STIGs and Compliance Framework
9 chapters
1. 1 STIGs ↔ CMMC
[Verse 1]
When your organization seeks CMMC certification
Three levels deep, you need documentation
STIGs and CMMC walk hand in hand
Both built on NIST controls across the land
Eight hundred fifty-three and seventy-one
Same foundation where compliance is won
[Chorus]
STIGs to CMMC, they align so well
Same controls, same story to tell
Hardening systems, protecting CUI
STIG compliance helps your case fly high
Evidence strong, assessors can see
STIGs to CMMC, naturally
[Verse 2]
DoD information systems need protection tight
STIG implementation gets the settings right
When CMMC assessors come to evaluate
Your STIG compliance demonstrates your state
Practice implementation clearly shown
Through hardened systems you have grown
[Chorus]
STIGs to CMMC, they align so well
Same controls, same story to tell
Hardening systems, protecting CUI
STIG compliance helps your case fly high
Evidence strong, assessors can see
STIGs to CMMC, naturally
[Bridge]
DoD contracts with CUI in scope
STIG alignment gives you hope
Level one, two, or three
Same controls set you free
NIST controls in both domains
Streamlined compliance, reduced pains
[Verse 3]
Organizations handling sensitive data
STIG hardening meets CMMC criteria
Assessors reference what you've done before
STIG compliance opens up the door
Evidence ready, controls in place
CMMC success with STIG embrace
[Chorus]
STIGs to CMMC, they align so well
Same controls, same story to tell
Hardening systems, protecting CUI
STIG compliance helps your case fly high
Evidence strong, assessors can see
STIGs to CMMC, naturally
[Outro]
From STIG to CMMC
Security flows naturally
Same controls, different name
Compliance plays the same game
2. 1 Where STIGs Fit in the RMF
[Verse 1]
When you start the RMF journey, six steps guide your way
Categorize your system first, that's where STIGs come into play
System type determines which security requirements you'll need
SRGs and STIGs will follow from the categories you feed
[Chorus]
STIGs in the RMF, where do they belong?
Step three implement, step four assess strong
Categorize drives selection, implementation makes it real
Assessment proves compliance, authorization seals the deal
Monitor continuously, that's how security feels
[Verse 2]
Step two is all selection, controls you need to choose
Security requirements that STIGs will help you use
Technical guidance waiting for the implementation phase
STIGs turn abstract controls into practical ways
[Chorus]
STIGs in the RMF, where do they belong?
Step three implement, step four assess strong
Categorize drives selection, implementation makes it real
Assessment proves compliance, authorization seals the deal
Monitor continuously, that's how security feels
[Bridge]
Checklists and SCAP scanning provide the evidence you need
Authorization decisions based on how well you succeed
Continuous monitoring keeps the cycle turning round
STIG compliance status keeps your systems safe and sound
[Verse 3]
Three and four are where STIGs really shine their light
Implementation hardens systems, gets configurations right
Assessment phase validates that hardening took hold
Compliance evidence gathered, that's security gold
[Chorus]
STIGs in the RMF, where do they belong?
Step three implement, step four assess strong
Categorize drives selection, implementation makes it real
Assessment proves compliance, authorization seals the deal
Monitor continuously, that's how security feels
[Outro]
Six steps of RMF, STIGs play their part
From categorization through monitoring, security from the start
3. 1 What Are STIGs?
[Verse 1]
When the Pentagon needs security that's tight and strong
They call on DISA to help them get it right, not wrong
Security Technical Implementation Guides they create
To lock down every system before it's too late
[Chorus]
STIGs are the rules, STIGs show the way
Configure your systems the DoD way
From NIST controls to technical commands
STIGs bridge the gap with actionable plans
S-T-I-G, keep your data safe today
[Verse 2]
Operating systems, applications too
Networks and devices, they cover what you do
Every configuration standard crystal clear
To maintain security posture year after year
[Chorus]
STIGs are the rules, STIGs show the way
Configure your systems the DoD way
From NIST controls to technical commands
STIGs bridge the gap with actionable plans
S-T-I-G, keep your data safe today
[Bridge]
Eight hundred fifty-three controls from NIST above
CNSSI twelve fifty-three, standards that we love
But broad requirements need translation down below
STIGs make them specific, tell you how to go
[Verse 3]
Every single finding maps back to the source
NIST controls connected with traceability force
From policy frameworks to system-level action
STIGs ensure your defense gets satisfaction
[Chorus]
STIGs are the rules, STIGs show the way
Configure your systems the DoD way
From NIST controls to technical commands
STIGs bridge the gap with actionable plans
S-T-I-G, keep your data safe today
[Outro]
Defense Information Systems Agency's gift
Security standards that give your posture a lift
STIGs are the answer when compliance is key
Technical implementation, security set free
4. 2 Automation Resources
[Verse 1]
When compliance calls your name tonight
Manual checks just aren't quite right
There's a world of tools to make it flow
Automation resources you should know
DISA gives you SCAP content free
Official benchmarks, scripts with guarantee
Hardening guides that never sleep
Making security promises you can keep
[Chorus]
Two paths to choose, two ways to go
Automation makes your systems glow
Official sources, community strength
Going the distance, going the length
SCAP and Ansible, side by side
Let automation be your guide
Two resources, tried and true
Making STIG compliance work for you
[Verse 2]
Ansible STIG roles take the stage
Community playbooks, page by page
Lockdown scripts that run so clean
Best automation you've ever seen
Chef InSpec profiles test your way
Compliance as code, day by day
Validation running through the night
Making sure your configs shine so bright
[Chorus]
Two paths to choose, two ways to go
Automation makes your systems glow
Official sources, community strength
Going the distance, going the length
SCAP and Ansible, side by side
Let automation be your guide
Two resources, tried and true
Making STIG compliance work for you
[Bridge]
CIS benchmarks align so well
Security stories they help tell
SSG open source and free
Cross-platform security
AWS Config in the cloud
Azure Policy standing proud
Native controls that understand
STIG requirements across the land
[Chorus]
Two paths to choose, two ways to go
Automation makes your systems glow
Official sources, community strength
Going the distance, going the length
SCAP and Ansible, side by side
Let automation be your guide
Two resources, tried and true
Making STIG compliance work for you
[Outro]
Don't go manual when you can automate
Two resource types seal your fate
Official DISA, community care
STIG automation everywhere
5. 2 STIGs and the ATO Package
[Verse 1]
When your system's ready for the world to see
There's a package you must build carefully
STIG results are woven through each part
Four key documents, let's make a start
Security Assessment Report leads the way
Scan results and findings on display
Manual checks and automated tests
Show the world your system's at its best
[Chorus]
SAR and POA&M, SSP and RAR
These four docs will take your system far
STIG findings flow through every page
Authorization to Operate's the final stage
SAR and POA&M, SSP and RAR
STIG compliance is your guiding star
[Verse 2]
POA&M comes next in line to show
Every open finding that you need to know
Timeline for fixes, risk acceptance too
Remediation plans to see you through
System Security Plan references how
STIG controls are implemented right now
Each applicable standard gets its place
Security framework you can trace
[Chorus]
SAR and POA&M, SSP and RAR
These four docs will take your system far
STIG findings flow through every page
Authorization to Operate's the final stage
SAR and POA&M, SSP and RAR
STIG compliance is your guiding star
[Bridge]
Risk Assessment Report completes the set
Residual risk that leadership must get
STIG findings paint the picture clear
Of what remains when fixes aren't here
Four documents working as one team
Building trust in your security scheme
[Chorus]
SAR and POA&M, SSP and RAR
These four docs will take your system far
STIG findings flow through every page
Authorization to Operate's the final stage
SAR and POA&M, SSP and RAR
STIG compliance is your guiding star
[Outro]
From assessment through the final sign
STIG results keep everything in line
ATO package built with care and pride
Security and compliance side by side
6. 5 STIGs and the Canadian Context (CPCSC / ITSG-33)
[Verse 1]
Cross the border with your data flows
Defense contracts where security shows
STIGs from DISA, rules we know
But Canada's got standards of their own
ITSG thirty-three is their design
Risk management framework, keep in line
Parallel to NIST but maple leaf signed
Two nations, one mission, systems aligned
[Chorus]
Five STIGs and Canadian ways
ITSG, CPCSC through the maze
Cross-border ops need compliance days
Granular controls in both our plays
Windows, Network, Application bright
Web servers, Database done right
North and south, we'll get it right
Security standards, day and night
[Verse 2]
Canadian Program Cyber Certification
CPCSC is their foundation
Like CMMC but northern nation
Defense contractors need validation
DND requirements match DoD goals
Technical controls fill both their roles
STIGs provide the detailed scrolls
Implementation guides for both our souls
[Chorus]
Five STIGs and Canadian ways
ITSG, CPCSC through the maze
Cross-border ops need compliance days
Granular controls in both our plays
Windows, Network, Application bright
Web servers, Database done right
North and south, we'll get it right
Security standards, day and night
[Bridge]
When you serve both flags today
Document every control you display
Risk management framework's way
Makes compliance easier to weigh
Control families align so well
Technical standards parallel
One implementation story to tell
Cross-border security done swell
[Verse 3]
Granular guidance STIGs provide
Satisfies both nations side by side
Technical requirements can't hide
When you follow STIG as your guide
Defense contractors understand
Compliance spans across the land
One strong framework, helping hand
Security posture, take your stand
[Chorus]
Five STIGs and Canadian ways
ITSG, CPCSC through the maze
Cross-border ops need compliance days
Granular controls in both our plays
Windows, Network, Application bright
Web servers, Database done right
North and south, we'll get it right
Security standards, day and night
[Outro]
Two frameworks, one security goal
STIGs and ITSG play their role
Cross-border defense, heart and soul
Comprehensive compliance makes us whole
7. 2 Lab 2 — Automated SCAP Scanning
[Verse 1]
Time to automate our STIG compliance checking
Download SCC or OpenSCAP for scanning
SCAP Compliance Checker is the tool we need
Install it first, then we can proceed
Get your benchmark from the DISA site
Make sure the version matches just right
[Chorus]
Scan, check, review - automated way
Open findings, Not a Finding, Not Reviewed today
Import to STIG Viewer when the scan is done
Manual review completion has just begun
S-C-A-P scanning makes compliance clear
Automated checking keeps our systems secure
[Verse 2]
Fire up your virtual machine for testing
Run the scan command, no more guessing
Watch as SCAP evaluates each control
System configuration under its patrol
Red means Open, needs immediate care
Green Not a Finding, system's prepared there
[Chorus]
Scan, check, review - automated way
Open findings, Not a Finding, Not Reviewed today
Import to STIG Viewer when the scan is done
Manual review completion has just begun
S-C-A-P scanning makes compliance clear
Automated checking keeps our systems secure
[Bridge]
Not Reviewed items need human eyes
Manual validation, no surprise
STIG Viewer helps you track it all
Mark each finding, big or small
From automated scan to final report
Compliance checking of every sort
[Verse 3]
Generate reports when scanning's complete
Documentation makes your audit neat
Every vulnerability clearly displayed
Security posture properly weighed
Remediate the Opens, document the rest
Your system's ready for the compliance test
[Final Chorus]
Scan, check, review - automated way
Open findings, Not a Finding, Not Reviewed today
Import to STIG Viewer when the scan is done
Manual review completion has just begun
S-C-A-P scanning makes compliance clear
Automated checking keeps our systems secure
Lab two complete, you've learned it here
8. 3 Lab 3 — Manual STIG Assessment
[Verse 1]
Lab two is done but work's not through
Ten findings wait for me and you
They're marked "Not Reviewed" in red
Manual assessment lies ahead
Pull up the checklist, grab your guide
The Check Content is our roadside
[Chorus]
Manual STIG, dig deeper in
Find the truth that tools can't win
Check Content shows the way to go
Document what you need to know
Evidence clear, status defined
Satisfy the assessor's mind
[Verse 2]
Start with finding number one
Read the Check Content, here we come
Follow steps exactly right
Look for clues in plain sight
Is it compliant, yes or no
Mark the status, let it show
[Chorus]
Manual STIG, dig deeper in
Find the truth that tools can't win
Check Content shows the way to go
Document what you need to know
Evidence clear, status defined
Satisfy the assessor's mind
[Bridge]
Write the details crystal clear
Make your reasoning appear
Screenshots, logs, and config files
Evidence that goes for miles
Not a Finding or it fails
Your documentation tells the tales
[Verse 3]
Nine more findings wait in line
Take your time, the work is fine
Registry keys and service states
Policy settings, don't be late
Each one needs your careful eye
Manual checks will verify
[Chorus]
Manual STIG, dig deeper in
Find the truth that tools can't win
Check Content shows the way to go
Document what you need to know
Evidence clear, status defined
Satisfy the assessor's mind
[Outro]
Ten findings done, the work complete
Manual assessment can't be beat
When automation falls behind
Your human skills will always find
The truth that matters in the end
STIG compliance you defend
9. 4 Common Implementation Pitfalls
[Verse 1]
Started with compliance, thought I had it right
Checked every box upon my STIG checklist tonight
Changed the TLS settings without testing first
Now the legacy app won't start, and things got worse
I thought that I was being thorough and precise
But I learned that checking boxes don't suffice
[Chorus]
Don't just check and break and trust and ignore
Test your changes, manage logs, verify more
Check and break and trust and ignore
These are pitfalls we've all seen before
Understanding beats compliance every time
Get it right the first time, make your systems shine
[Verse 2]
Turned on comprehensive logging yesterday
Gigabytes of audit data flowing every day
But I forgot to plan for storage space
Now my disk is full and logs are getting erased
Should have set up forwarding and retention rules
Now I'm drowning in data like a bunch of fools
[Chorus]
Don't just check and break and trust and ignore
Test your changes, manage logs, verify more
Check and break and trust and ignore
These are pitfalls we've all seen before
Understanding beats compliance every time
Get it right the first time, make your systems shine
[Verse 3]
Scanner found some issues, marked them as high risk
But I trusted automation without double checking this
Manual validation showed a different view
Half those findings were false positives coming through
Technology's not listed but I let it slide
Should have used the SRG as my guide
[Bridge]
Version three point two but I'm using one point eight
Outdated STIG versions seal your system's fate
Every implementation needs a human eye
Automation helps but can't replace the why
[Chorus]
Don't just check and break and trust and ignore
Test your changes, manage logs, verify more
Check and break and trust and ignore
These are pitfalls we've all seen before
Understanding beats compliance every time
Get it right the first time, make your systems shine
[Outro]
Stage your testing, plan your logs
Verify scans and check your docs
STIG compliance done the proper way
Keeps your systems safe today
Back to Home