[Verse 1] Time to automate our STIG compliance checking Download SCC or OpenSCAP for scanning SCAP Compliance Checker is the tool we need Install it first, then we can proceed Get your benchmark from the DISA site Make sure the version matches just right [Chorus] Scan, check, review - automated way Open findings, Not a Finding, Not Reviewed today Import to STIG Viewer when the scan is done Manual review completion has just begun S-C-A-P scanning makes compliance clear Automated checking keeps our systems secure [Verse 2] Fire up your virtual machine for testing Run the scan command, no more guessing Watch as SCAP evaluates each control System configuration under its patrol Red means Open, needs immediate care Green Not a Finding, system's prepared there [Chorus] Scan, check, review - automated way Open findings, Not a Finding, Not Reviewed today Import to STIG Viewer when the scan is done Manual review completion has just begun S-C-A-P scanning makes compliance clear Automated checking keeps our systems secure [Bridge] Not Reviewed items need human eyes Manual validation, no surprise STIG Viewer helps you track it all Mark each finding, big or small From automated scan to final report Compliance checking of every sort [Verse 3] Generate reports when scanning's complete Documentation makes your audit neat Every vulnerability clearly displayed Security posture properly weighed Remediate the Opens, document the rest Your system's ready for the compliance test [Final Chorus] Scan, check, review - automated way Open findings, Not a Finding, Not Reviewed today Import to STIG Viewer when the scan is done Manual review completion has just begun S-C-A-P scanning makes compliance clear Automated checking keeps our systems secure Lab two complete, you've learned it here
← 5 STIGs and the Canadian Context (CPCSC / ITSG-33) | 3 Lab 3 — Manual STIG Assessment →