HomeGlossarySecurity Technical Implementation Guide (STIG)
Professional CertificationsSTIG

Security Technical Implementation Guide (STIG)

A STIG is a DoD cybersecurity configuration standard that specifies how hardware and software must be hardened to reduce vulnerabilities in defense information systems.

Quick answer

A STIG is a DoD cybersecurity configuration standard that specifies how hardware and software must be hardened to reduce vulnerabilities in defense information systems.


A Security Technical Implementation Guide (STIG) is a cybersecurity configuration standard published by the Defense Information Systems Agency (DISA) that specifies the security settings and hardening requirements for specific operating systems, applications, databases, and network devices deployed in Department of Defense information systems.

What is a STIG?

STIGs are the DoD's primary mechanism for standardizing the security configuration of IT components across the defense enterprise. Each STIG covers a specific technology, such as Windows Server, Red Hat Linux, Oracle Database, or a network switch, and specifies configuration settings, audit requirements, account management rules, and other technical controls that must be implemented to reduce vulnerabilities. STIG findings are categorized as CAT I (most severe, must be fixed), CAT II (significant risk, should be fixed), and CAT III (lower risk). Systems deployed in DoD environments must be configured per applicable STIGs and assessed for compliance during security authorization activities (the DoD Risk Management Framework, or RMF). Contractors who develop, integrate, or maintain DoD IT systems must understand and apply STIGs during system development and testing, and must document STIG compliance in their Security Technical Implementation Guide checklists (STIG viewer files). Failure to address CAT I STIG findings typically prevents a system from receiving an Authority to Operate (ATO). STIGs are publicly available from DISA's STIG Viewer application and the public DISA STIG website, and contractors are expected to stay current as DISA publishes updated STIGs for evolving technology versions.

Why STIGs matter for government contractors

STIG compliance is a non-negotiable technical requirement for any contractor deploying IT systems in DoD environments. Systems that do not meet STIG requirements cannot receive an ATO, which means they cannot operate. Proposal teams should address STIG compliance strategy in technical volumes, and system developers must build STIG adherence into their software development and configuration management processes from the start.

Example

An IT firm developing a web application for a Navy intelligence office applies all applicable DISA STIGs during development: the Apache web server STIG, the underlying Linux OS STIG, and the database STIG for PostgreSQL. Before submitting the system for ATO assessment, the firm runs STIG viewer checklists and resolves all CAT I findings and the majority of CAT II findings, enabling the assessor to approve the Authority to Operate without significant remediation holdups.

Frequently Asked Questions

Where can I find DISA STIGs?


DISA publishes STIGs on its public Cyber Exchange website (public.cyber.mil/stiq-wres/), where contractors can download current and archived STIGs as well as the STIG Viewer application used to assess and document compliance.

Are STIGs required for civilian agency systems?


STIGs are mandatory for DoD systems. Civilian agencies typically use NIST SP 800-53 controls and CIS Benchmarks rather than STIGs, though some civilian defense-adjacent agencies may reference STIGs. Contractors should confirm which configuration standards apply based on the specific agency and system security requirements.

How often are STIGs updated?


DISA updates STIGs on varying schedules, some are updated annually, others more frequently when significant vulnerabilities are discovered. Contractors must track STIG versioning to ensure their systems remain compliant as new STIG versions are released and old versions are sunset.

What is the difference between a STIG and a CIS Benchmark?


STIGs are DISA-published standards specifically for DoD systems and carry a mandatory compliance obligation for DoD IT. CIS (Center for Internet Security) Benchmarks are industry consensus security configuration guides widely used in civilian and commercial environments. Both serve similar hardening purposes but have different governance authorities and applicability contexts.

How Bidovate helps

Bidovate puts Security Technical Implementation Guide (STIG) to work inside your capture and proposal workflow.

Proposal checklists

See Bidovate in action

Book a demo and we will show you the platform using your actual contract data.