STIGs and Compliance Framework

9 chapters

Chapters

  1. 1 STIGs ↔ CMMC
    STIGs and Compliance Framework · 4:42
    Explore the powerful relationship between STIGs and the Cybersecurity Maturity Model Certification (CMMC), uncovering how both frameworks share a common NIST foundation that organizations can leverage across all three certification levels.
  2. 1 Where STIGs Fit in the RMF
    STIGs and Compliance Framework · 4:14
    Discover where STIGs fit within the Risk Management Framework's six-step process, revealing how system categorization drives the selection of Security Requirements Guides and STIGs. Listeners will gain a clear understanding of how Steps 3 and 4 — implement and assess — serve as the critical stages where STIGs come to life in federal security compliance.
  3. 1 What Are STIGs?
    STIGs and Compliance Framework · 7:59
    Dive into the world of STIGs as this chapter breaks down what Security Technical Implementation Guides are, who creates them, and why the Department of Defense relies on them to lock down and secure their critical systems.
  4. 2 Automation Resources
    STIGs and Compliance Framework · 3:42
    Exploring the powerful automation tools available for compliance work, this chapter introduces DISA's free SCAP content, official benchmarks, and hardening guides that streamline the tedious process of manual security checks.
  5. 2 STIGs and the ATO Package
    STIGs and Compliance Framework · 3:42
    Dive into the essential components of an Authorization to Operate (ATO) package, where you'll learn how STIG results connect to the four critical documents needed to get your system officially approved for deployment.
  6. 5 STIGs and the Canadian Context (CPCSC / ITSG-33)
    STIGs and Compliance Framework · 3:54
    Explore how STIGs align with Canada's cybersecurity landscape, diving into ITSG-33 and the CPCSC framework as a NIST-parallel approach to risk management that governs defense and government security standards north of the border.
  7. 2 Lab 2 — Automated SCAP Scanning
    STIGs and Compliance Framework · 4:04
    Dive into hands-on automation of STIG compliance scanning using tools like SCC and OpenSCAP, walking through the process of downloading, installing, and running benchmark scans to streamline your security compliance workflow.
  8. 3 Lab 3 — Manual STIG Assessment
    STIGs and Compliance Framework · 4:16
    A hands-on lab walkthrough guides you through manually assessing ten unreviewed STIG findings, teaching you how to use the checklist and Check Content to conduct a proper manual security evaluation.
  9. 4 Common Implementation Pitfalls
    STIGs and Compliance Framework · 3:21
    Discover the most common mistakes organizations make when implementing STIGs and compliance frameworks, from rushing through checklists to making untested configuration changes that break critical systems.