4 STIG Assessment Workflow

Security Hardening & Compliance (STIGs/CIS) · 3:34

Listen on 93

Lyrics

[Verse 1]
When security assessment time arrives
We need a workflow to keep systems alive
Eight steps to follow, each one has its place
From scope to reporting, we'll set the right pace
Start with the boundary, what's in our domain
Every system matters, nothing left unnamed

[Chorus]
Scope and Baseline, Scan then Review
Document findings, make them come through
Remediate problems, Validate twice
Report the results, security's nice
S-B-S-M-D-R-V-R, STIG workflow takes us far

[Verse 2]
Baseline comes next, we determine what's right
Which STIGs and SRGs will guide us tonight
Match every technology with proper controls
Security requirements to reach all our goals
SCAP automation makes scanning so clean
Finding vulnerabilities in the machine

[Chorus]
Scope and Baseline, Scan then Review
Document findings, make them come through
Remediate problems, Validate twice
Report the results, security's nice
S-B-S-M-D-R-V-R, STIG workflow takes us far

[Bridge]
Manual review for what scans can't see
Human eyes catching what automation missed free
Document in checklists with dot-C-K-L files
Evidence matters, go that extra mile
POA and Ms when fixes can't wait
Justify reasons, don't leave it to fate

[Verse 3]
Remediation fixes what we found wrong
Validate changes, make security strong
Re-scan and re-assess, confirm every change
Report to stakeholders across the whole range
Authorization package needs our complete view
STIG assessment workflow sees us through

[Chorus]
Scope and Baseline, Scan then Review
Document findings, make them come through
Remediate problems, Validate twice
Report the results, security's nice
S-B-S-M-D-R-V-R, STIG workflow takes us far

[Outro]
Eight steps together make systems secure
DISA STIG workflow, tested and sure

← 2 STIGs ↔ FedRAMP | 1 Windows Server STIG →