DISA Security Technical Implementation Guides
STIG Reference
Official DISA STIG checklists for system hardening and security compliance. Browse CAT I, II, and III findings with check procedures and remediation guidance.
Browser
Directory Services
Endpoint Security
Operating System
Windows Server 2022
Windows Server 2019
Windows 11
Red Hat Enterprise Linux 9
Web Server
Severity Categories
Any vulnerability that could directly and immediately result in loss of Confidentiality, Integrity, or Availability. These are open findings — remediate immediately.
Any vulnerability that could potentially result in loss of CIA. The majority of STIG findings fall in this category and must be addressed within 30 days.
Any vulnerability that could degrade measures protecting CIA. These are best-practice hardening items addressed within 90 days or during scheduled maintenance.