STIG Fundamentals
9 chapters
1. 3 Major STIG Categories
[Verse 1]
When security standards need to be clear
DISA creates guides that we hold dear
STIGs for systems both old and new
Three major categories coming through
Operating systems need protection strong
Windows and Linux where configs belong
Red Hat and Ubuntu, SUSE in line
Oracle Linux and macOS design
[Chorus]
OS, Network, Apps - remember these three
Operating systems running free
Network devices keeping us secure
Application STIGs making code pure
OS, Network, Apps - the major domains
Security guidance flowing through our veins
[Verse 2]
Network infrastructure needs rules to follow
Cisco and Juniper, no room for hollow
Palo Alto firewalls and F5 load balancing
Aruba wireless networks, security enhancing
Routers and switches with IOS commands
NX-OS configurations across all the lands
[Chorus]
OS, Network, Apps - remember these three
Operating systems running free
Network devices keeping us secure
Application STIGs making code pure
OS, Network, Apps - the major domains
Security guidance flowing through our veins
[Verse 3]
Applications running need standards too
Databases storing data me and you
Oracle and SQL Server holding information tight
PostgreSQL and MySQL shining bright
MongoDB and web servers serving pages clean
Apache and IIS, NGINX on the scene
[Bridge]
From VMware virtual to cloud up high
AWS and Azure reaching for the sky
Docker containers and Kubernetes orchestration
Mobile devices across the nation
Email systems and browsers we use each day
Every technology has a STIG to obey
[Chorus]
OS, Network, Apps - remember these three
Operating systems running free
Network devices keeping us secure
Application STIGs making code pure
OS, Network, Apps - the major domains
Security guidance flowing through our veins
[Outro]
Three categories standing strong and true
Operating systems, networks, applications too
DISA STIGs protecting all we do
Security standards seeing us through
2. 2 STIG Document Structure
[Verse 1]
When you open up a STIG to see what's inside
Nine components waiting there to be your guide
Group Title starts us off with categorization
Rule Title gives the clear and full explanation
[Chorus]
STIG ID, Vuln ID, numbers you can trust
Severity tells you CAT one, two, or three's a must
Discussion shows the why, Check tells you how
Fix Text makes it right, CCI maps it now
Reference points the way, structure's clear somehow
Nine parts working together, STIG knowledge now
[Verse 2]
STIG ID and Vuln ID are the unique keys
Help you track each finding with the greatest ease
Severity levels guide you where to start your work
CAT One's critical, can't let security lurk
[Chorus]
STIG ID, Vuln ID, numbers you can trust
Severity tells you CAT one, two, or three's a must
Discussion shows the why, Check tells you how
Fix Text makes it right, CCI maps it now
Reference points the way, structure's clear somehow
Nine parts working together, STIG knowledge now
[Verse 3]
Discussion gives you context, rationale so clear
Check Content shows the steps to verify what's here
Fix Text remediation makes the problem go
CCI links to NIST controls that you should know
[Bridge]
Group and Rule and IDs
Severity's your priority
Discussion, Check, and Fix
CCI and Reference in the mix
[Chorus]
STIG ID, Vuln ID, numbers you can trust
Severity tells you CAT one, two, or three's a must
Discussion shows the why, Check tells you how
Fix Text makes it right, CCI maps it now
Reference points the way, structure's clear somehow
Nine parts working together, STIG knowledge now
[Outro]
Nine components strong and true
STIG structure guiding you
From Group Title to Reference line
Security knowledge by design
3. 1 Obtaining STIGs
[Verse 1]
When you need security guidance that's official and true
DISA's got the standards waiting there for you
Navigate to public dot cyber dot mil
STIGs are the pathway, climb that security hill
No account needed, it's open and free
Download the knowledge for all to see
[Chorus]
Get your STIGs from the Cyber Exchange
XCCDF format, don't think it's strange
Quarterly updates keep you in range
STIG Viewer opens what you arrange
Public dot cyber dot mil slash STIGs
That's where security guidance lives
[Verse 2]
XML structure in XCCDF design
STIG Viewer software makes it all shine
Browse through the categories, find what you need
Operating systems or database feed
Each STIG's a treasure of security rules
Hardening guidance and compliance tools
[Chorus]
Get your STIGs from the Cyber Exchange
XCCDF format, don't think it's strange
Quarterly updates keep you in range
STIG Viewer opens what you arrange
Public dot cyber dot mil slash STIGs
That's where security guidance lives
[Bridge]
SRG and STIG Library compilation
Updated each quarter for the whole nation
Sometimes more often when issues are critical
Security standards that are analytical
Every three months brings the latest version
Keeping your systems safe from subversion
[Verse 3]
Download the library, get them all at once
Current and complete, no need to hunt
From Windows servers to network devices
DISA provides all the best practices
Publicly available, no hidden cost
Without these standards, security's lost
[Final Chorus]
Get your STIGs from the Cyber Exchange
XCCDF format, don't think it's strange
Quarterly updates keep you in range
STIG Viewer opens what you arrange
Public dot cyber dot mil slash STIGs
That's where security guidance lives
That's where your compliance journey begins
4. 2 STIG Viewer
[Verse 1]
When security standards need to be applied
STIG Viewer helps you stay compliant inside
Import your XCCDF files with ease
Transform them to checklists, assessments to please
Create those dot-CKL files, structured and clean
The most organized security you've ever seen
[Chorus]
Open, Not a Finding, Not Applicable too
Not Reviewed status when you're not quite through
Mark your findings, add your evidence clear
STIG Viewer makes compliance crystal clear
Import, assess, export with might
Keep your systems secure day and night
[Verse 2]
Load up those benchmarks from DISA's collection
Every vulnerability needs your inspection
Click through each finding, make your call
Document the reasons, evidence and all
Comments and details paint the full picture
Security posture getting ever stricter
[Chorus]
Open, Not a Finding, Not Applicable too
Not Reviewed status when you're not quite through
Mark your findings, add your evidence clear
STIG Viewer makes compliance crystal clear
Import, assess, export with might
Keep your systems secure day and night
[Bridge]
Four simple statuses to remember well
Open means problems you need to tell
Not a Finding when you're in the clear
Not Applicable when it doesn't appear
Not Reviewed means you're still working through
STIG Viewer guides you in all that you do
[Verse 3]
Export your results when assessment's complete
Reports and summaries, professional and neat
Though STIG Manager's the future we're told
STIG Viewer's lessons are worth their weight in gold
Checklist creation, the foundation stone
Of enterprise security you can call your own
[Chorus]
Open, Not a Finding, Not Applicable too
Not Reviewed status when you're not quite through
Mark your findings, add your evidence clear
STIG Viewer makes compliance crystal clear
Import, assess, export with might
Keep your systems secure day and night
[Outro]
From XCCDF to checklist files
STIG Viewer helps you go the miles
Security standards, now you know the way
Compliant systems, every single day
5. 2 The STIG Ecosystem
[Verse 1]
In the world of DoD security there's a framework we must know
STIGs don't stand alone they're part of a greater flow
DoD Instruction eight five hundred oh one sets the foundation stone
Cybersecurity policy that makes our systems strong
[Chorus]
Eight five hundred oh one starts the game
Eight five ten oh one brings RMF to fame
CNSSI twelve fifty three categorizes with care
NIST eight hundred fifty three controls are everywhere
Eight hundred thirty seven guides us through each phase
The STIG ecosystem working through our days
[Verse 2]
Risk Management Framework comes from eight five ten oh one
Assessment and authorization before our work is done
National security systems need CNSSI guidance clear
Twelve fifty three shows us which controls we should revere
[Chorus]
Eight five hundred oh one starts the game
Eight five ten oh one brings RMF to fame
CNSSI twelve fifty three categorizes with care
NIST eight hundred fifty three controls are everywhere
Eight hundred thirty seven guides us through each phase
The STIG ecosystem working through our days
[Bridge]
NIST Special Publication eight hundred fifty three
Provides the catalog of controls for you and me
While eight hundred thirty seven shows the RMF way
STIGs implement these standards every single day
[Verse 3]
From policy to practice STIGs bridge the gap
Technical implementation following the map
Governance structure flowing from the top on down
STIGs are the foundation keeping systems sound
[Chorus]
Eight five hundred oh one starts the game
Eight five ten oh one brings RMF to fame
CNSSI twelve fifty three categorizes with care
NIST eight hundred fifty three controls are everywhere
Eight hundred thirty seven guides us through each phase
The STIG ecosystem working through our days
[Outro]
Five key pieces in our cybersecurity dance
DoD and NIST together giving systems their chance
STIGs within the ecosystem playing their part
Security governance flowing like a work of art
6. 1 SRG-to-STIG Hierarchy
[Verse 1]
From NIST controls way up high
Down to products where they apply
There's a pathway we must trace
Through the hierarchy's embrace
Eight hundred fifty-three controls
Set the standards for our goals
But they're too broad to use alone
Need translation to call home
[Chorus]
NIST to SRG to STIG we go
Watch the requirements flow
From the general to specific needs
Following where compliance leads
SRG takes the broad control
Makes it fit technology's role
STIG takes it one step more
To the product at the core
[Verse 2]
SRG stands between the lines
Takes those NIST control designs
Makes them fit a category
Operating systems, you see
General Purpose OS SRG
Translates what AC-2 means
Account management made clear
For the platform engineers
[Chorus]
NIST to SRG to STIG we go
Watch the requirements flow
From the general to specific needs
Following where compliance leads
SRG takes the broad control
Makes it fit technology's role
STIG takes it one step more
To the product at the core
[Bridge]
RHEL 8 STIG shows the way
Check inactive accounts today
Lock them out when time expires
That's what AC-2 requires
From the abstract to concrete
Makes compliance more complete
[Verse 3]
Inheritance is the key
Flowing down from one to three
Nothing lost along the way
Just more specific every day
Technology category
Then the product family
Step by step we drill it down
Till implementation's found
[Chorus]
NIST to SRG to STIG we go
Watch the requirements flow
From the general to specific needs
Following where compliance leads
SRG takes the broad control
Makes it fit technology's role
STIG takes it one step more
To the product at the core
[Outro]
Three levels in the chain
Keep security's domain
From controls to checks complete
Making compliance concrete
7. 3 SCAP and Automated Assessment
[Verse 1]
When compliance checking takes too long to do by hand
SCAP automation helps you understand
Security Content Automation Protocol's the way
Makes STIG assessment faster every day
Machine-readable benchmarks in XCCDF form
OVAL definitions keep your systems in the norm
[Chorus]
SCAP it up, scan it down
SCC is DISA's crown
Sixty to eighty percent automated
Manual checks still validated
SCAP it up, make it flow
OpenSCAP for Linux, now you know
[Verse 2]
SCAP Compliance Checker is the official tool
DISA built it following every rule
Benchmarks translate STIGs to machine code
XCCDF and OVAL share the load
PowerShell users get Evaluate-STIG
Windows assessment dancing to this jig
[Chorus]
SCAP it up, scan it down
SCC is DISA's crown
Sixty to eighty percent automated
Manual checks still validated
SCAP it up, make it flow
OpenSCAP for Linux, now you know
[Bridge]
Not everything can be scanned automatically
Interviews and documentation need humanity
Architecture analysis requires human eyes
But automation handles most of the tries
Combine both methods for complete review
Manual plus automated gets you through
[Verse 3]
Open-source OpenSCAP in Linux land
Scanning compliance with a steady hand
But remember that gap of twenty to forty
Some findings need review, don't get sporty
Documentation checks and interview time
Human verification keeps you in line
[Chorus]
SCAP it up, scan it down
SCC is DISA's crown
Sixty to eighty percent automated
Manual checks still validated
SCAP it up, make it flow
OpenSCAP for Linux, now you know
[Outro]
Security Content Automation Protocol
Makes compliance checking more practical
Scan the systems, check the findings
Manual review for perfect bindings
8. 2 RHEL / Linux STIG
[Verse 1]
Lock down your system files tight
Check permissions day and night
Seven five five for user read and write
Four for group and others sight
SUID and SGID must be controlled
No surprise escalation unfold
Root access needs a careful hold
Security stories must be told
[Chorus]
RHEL STIG keeping systems strong
File ownership where it belongs
PAM and audit all along
SELinux enforcing nothing wrong
Harden kernels all day long
FIPS crypto singing security's song
Partition smart and mount with care
Linux locked down everywhere
[Verse 2]
PAM configuration leads the way
Password quality rules the day
Pwquality module here to stay
Weak passwords we don't obey
SSH hardening protocol
No root login through the wall
Key based auth standing tall
Security practices for us all
[Chorus]
RHEL STIG keeping systems strong
File ownership where it belongs
PAM and audit all along
SELinux enforcing nothing wrong
Harden kernels all day long
FIPS crypto singing security's song
Partition smart and mount with care
Linux locked down everywhere
[Bridge]
Auditd watching every move
Privileged commands in the groove
File access logs improve
Account changes we must prove
ASLR randomizing space
Sysctl parameters in their place
Network memory protection base
Security woven with such grace
[Verse 3]
SELinux enforcing mode required
Context labels never tired
Policy management inspired
Security boundaries never expired
Package management GPG signed
Unnecessary software left behind
FIPS validation peace of mind
Cryptographic strength refined
[Chorus]
RHEL STIG keeping systems strong
File ownership where it belongs
PAM and audit all along
SELinux enforcing nothing wrong
Harden kernels all day long
FIPS crypto singing security's song
Partition smart and mount with care
Linux locked down everywhere
[Outro]
Tmp and var in separate space
Nosuid noexec keeping pace
Var log partition finds its place
DISA STIG security embrace
Red Hat systems locked and true
Compliance shining through and through
9. 3 Network Device STIGs
[Verse 1]
Three device types guard our network core
Routers, switches, firewalls and more
But common rules apply across the board
DISA STIGs show us how to secure
Authentication's where we start the fight
TACACS RADIUS keep access tight
Local accounts when servers go down
Triple A framework keeps threats from town
[Chorus]
Authenticate Authorize Account for all
Management plane secured against the fall
Log everything with time stamps that align
Access control lists drawn by design
Protocol security router by router
Banners warning every network intruder
Firmware validated versions running clean
Network device STIGs keep systems lean
[Verse 2]
Management plane needs protection strong
SSH connections keep us safe from wrong
Never use Telnet sends passwords clear
SNMP version three keeps admin secure
Encrypted channels for every control
Web interfaces with TLS goals
Console access with proper authentication
Management VLAN isolation
[Chorus]
Authenticate Authorize Account for all
Management plane secured against the fall
Log everything with time stamps that align
Access control lists drawn by design
Protocol security router by router
Banners warning every network intruder
Firmware validated versions running clean
Network device STIGs keep systems lean
[Verse 3]
Logging tells the story of our network health
Syslog collectors gathering wealth
Central correlation needs synchronized time
NTP servers keep logs aligned
When incidents happen we need to see
Timeline of events chronologically
Without proper timestamps we're flying blind
Network forensics need time aligned
[Bridge]
Ingress filtering at the border gate
Egress filtering data we create
Anti spoofing stops the fake source lies
Access lists control who gets inside
OSPF BGP EIGRP too
Authentication keys for me and you
Routing protocols need security strong
Or attackers redirect where packets belong
[Verse 4]
Banner warnings greet each login screen
DoD approved messages keep networks clean
Legal notices tell users what's allowed
Unauthorized access isn't allowed
Firmware versions must be validated clean
Approved by DISA security team
Patches tested before deployment day
Vulnerability management leads the way
[Chorus]
Authenticate Authorize Account for all
Management plane secured against the fall
Log everything with time stamps that align
Access control lists drawn by design
Protocol security router by router
Banners warning every network intruder
Firmware validated versions running clean
Network device STIGs keep systems lean
[Outro]
Three device types one security goal
DISA STIGs keep networks under control
Router switch firewall working as one
Network security never done
Back to Home