[Verse 1]
When you start the RMF journey, six steps guide your way
Categorize your system first, that's where STIGs come into play
System type determines which security requirements you'll need
SRGs and STIGs will follow from the categories you feed
[Chorus]
STIGs in the RMF, where do they belong?
Step three implement, step four assess strong
Categorize drives selection, implementation makes it real
Assessment proves compliance, authorization seals the deal
Monitor continuously, that's how security feels
[Verse 2]
Step two is all selection, controls you need to choose
Security requirements that STIGs will help you use
Technical guidance waiting for the implementation phase
STIGs turn abstract controls into practical ways
[Chorus]
STIGs in the RMF, where do they belong?
Step three implement, step four assess strong
Categorize drives selection, implementation makes it real
Assessment proves compliance, authorization seals the deal
Monitor continuously, that's how security feels
[Bridge]
Checklists and SCAP scanning provide the evidence you need
Authorization decisions based on how well you succeed
Continuous monitoring keeps the cycle turning round
STIG compliance status keeps your systems safe and sound
[Verse 3]
Three and four are where STIGs really shine their light
Implementation hardens systems, gets configurations right
Assessment phase validates that hardening took hold
Compliance evidence gathered, that's security gold
[Chorus]
STIGs in the RMF, where do they belong?
Step three implement, step four assess strong
Categorize drives selection, implementation makes it real
Assessment proves compliance, authorization seals the deal
Monitor continuously, that's how security feels
[Outro]
Six steps of RMF, STIGs play their part
From categorization through monitoring, security from the start