[Verse 1] When your system's ready for the world to see There's a package you must build carefully STIG results are woven through each part Four key documents, let's make a start Security Assessment Report leads the way Scan results and findings on display Manual checks and automated tests Show the world your system's at its best [Chorus] SAR and POA&M, SSP and RAR These four docs will take your system far STIG findings flow through every page Authorization to Operate's the final stage SAR and POA&M, SSP and RAR STIG compliance is your guiding star [Verse 2] POA&M comes next in line to show Every open finding that you need to know Timeline for fixes, risk acceptance too Remediation plans to see you through System Security Plan references how STIG controls are implemented right now Each applicable standard gets its place Security framework you can trace [Chorus] SAR and POA&M, SSP and RAR These four docs will take your system far STIG findings flow through every page Authorization to Operate's the final stage SAR and POA&M, SSP and RAR STIG compliance is your guiding star [Bridge] Risk Assessment Report completes the set Residual risk that leadership must get STIG findings paint the picture clear Of what remains when fixes aren't here Four documents working as one team Building trust in your security scheme [Chorus] SAR and POA&M, SSP and RAR These four docs will take your system far STIG findings flow through every page Authorization to Operate's the final stage SAR and POA&M, SSP and RAR STIG compliance is your guiding star [Outro] From assessment through the final sign STIG results keep everything in line ATO package built with care and pride Security and compliance side by side
← 2 Automation Resources | 5 STIGs and the Canadian Context (CPCSC / ITSG-33) →