STIG and SCAP Compliance
9 chapters
1. 1 What a STIG Actually Is
[Verse 1]
DISA publishes guides to keep systems secure
Configuration standards that are tested and sure
Each STIG document covers one product line
Operating systems, databases, apps defined
Hundreds of rules inside each comprehensive tome
Making your infrastructure a hardened home
[Chorus]
STIG means Security Technical Implementation Guide
Rules and checks and fixes are your cyber guide
Rule ID, STIG ID, severity cats one through three
Description, check text, fix text, CCI
From critical to low risk, every finding has its place
DISA updates quarterly to keep up with the pace
[Verse 2]
Rule ID starts with SV, numbers follow long
STIG ID is shorter, product specific and strong
RHEL dash zero eight means Red Hat Enterprise Linux
Every rule maps clearly to the systems that it links
Category One is critical, must fix right away
Category Two significant, Category Three can wait a day
[Chorus]
STIG means Security Technical Implementation Guide
Rules and checks and fixes are your cyber guide
Rule ID, STIG ID, severity cats one through three
Description, check text, fix text, CCI
From critical to low risk, every finding has its place
DISA updates quarterly to keep up with the pace
[Bridge]
Description tells you what the vulnerability means
Check text shows you how to verify what the scanner sees
Fix text gives the steps to remediate the flaw
CCI maps to NIST eight hundred fifty-three controls you saw
Network devices, middleware, cloud services too
Every platform gets a STIG to see your setup through
[Verse 3]
When auditors come knocking with their compliance demands
You'll have documented proof that security stands
Each finding cross-references to federal control frameworks
Manual instructions that eliminate the guesswork
From Windows Server down to Oracle database
STIG compliance puts security in its rightful place
[Chorus]
STIG means Security Technical Implementation Guide
Rules and checks and fixes are your cyber guide
Rule ID, STIG ID, severity cats one through three
Description, check text, fix text, CCI
From critical to low risk, every finding has its place
DISA updates quarterly to keep up with the pace
[Outro]
Six components make each rule complete and clear
DISA's technical guidance keeps threats from drawing near
STIG documentation, your security foundation
Protecting all our systems across the entire nation
2. 1 STIG/SCAP Format Stack
[Verse 1]
In the world of compliance checking today
There's a stack that shows us the STIG way
XCCDF Benchmark sits up on top
Defining the rules that make systems stop
XML structure holds it all in place
Benchmarks and profiles set the pace
Groups contain rules with severity high
Each one numbered with an ID
[Chorus]
STIG stack climbing from bottom to top
OVAL defines where the checking won't stop
XCCDF Benchmark sets the standard clear
Results flow back when the tests appear
Format stack, format stack
SCAP components working back to back
Benchmark, rules, and OVAL too
STIG compliance coming through
[Verse 2]
Profile selects which rules to run
MAC-One Classified when security's done
Rule ID shows the specific test
SV numbers put controls to rest
Title tells you what must be true
RHEL Eight crypto FIPS won't do
Description explains the reasoning why
Check content makes the system comply
[Chorus]
STIG stack climbing from bottom to top
OVAL defines where the checking won't stop
XCCDF Benchmark sets the standard clear
Results flow back when the tests appear
Format stack, format stack
SCAP components working back to back
Benchmark, rules, and OVAL too
STIG compliance coming through
[Bridge]
Check system points to OVAL down below
Content reference tells us where to go
When the test runs results come back
Pass or fail upon this track
Fix element shows the remedy
CCI ident links to NIST taxonomy
Test result captures what was found
STIG format keeps systems sound
[Chorus]
STIG stack climbing from bottom to top
OVAL defines where the checking won't stop
XCCDF Benchmark sets the standard clear
Results flow back when the tests appear
Format stack, format stack
SCAP components working back to back
Benchmark, rules, and OVAL too
STIG compliance coming through
[Outro]
From benchmark down to OVAL's core
STIG format gives us so much more
Structured compliance in XML
The SCAP stack serves security well
3. 5 CCI: The Rosetta Stone
[Verse 1]
In the world of compliance there's a bridge we need
Between the STIG rules and controls that we read
DISA built a system to connect the dots
Control Correlation Identifiers tie up loose knots
Each CCI maps to one control statement clean
While STIG rules reference what the numbers mean
Multiple products can share the same code
When they implement controls on the same road
[Chorus]
CCI is the Rosetta Stone
Translation key we've always known
From STIG to NIST it shows the way
One identifier lights the pathway
CCI one four five three tells the tale
How encryption keeps our systems safe and well
The bridge between compliance worlds so wide
CCI is our trusty guide
[Verse 2]
Take RHEL zero eight zero one zero four zero zero
DOD approved encryption is the hero
Maps to CCI one thousand four five three
Which points to AC seventeen part two you see
Protection of confidentiality and integrity
Using encryption for our network security
The chain connects from rule to control clean
OSCAL SSP shows what it all means
[Chorus]
CCI is the Rosetta Stone
Translation key we've always known
From STIG to NIST it shows the way
One identifier lights the pathway
CCI one four five three tells the tale
How encryption keeps our systems safe and well
The bridge between compliance worlds so wide
CCI is our trusty guide
[Bridge]
Component RHEL eight server in the frame
Implementation status plays the game
Evidence provided through the STIG requirement
FIPS validated crypto shows compliance achievement
One CCI to many STIG rules can relate
When products implement controls at the same rate
The identifier shows which statement applies
No more guessing no more compliance lies
[Chorus]
CCI is the Rosetta Stone
Translation key we've always known
From STIG to NIST it shows the way
One identifier lights the pathway
CCI one four five three tells the tale
How encryption keeps our systems safe and well
The bridge between compliance worlds so wide
CCI is our trusty guide
[Outro]
When STIG meets OSCAL and the mapping's unclear
Just find the CCI and the path will appear
DISA's gift to compliance teams everywhere
The Rosetta Stone that shows us how to care
4. 2 Who Cares About OSCAL
[Verse 1]
When compliance gets complex and the paperwork grows
Every stakeholder needs structure that clearly shows
From the SSP author writing security plans
To the cloud service provider serving enterprise demands
[Chorus]
Who cares about OSCAL? Everyone in the chain
Authors and assessors, vendors feeling the pain
Standardized and structured, machine-readable too
OSCAL makes compliance work for me and you
[Verse 2]
GRC tool vendors building platforms that scale
Need consistent formats that will never fail
Assessors and three-P-A-Os create their plans
Document all their findings with structured commands
[Chorus]
Who cares about OSCAL? Everyone in the chain
Authors and assessors, vendors feeling the pain
Standardized and structured, machine-readable too
OSCAL makes compliance work for me and you
[Verse 3]
Authorizing officials need packages they can trust
Machine-validatable content is really a must
Cloud providers publish components defined
FedRAMP packages formatted and aligned
[Bridge]
Compliance consultants building SSPs with care
Managing lifecycles, frameworks everywhere
Policy authors writing catalogs and baselines clean
Most readable format the industry's seen
[Chorus]
Who cares about OSCAL? Everyone in the chain
Authors and assessors, vendors feeling the pain
Standardized and structured, machine-readable too
OSCAL makes compliance work for me and you
[Outro]
From creation to assessment to authorization day
OSCAL serves the stakeholders in every way
One format to rule them, one standard so true
OSCAL makes compliance work for me and you
5. 1 Who Cares About STIGs
[Verse 1]
System administrators wake up every morning
Hardening servers with STIG configurations
Running SCAP scans to check their compliance warnings
Making sure systems meet security specifications
[Verse 2]
Security engineers selecting what applies
Managing exceptions when standards can't be met
Interpreting results with their trained expert eyes
Choosing the right STIGs without any regret
[Chorus]
Who cares about STIGs, who needs them today
System admins, security teams show the way
ISSM and ISSO keeping watch from above
Vendors and auditors, STIGs are what they love
Who cares about STIGs, everyone plays their part
Making systems secure right from the start
[Verse 3]
Information System Security Managers lead
Overseeing compliance across every machine
ISSO partners help fulfill the need
Managing checklist evidence kept clean
[Verse 4]
Vendors and developers work with DISA's crew
Building STIGs for products they create
Ensuring their software can meet standards too
Requirements their systems can accommodate
[Chorus]
Who cares about STIGs, who needs them today
System admins, security teams show the way
ISSM and ISSO keeping watch from above
Vendors and auditors, STIGs are what they love
Who cares about STIGs, everyone plays their part
Making systems secure right from the start
[Bridge]
Auditors inspect the checklist results
Reviewing SCAP findings line by line
Each role has purpose, no one insults
Working together by security design
[Chorus]
Who cares about STIGs, who needs them today
System admins, security teams show the way
ISSM and ISSO keeping watch from above
Vendors and auditors, STIGs are what they love
Who cares about STIGs, everyone plays their part
Making systems secure right from the start
[Outro]
Five key players in the STIG game
Each one essential, each one the same
Security's strength comes from their combined frame
Who cares about STIGs, everyone knows the name
6. 2 For a Technical Audience
[Verse 1]
In the world of compliance there's a tale to tell
Two different layers working oh so well
STIGs and SCAP down at configuration ground
Checking every setting that can be found
Product specific rules they verify and test
While OSCAL sits above doing governance best
[Chorus]
Configuration down below
Governance up above
STIG and SCAP make settings flow
OSCAL models what we love
Catalogs and baselines too
SSPs in machine format
Evidence feeds right on through
That's where both the layers at
[Verse 2]
OSCAL speaks in structured data streams
Control catalogs and assessment schemes
System security plans in readable code
Assessment results down a digital road
While STIG scans tell you what's right or wrong
OSCAL makes the governance strong
[Chorus]
Configuration down below
Governance up above
STIG and SCAP make settings flow
OSCAL models what we love
Catalogs and baselines too
SSPs in machine format
Evidence feeds right on through
That's where both the layers at
[Bridge]
ComplianceAsCode builds the bridge between
Compliance Trestle keeps the pathway clean
STIG content becomes component definitions
OSCAL ready for all implementations
Two layers working hand in hand
Making compliance easier to understand
[Chorus]
Configuration down below
Governance up above
STIG and SCAP make settings flow
OSCAL models what we love
Catalogs and baselines too
SSPs in machine format
Evidence feeds right on through
That's where both the layers at
[Outro]
From settings to governance they unite
Making compliance frameworks work just right
7. 2 STIG Formats and Artifacts
[Verse 1]
When security standards need to be clear
Four artifacts help us engineer
STIG Manual leads the way today
XCCDF benchmark shows us how to stay
Safe and sound with rules defined
Machine and human both aligned
[Chorus]
STIG formats, four to know
Manual, Benchmark, Checklist, SRG flow
XCCDF XML shows the way
OVAL checks what systems say
Status codes tell the story true
Open findings, not reviewed
[Verse 2]
STIG Benchmark takes it further still
XCCDF plus OVAL gives the skill
Data streams for automated checks
SCAP content that interconnects
Machine readable, precise and clean
Best security you've ever seen
[Chorus]
STIG formats, four to know
Manual, Benchmark, Checklist, SRG flow
XCCDF XML shows the way
OVAL checks what systems say
Status codes tell the story true
Open findings, not reviewed
[Bridge]
Checklist files in CKL we find
XML structure, well designed
Per system evidence we trace
Not a Finding, Not Applicable
Not Reviewed or Open case
Each rule status has its place
[Verse 3]
SRG stands above them all
Security Requirements Guide stands tall
Higher level, bridges the gap
DoD policy to product map
Documents that pave the way
For STIGs we use today
[Final Chorus]
STIG formats, four to know
Manual, Benchmark, Checklist, SRG flow
XCCDF XML shows the way
OVAL checks what systems say
Four artifacts working as one
Security compliance, job well done
[Outro]
From requirements down to code
STIG artifacts light the road
Manual, Benchmark, Checklist, Guide
Security standards, verified
8. 3 The Analogy
[Verse 1]
Picture building your dream house, foundation to the roof
Every trade has got their standards, that's the basic truth
Electricians wire by the code, plumbers follow rules
Framers build the structure right with their specific tools
[Chorus]
STIGs are the building codes, product by product guide
OSCAL is the paperwork that keeps you certified
One tells you how to build it, one proves that you comply
You need them both together, like the earth needs the sky
[Verse 2]
Network switches need their settings, servers need their locks
Databases and firewalls, each one's got their blocks
STIGs define the standards for every piece of kit
Like electrical and plumbing codes, they make everything fit
[Chorus]
STIGs are the building codes, product by product guide
OSCAL is the paperwork that keeps you certified
One tells you how to build it, one proves that you comply
You need them both together, like the earth needs the sky
[Bridge]
Permit application starts the show
Inspection reports let the progress flow
Certificate of occupancy makes it legal now
OSCAL documents the what, the when, the why, the how
[Verse 3]
When the inspector comes around to check your cyber space
They want to see the OSCAL forms, documentation's face
But underneath those reports are STIGs that guide the way
Both working hand in hand to keep the threats at bay
[Chorus]
STIGs are the building codes, product by product guide
OSCAL is the paperwork that keeps you certified
One tells you how to build it, one proves that you comply
You need them both together, like the earth needs the sky
[Outro]
Don't think one replaces the other in this game
They're partners in security, not playing for the same
Build it right with STIGs, document with OSCAL's might
That's how you keep your systems running day and night
9. 7 "You have to choose one ecosystem or the other"
[Verse 1]
They tell you pick a side, it's one or the other way
STIGs or OSCAL, you can't have both they say
But that's old thinking from a siloed past
The future's integration, built to last
[Chorus]
Don't choose between, integrate the scene
STIGs configure, SCAP verifies clean
OSCAL governs what the docs all mean
Three layers working as one machine
Don't choose between, integrate the scene
[Verse 2]
Configuration layer needs those STIG rules tight
SCAP automation checks if settings are right
OSCAL documentation keeps governance clear
Three different jobs, but they work as peers
[Chorus]
Don't choose between, integrate the scene
STIGs configure, SCAP verifies clean
OSCAL governs what the docs all mean
Three layers working as one machine
Don't choose between, integrate the scene
[Bridge]
ComplianceAsCode builds the bridge you need
Compliance Trestle makes the pipeline feed
Organizations getting value most
Use integrated approach, not either-or boast
[Verse 3]
Mature approach says use them all as one
Pipeline flowing till the job is done
Configuration, verification, documentation flow
Together they make compliance systems grow
[Chorus]
Don't choose between, integrate the scene
STIGs configure, SCAP verifies clean
OSCAL governs what the docs all mean
Three layers working as one machine
Don't choose between, integrate the scene
[Outro]
False dichotomy leads you astray
Integration is the modern way
STIGs and OSCAL working hand in hand
That's how the best compliance systems stand
Back to Home