Terminology Index

Glossary

2953 terms

Open concept maps
S
32

STIGs

Security Technical Implementation Guides from the US Defense Information Systems Agency, detailed hardening checklists for specific products. STIGs are widely used hardening benchmarks beyond just defense.

STIGs are very detailed, product-specific hardening guides published by DISA: every required setting on a Windows server, a database, a network device, with the rationale and the check. While developed for US defense use, they are widely consulted as authoritative hardening references across industries. As a system-hardening fundamentals topic, STIGs sit alongside CIS Benchmarks as the most thorough sources of product hardening guidance. Following STIGs is often mandatory for federal systems and serves as a high bar elsewhere.

Introduced in: System Hardening Fundamentals

Examples

  • Following a STIG checklist for hardening a Windows server.
  • Treating STIGs as a high-bar hardening reference outside of defense.
  • Mandating STIG compliance for federal systems.