DISA Security Technical Implementation Guides (STIGs)
Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
DISA STIG: Assessment and Automation
Have STIG assessment results independently validated (e.g. by a security control assessor) to confirm findings and remediation.
- Independent validation/assessor records
- Self-attestation with no independent validation
Use a SCAP-validated tool (e.g. SCAP Compliance Checker / Evaluate-STIG) to automatically assess systems against the applicable STIG benchmarks where automation is available.
- SCAP benchmark scan results mapped to STIG requirements
- Manual-only assessment where automated benchmarks exist
- Stale benchmark content
Use DISA STIG Viewer (or an equivalent) to execute STIG checklists and record the status of each requirement (Open/Not a Finding/Not Applicable/Not Reviewed) in a checklist (.ckl) artefact.
- Completed STIG Viewer checklists (.ckl) per asset
- Status recorded for each requirement
- No checklist evidence of STIG assessment
DISA STIG: Exceptions and Governance
Maintain traceability from STIG requirements through Control Correlation Identifiers (CCIs) to the NIST SP 800-53 security controls they implement, so that STIG compliance evidences the corresponding 800-53 controls.
- A mapping from implemented STIG requirements (via CCI) to NIST 800-53 controls
- No traceability between STIG findings and the 800-53 control baseline
Record STIG assessment status, findings and POA&Ms in eMASS (or the applicable authorisation/GRC system) for authorisation and continuous-monitoring reporting.
- STIG status and POA&Ms recorded in eMASS / the authorisation system
- STIG results not reflected in the authorisation package
Document STIG requirements that cannot be met as exceptions with risk acceptance and a Plan of Action and Milestones (POA&M) approved by the authorising official.
- POA&M entries for open findings
- Risk-acceptance approvals by the authorising official
- Open findings with neither remediation nor an approved POA&M
Ensure system administrators and assessors are trained on applying STIGs, using the assessment tooling, and the remediation/exception process.
- Training records for STIG implementers and assessors
- Untrained staff applying or assessing STIGs
DISA STIG: Program and Applicability
Identify, for each information system and component, the applicable Security Requirements Guides and product Security Technical Implementation Guides, and establish them as the secure-configuration baseline for build and operation.
- A documented mapping of systems/components to their applicable STIGs/SRGs
- Secure-configuration baseline derived from the applicable STIGs
- No determination of which STIGs apply
- Systems with no STIG baseline
Track DISA's quarterly STIG/SRG release cycle and update baselines and assessments to the current STIG version within a defined timeframe after release.
- Records showing STIG versions in use match current DISA releases
- A process to adopt new STIG releases on a defined cadence
- Assessing against superseded STIG versions
- No tracking of STIG release updates
Apply change-control and configuration-management processes so that STIG-compliant settings are maintained over time and configuration drift away from the STIG baseline is detected and corrected.
- Change-control records for configuration changes
- Drift-detection results and remediation
- Unmanaged configuration changes that break STIG settings
- No drift detection
DISA STIG: Severity and Remediation
Remediate CAT I (Category I, high severity) STIG findings, which would directly and immediately result in loss of confidentiality, availability or integrity, as the highest priority.
- Evidence that CAT I findings are closed (or have an approved, time-bound risk acceptance)
- Open CAT I findings without remediation or formal risk acceptance
Remediate CAT II (Category II, medium severity) STIG findings, which may result in loss that could lead to a CAT I condition.
- Tracking and remediation of CAT II findings
- Unmanaged CAT II findings
Address CAT III (Category III, low severity) STIG findings, which degrade measures to protect against loss.
- Tracking and disposition of CAT III findings
- No disposition of CAT III findings
DISA STIG: Technology-Family Requirements (SRGs)
Apply the Application Security and Development STIG and application-server STIGs, covering secure development, input validation, authentication and session management, and application logging.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Harden web browsers in accordance with the applicable browser STIG.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Apply the applicable cloud-computing SRG and virtualization/container STIGs, covering hypervisor and virtual-machine hardening, container security, cloud identity and access management, and cloud network/data protection.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Harden database management systems (e.g. SQL Server, Oracle, PostgreSQL) in accordance with the applicable database STIG.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Configure endpoint protection (antivirus / endpoint detection and response) in accordance with the applicable STIG.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Apply the applicable mobility SRG and mobile-device STIGs, covering mobile device management, mobile OS configuration and removable-media controls.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Harden network devices (routers, switches, firewalls, VPN concentrators, wireless) in accordance with the applicable network STIGs, covering device management, routing-protocol security, boundary protection and remote access.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Harden operating systems (e.g. Windows, RHEL, Ubuntu, macOS) in accordance with the applicable operating-system STIG, covering account management, access control, audit/logging, authentication, cryptographic settings and system services.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Harden web servers (e.g. IIS, Apache, NGINX) in accordance with the applicable web-server STIG.
- STIG checklist (.ckl) or benchmark results for the in-scope products
- Evidence that applicable settings are applied
- Systems built without the applicable STIG/SRG baseline
- Open CAT I findings with no remediation or POA&M
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the DISA Security Technical Implementation Guides (STIGs) framework page.