Skip to content

Evidence request lists

DISA Security Technical Implementation Guides (STIGs)

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

DISA STIG: Assessment and Automation

STIG-ASSESS-IV
Independent validation of STIG findings

Have STIG assessment results independently validated (e.g. by a security control assessor) to confirm findings and remediation.

Artefacts an auditor will ask for
  • Independent validation/assessor records
Where this commonly fails
  • Self-attestation with no independent validation
STIG-ASSESS-SCAP
SCAP automated benchmark scanning

Use a SCAP-validated tool (e.g. SCAP Compliance Checker / Evaluate-STIG) to automatically assess systems against the applicable STIG benchmarks where automation is available.

Artefacts an auditor will ask for
  • SCAP benchmark scan results mapped to STIG requirements
Where this commonly fails
  • Manual-only assessment where automated benchmarks exist
  • Stale benchmark content
STIG-ASSESS-VIEWER
STIG Viewer checklist execution

Use DISA STIG Viewer (or an equivalent) to execute STIG checklists and record the status of each requirement (Open/Not a Finding/Not Applicable/Not Reviewed) in a checklist (.ckl) artefact.

Artefacts an auditor will ask for
  • Completed STIG Viewer checklists (.ckl) per asset
  • Status recorded for each requirement
Where this commonly fails
  • No checklist evidence of STIG assessment

DISA STIG: Exceptions and Governance

STIG-GOV-CCI
CCI and NIST SP 800-53 traceability

Maintain traceability from STIG requirements through Control Correlation Identifiers (CCIs) to the NIST SP 800-53 security controls they implement, so that STIG compliance evidences the corresponding 800-53 controls.

Artefacts an auditor will ask for
  • A mapping from implemented STIG requirements (via CCI) to NIST 800-53 controls
Where this commonly fails
  • No traceability between STIG findings and the 800-53 control baseline
STIG-GOV-EMASS
eMASS integration and reporting

Record STIG assessment status, findings and POA&Ms in eMASS (or the applicable authorisation/GRC system) for authorisation and continuous-monitoring reporting.

Artefacts an auditor will ask for
  • STIG status and POA&Ms recorded in eMASS / the authorisation system
Where this commonly fails
  • STIG results not reflected in the authorisation package
STIG-GOV-EXC
Exception and risk acceptance (POA&M)

Document STIG requirements that cannot be met as exceptions with risk acceptance and a Plan of Action and Milestones (POA&M) approved by the authorising official.

Artefacts an auditor will ask for
  • POA&M entries for open findings
  • Risk-acceptance approvals by the authorising official
Where this commonly fails
  • Open findings with neither remediation nor an approved POA&M
STIG-GOV-TRAIN
STIG-aware personnel training

Ensure system administrators and assessors are trained on applying STIGs, using the assessment tooling, and the remediation/exception process.

Artefacts an auditor will ask for
  • Training records for STIG implementers and assessors
Where this commonly fails
  • Untrained staff applying or assessing STIGs

DISA STIG: Program and Applicability

STIG-PGM-1
STIG/SRG applicability determination and baseline

Identify, for each information system and component, the applicable Security Requirements Guides and product Security Technical Implementation Guides, and establish them as the secure-configuration baseline for build and operation.

Artefacts an auditor will ask for
  • A documented mapping of systems/components to their applicable STIGs/SRGs
  • Secure-configuration baseline derived from the applicable STIGs
Where this commonly fails
  • No determination of which STIGs apply
  • Systems with no STIG baseline
STIG-PGM-2
STIG and SRG currency and release management

Track DISA's quarterly STIG/SRG release cycle and update baselines and assessments to the current STIG version within a defined timeframe after release.

Artefacts an auditor will ask for
  • Records showing STIG versions in use match current DISA releases
  • A process to adopt new STIG releases on a defined cadence
Where this commonly fails
  • Assessing against superseded STIG versions
  • No tracking of STIG release updates
STIG-PGM-3
Change control and configuration-drift prevention

Apply change-control and configuration-management processes so that STIG-compliant settings are maintained over time and configuration drift away from the STIG baseline is detected and corrected.

Artefacts an auditor will ask for
  • Change-control records for configuration changes
  • Drift-detection results and remediation
Where this commonly fails
  • Unmanaged configuration changes that break STIG settings
  • No drift detection

DISA STIG: Severity and Remediation

STIG-SEV-CAT1
Category I (high severity) finding remediation

Remediate CAT I (Category I, high severity) STIG findings, which would directly and immediately result in loss of confidentiality, availability or integrity, as the highest priority.

Artefacts an auditor will ask for
  • Evidence that CAT I findings are closed (or have an approved, time-bound risk acceptance)
Where this commonly fails
  • Open CAT I findings without remediation or formal risk acceptance
STIG-SEV-CAT2
Category II (medium severity) finding remediation

Remediate CAT II (Category II, medium severity) STIG findings, which may result in loss that could lead to a CAT I condition.

Artefacts an auditor will ask for
  • Tracking and remediation of CAT II findings
Where this commonly fails
  • Unmanaged CAT II findings
STIG-SEV-CAT3
Category III (low severity) finding remediation

Address CAT III (Category III, low severity) STIG findings, which degrade measures to protect against loss.

Artefacts an auditor will ask for
  • Tracking and disposition of CAT III findings
Where this commonly fails
  • No disposition of CAT III findings

DISA STIG: Technology-Family Requirements (SRGs)

STIG-SRG-APP
Application and application server STIG

Apply the Application Security and Development STIG and application-server STIGs, covering secure development, input validation, authentication and session management, and application logging.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
STIG-SRG-BROW
Browser STIG

Harden web browsers in accordance with the applicable browser STIG.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
STIG-SRG-CLD
Cloud, virtualization and container STIG

Apply the applicable cloud-computing SRG and virtualization/container STIGs, covering hypervisor and virtual-machine hardening, container security, cloud identity and access management, and cloud network/data protection.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
STIG-SRG-DB
Database STIG

Harden database management systems (e.g. SQL Server, Oracle, PostgreSQL) in accordance with the applicable database STIG.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
STIG-SRG-EPP
Endpoint protection (antivirus/EDR) STIG

Configure endpoint protection (antivirus / endpoint detection and response) in accordance with the applicable STIG.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
STIG-SRG-MOB
Mobility and mobile device STIG

Apply the applicable mobility SRG and mobile-device STIGs, covering mobile device management, mobile OS configuration and removable-media controls.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
STIG-SRG-NET
Network device STIG hardening

Harden network devices (routers, switches, firewalls, VPN concentrators, wireless) in accordance with the applicable network STIGs, covering device management, routing-protocol security, boundary protection and remote access.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
STIG-SRG-OS
Operating system STIG hardening

Harden operating systems (e.g. Windows, RHEL, Ubuntu, macOS) in accordance with the applicable operating-system STIG, covering account management, access control, audit/logging, authentication, cryptographic settings and system services.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
STIG-SRG-WEB
Web server STIG

Harden web servers (e.g. IIS, Apache, NGINX) in accordance with the applicable web-server STIG.

Artefacts an auditor will ask for
  • STIG checklist (.ckl) or benchmark results for the in-scope products
  • Evidence that applicable settings are applied
Where this commonly fails
  • Systems built without the applicable STIG/SRG baseline
  • Open CAT I findings with no remediation or POA&M
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the DISA Security Technical Implementation Guides (STIGs) framework page.