 'must be configured to' | 0 |
REQ-3 | REQ-3 Vulnerability discussion: the risk of the requirement unmet, adapted to the product | 0 |
REQ-4 | REQ-4 Status: Applicable-Configurable, Applicable-Inherently Meets, Applicable-Does Not Meet or Not Applicable | 0 |
REQ-5 | REQ-5 Check text: exact validation steps ending in 'If ..., this is a finding' | 0 |
REQ-6 | REQ-6 Fix text: complete, specific, idempotent configuration steps with no finding statement | 0 |
REQ-7 | REQ-7 Severity: CAT I, II or III by the DISA category code definitions, verified by DOD SMEs | 0 |
REQ-8 | REQ-8 Mitigation for Does-Not-Meet requirements, with a residual-risk summary | 0 |
REQ-9 | REQ-9 Artifact description and evidence for Inherently-Meets claims | 0 |
SRG | Security Requirements Guides: the CCI to SRG to STIG hierarchy and the general requirements of a technology SRG | 0 |
SRG-1 | SRG-1 CCIs are the discrete, measurable items sourced from NIST SP 800-53; SRGs sit between CCIs and STIGs | 0 |
SRG-2 | SRG-2 Four core SRGs, technology SRGs beneath them, product STIGs beneath those | 0 |
SRG-3 | SRG-3 SRG naming standard: core SRG, technology SRG and a five- or six-digit sequence | 0 |
SRG-4 | SRG-4 SRG compliance reporting: requirements a product cannot meet go to AOs as a CUI report | 0 |
SRG-5 | SRG-5 NDM SRG scope: the management plane of every network device, applied with the device's function SRG | 0 |
SRG-6 | SRG-6 NDM general requirements: out-of-band or leak-free management network, SNMPv3, logging to syslog, AAA, authenticated NTP, secure image and configuration storage | 0 |
SRG-7 | SRG-7 ASD STIG scope: all networked enterprise applications, DOD-developed and third-party, with the companion STIGs | 0 |
SRG-8 | SRG-8 ASD assessment inputs: application and system documentation, the SSP and the functionality review | 0 |
SRG-9 | SRG-9 ASD general requirements: code scanners whenever possible, application scanners regularly, mobile code by category | 0 |