Back to Frameworks

DISA Security Technical Implementation Guides (STIGs)

United States
vN/A - STIGs are continuously updated; specify the latest release date or omit the field.
5 domains
22 controls

DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs), published by the Defense Information Systems Agency via the DoD Cyber Exchange. SRGs are technology-family security-requirement sets derived from NIST SP 800-53 (via Control Correlation Identifiers); STIGs are product-specific hardening guides implementing the applicable SRG, each comprising findings categorised CAT I/II/III, assessed using STIG Viewer and SCAP-validated tools and tracked in eMASS. This node represents the STIG/SRG program structure (technology families, severity categories, assessment tooling and governance lifecycle); the per-product STIG findings are a catalog (hundreds of STIGs) and are not enumerated here.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

DISA STIG: Assessment and Automation

3 controls
Controls in the DISA STIG: Assessment and Automation domain of DISA Security Technical Implementation Guides (STIGs)3 controls
CodeTitle
STIG-ASSESS-IVIndependent validation of STIG findings
STIG-ASSESS-SCAPSCAP automated benchmark scanning
STIG-ASSESS-VIEWERSTIG Viewer checklist execution

DISA STIG: Exceptions and Governance

4 controls
Controls in the DISA STIG: Exceptions and Governance domain of DISA Security Technical Implementation Guides (STIGs)4 controls
CodeTitle
STIG-GOV-CCICCI and NIST SP 800-53 traceability
STIG-GOV-EMASSeMASS integration and reporting
STIG-GOV-EXCException and risk acceptance (POA&M)
STIG-GOV-TRAINSTIG-aware personnel training

DISA STIG: Program and Applicability

3 controls
Controls in the DISA STIG: Program and Applicability domain of DISA Security Technical Implementation Guides (STIGs)3 controls
CodeTitle
STIG-PGM-1STIG/SRG applicability determination and baseline
STIG-PGM-2STIG and SRG currency and release management
STIG-PGM-3Change control and configuration-drift prevention

DISA STIG: Severity and Remediation

3 controls
Controls in the DISA STIG: Severity and Remediation domain of DISA Security Technical Implementation Guides (STIGs)3 controls
CodeTitle
STIG-SEV-CAT1Category I (high severity) finding remediation
STIG-SEV-CAT2Category II (medium severity) finding remediation
STIG-SEV-CAT3Category III (low severity) finding remediation

DISA STIG: Technology-Family Requirements (SRGs)

9 controls
Controls in the DISA STIG: Technology-Family Requirements (SRGs) domain of DISA Security Technical Implementation Guides (STIGs)9 controls
CodeTitle
STIG-SRG-APPApplication and application server STIG
STIG-SRG-BROWBrowser STIG
STIG-SRG-CLDCloud, virtualization and container STIG
STIG-SRG-DBDatabase STIG
STIG-SRG-EPPEndpoint protection (antivirus/EDR) STIG
STIG-SRG-MOBMobility and mobile device STIG
STIG-SRG-NETNetwork device STIG hardening
STIG-SRG-OSOperating system STIG hardening
STIG-SRG-WEBWeb server STIG

Your Compliance Coverage

If you comply with DISA Security Technical Implementation Guides (STIGs), you already cover:

Maps to 3 other frameworks

22 total controls
NIST SP 800-53 Rev 5
5 source controls mapped|5 target controls covered
23%
CMMC 2.0
3 source controls mapped|3 target controls covered
14%
CIS Controls v8
1 source controls mapped|1 target controls covered
5%

Frequently Asked Questions

What is DISA Security Technical Implementation Guides (STIGs)?

DISA Security Technical Implementation Guides (STIGs) is a compliance framework from United States with 5 domains and 22 controls. DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs), published by the Defense Information Systems Agency via the DoD Cyber Exchange. SRGs are technology-family security-requirement sets derived from NIST SP 800-53 (via Control Correlation Identifiers); STIGs are product-specific hardening guides implementing the applicable SRG, each comprising findings categorised CAT I/II/III, assessed using STIG Viewer and SCAP-validated tools and tracked in eMASS. This node represents the STIG/SRG program structure (technology families, severity categories, assessment tooling and governance lifecycle); the per-product STIG findings are a catalog (hundreds of STIGs) and are not enumerated here. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does DISA Security Technical Implementation Guides (STIGs) have?

DISA Security Technical Implementation Guides (STIGs) has 22 controls organised across 5 domains. The largest domains are DISA STIG: Technology-Family Requirements (SRGs) (9 controls), DISA STIG: Exceptions and Governance (4 controls), DISA STIG: Assessment and Automation (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does DISA Security Technical Implementation Guides (STIGs) map to?

DISA Security Technical Implementation Guides (STIGs) maps to 3 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 (23% coverage), CMMC 2.0 (14% coverage), CIS Controls v8 (5% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with DISA Security Technical Implementation Guides (STIGs) compliance?

Start your DISA Security Technical Implementation Guides (STIGs) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about DISA Security Technical Implementation Guides (STIGs) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required