[Verse 1]
When you're scanning systems for security flaws
There's a language that follows compliance laws
STIG's the document that shows the way
Every requirement mapped out clear as day
Security Technical Implementation Guide
Tells you how to keep your systems fortified
[Chorus]
STIG and SRG, findings all around
V-numbers and Rule IDs can be found
CAT One Two and Three, severity's the key
Open Not a Finding, status helps you see
POA and M when problems need a plan
DISA terminology, now you understand
[Verse 2]
SRG stands above the STIG below
Security Requirements Guide helps standards grow
Higher level guidance for technology types
Operating systems, databases, all the hypes
General purpose categories define the rules
That STIGs inherit as their building tools
[Chorus]
STIG and SRG, findings all around
V-numbers and Rule IDs can be found
CAT One Two and Three, severity's the key
Open Not a Finding, status helps you see
POA and M when problems need a plan
DISA terminology, now you understand
[Bridge]
Every finding's got its ID tag
V-two-three-oh-two-two-one, don't let it lag
Rule ID for automation tools
SV format follows technical rules
Critical Medium Low, that's CAT One Two Three
Compliance status sets your systems free
[Verse 3]
When assessment time comes around
Check each finding that can be found
Open means you've got work to do
Not a Finding means you're sailing through
Not Applicable doesn't fit your case
Not Reviewed means you need more space
[Chorus]
STIG and SRG, findings all around
V-numbers and Rule IDs can be found
CAT One Two and Three, severity's the key
Open Not a Finding, status helps you see
POA and M when problems need a plan
DISA terminology, now you understand
[Outro]
Plan of Action and Milestones too
Documents the work you need to do
Remediation steps all written down
STIG compliance keeps security sound