DISA STIG
What is DISA STIG?
Defence Information Systems Agency Security Technical Implementation Guides that provide technical security configuration standards for US Department of Defense information systems. STIGs are based on NIST SP 800-53 controls.
Terms that appear alongside disa stig
Each of these is named in at least one of the same controls as disa stig. The number is how many controls name both.
- cis benchmarks 4 shared controls
- patch management 4 shared controls
- secure configuration 4 shared controls
- baseline 4 shared controls
- hardening 4 shared controls
- nist 3 shared controls
- system hardening 3 shared controls
- zero trust 2 shared controls
Frameworks that govern disa stig
What the standards actually require on disa stig
Requirements naming disa stig across 6 standards, quoted from the control text.
Use DISA STIG Viewer (or an equivalent) to execute STIG checklists and record the status of each requirement (Open/Not a Finding/Not Applicable/Not Reviewed) in a checklist (.ckl) artefact.
STIG-ASSESS-VIEWER · STIG Viewer checklist execution →Establish/document configuration settings using checklists; CIS/USGCB/DISA STIG when available; HIGH baseline.
CM-6 · Configuration Settings →Establish/document configuration settings using checklists; CIS/USGCB/DISA STIG when available; HIGH baseline.
CM-6 · Configuration Settings →Vulnerability Management is a core technical control area per FSA Cybersecurity Guidelines. (1) Vulnerability Discovery: (a) Authenticated and Unauthenticated Scanning - Nessus + Qualys + Rapid7 + open source; (b) DAST Dynamic Application Security Testing;
JP-FSA-CYB-Vulnerability-Management-Patching-CVE-Risk-Based-Prioritisation-Penetration-Testing-Red-Team · Japan FSA Cybersecurity Vulnerability Management + Patching + CVE Tracking + Risk-Based Prioritisation + Penetration Testing + Red-Team + Bug Bounty + Coordinated Vulnerability Disclosure + Zero-Day Response →Kuwait NCF Protect function (Infrastructure). Network Security and Segmentation: defense in depth + perimeter (firewall + WAF + DDoS mitigation) + internal segmentation (microsegmentation + VLAN + zero-trust network access ZTNA) + east-west traffic inspection...
KNCF-Protect-Network-Configuration-Vulnerability-Physical-Secure-SDLC-Hardening-Patching-Drift · Kuwait NCF Protect + Network + Configuration + Vulnerability + Physical + Secure SDLC →Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-C...
LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15 · Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15 →Questions people ask about disa stig
What is DISA STIG?
Why is DISA STIG important for compliance?
Which compliance frameworks address DISA STIG?
Where can I learn more about DISA STIG?
See how DISA STIG applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.