DISA Security Technical Implementation Guides (STIGs)
Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) are a set of configuration standards and security checklists that provide detailed technical guidance for securing DoD information systems. They are derived from Security Requirements Guides (SRGs) and cover operating systems, applications, network devices, databases, cloud services, and other technologies, offering thousands of specific security controls and checks.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (26)
Account Controls
| Code | Title |
|---|---|
| STIG-OS-02 | Account Management on OS |
AppSec
| Code | Title |
|---|---|
| STIG-APP-01 | Application Security and Development STIG |
Application Security
Security requirements for web servers, application servers, databases, and enterprise applications
| Code | Title |
|---|---|
| STIG-APP-001 | Web Server Security |
| STIG-APP-002 | Application Server Hardening |
| STIG-APP-003 | Database Security Configuration |
| STIG-APP-004 | Application Input Validation |
| STIG-APP-005 | Application Authentication and Session Management |
| STIG-APP-006 | Application Logging and Monitoring |
| STIG-APP-007 | Email and Messaging Security |
Assessment
| Code | Title |
|---|---|
| STIG-GEN-03 | STIG Viewer Checklist Execution |
Automation
| Code | Title |
|---|---|
| STIG-GEN-04 | SCAP Automated Compliance Scanning |
Change Control
| Code | Title |
|---|---|
| STIG-CHG-01 | Change Control and STIG Drift Prevention |
Cloud and Virtualization
Security requirements for cloud computing environments and virtualization platforms
| Code | Title |
|---|---|
| STIG-CLD-001 | Cloud Service Provider Assessment |
| STIG-CLD-002 | Virtual Machine Hardening |
| STIG-CLD-003 | Container Security |
| STIG-CLD-004 | Identity and Access Management in Cloud |
| STIG-CLD-005 | Cloud Data Protection |
| STIG-CLD-006 | Cloud Network Security |
Database
| Code | Title |
|---|---|
| STIG-DB-01 | Database STIG (SQL Server / Oracle / Postgres) |
Endpoint
| Code | Title |
|---|---|
| STIG-BROW-01 | Browser STIG |
Endpoint Protection
| Code | Title |
|---|---|
| STIG-AV-01 | Antivirus / EDR STIG |
Exceptions
| Code | Title |
|---|---|
| STIG-EXC-01 | STIG Exception and Risk Acceptance |
General Purpose Operating Systems
Security requirements for server and desktop operating systems including Windows, Linux, and macOS
| Code | Title |
|---|---|
| STIG-OS-001 | Account Management Controls |
| STIG-OS-002 | Access Control Mechanisms |
| STIG-OS-003 | Audit and Logging Configuration |
| STIG-OS-004 | Authentication Mechanisms |
| STIG-OS-005 | System Hardening |
| STIG-OS-006 | Encryption and Cryptographic Controls |
| STIG-OS-007 | Patch and Vulnerability Management |
Independent Validation
| Code | Title |
|---|---|
| STIG-AUDIT-01 | Independent Validation of STIG Findings |
Logging
| Code | Title |
|---|---|
| STIG-OS-03 | Audit Logging on OS |
Mobile and Endpoint Security
Security requirements for mobile devices, MDM platforms, and endpoint protection
| Code | Title |
|---|---|
| STIG-MOB-001 | Mobile Device Management |
| STIG-MOB-002 | Mobile OS Security Configuration |
| STIG-MOB-003 | Endpoint Detection and Response |
| STIG-MOB-004 | Removable Media Controls |
| STIG-MOB-005 | Browser Security Configuration |
Network Hardening
| Code | Title |
|---|---|
| STIG-NET-01 | Network Device STIG (Router/Switch/Firewall) |
Network Infrastructure
Security requirements for routers, switches, firewalls, wireless access points, and network devices
| Code | Title |
|---|---|
| STIG-NET-001 | Network Device Management |
| STIG-NET-002 | Routing Protocol Security |
| STIG-NET-003 | Switch Security Configuration |
| STIG-NET-004 | Firewall and ACL Configuration |
| STIG-NET-005 | Wireless Network Security |
| STIG-NET-006 | Network Boundary Protection |
| STIG-NET-007 | VPN and Remote Access Security |
OS Hardening
| Code | Title |
|---|---|
| STIG-OS-01 | Operating System STIG (Windows / RHEL / Ubuntu) |
Reporting
| Code | Title |
|---|---|
| STIG-eMASS-01 | eMASS Integration and Reporting |
Scope
| Code | Title |
|---|---|
| STIG-GEN-01 | STIG Applicability Determination |
Severity Management
| Code | Title |
|---|---|
| STIG-CAT1 | Category I Finding Remediation |
| STIG-CAT2 | Category II Finding Remediation |
| STIG-CAT3 | Category III Finding Remediation |
Time Sync
| Code | Title |
|---|---|
| STIG-NET-02 | Network Time and Synchronisation |
Training
| Code | Title |
|---|---|
| STIG-TRAIN-01 | STIG-Aware Personnel Training |
Version Management
| Code | Title |
|---|---|
| STIG-GEN-02 | STIG Currency and Version Management |
Virtualisation
| Code | Title |
|---|---|
| STIG-VIRT-01 | Virtualisation/Container STIG |
Web Server
| Code | Title |
|---|---|
| STIG-WEB-01 | Web Server STIG (IIS / Apache / NGINX) |
Your Compliance Coverage
If you comply with DISA Security Technical Implementation Guides (STIGs), you already cover:
ASD Information Security Manual (ISM)
40%
22 controls mapped
Compare →NIST SP 800-171A - Assessing CUI Security Requirements
38%
21 controls mapped
Compare →Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
38%
21 controls mapped
Compare →+ 565 more: PCI DSS v4.0 (36%), DoD Zero Trust Reference Architecture (36%)
See all 568 mapped frameworks ↓Maps to 568 other frameworks
Frequently Asked Questions
What is DISA Security Technical Implementation Guides (STIGs)?
DISA Security Technical Implementation Guides (STIGs) is a compliance framework from United States with 26 domains and 55 controls. Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) are a set of configuration standards and security checklists that provide detailed technical guidance for securing DoD information systems. They are derived from Security Requirements Guides (SRGs) and cover operating systems, applications, network devices, databases, cloud services, and other technologies, offering thousands of specific security controls and checks. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does DISA Security Technical Implementation Guides (STIGs) have?
DISA Security Technical Implementation Guides (STIGs) has 55 controls organised across 26 domains. The largest domains are Application Security (7 controls), General Purpose Operating Systems (7 controls), Network Infrastructure (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does DISA Security Technical Implementation Guides (STIGs) map to?
DISA Security Technical Implementation Guides (STIGs) maps to 568 other compliance frameworks. The top mapping partners are ASD Information Security Manual (ISM) (40% coverage), NIST SP 800-171A - Assessing CUI Security Requirements (38% coverage), Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with DISA Security Technical Implementation Guides (STIGs) compliance?
Start your DISA Security Technical Implementation Guides (STIGs) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about DISA Security Technical Implementation Guides (STIGs) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 55 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required