Skip to main content

1. What are STIGs?
2. Who Develops STIGs?
3. Roughly how often are STIGs updated?
4. Where are STIGS published to/downloaded from?
5. Which STIGs require a CAC to download?
6. What are sunset products?
7. What authoritative documents dictate that DoD organizations use security technical implementation guidance?
8. What is XCCDF?
9. What is a CAT 1 finding?
10. Which software tool generates a manual review checklist?
11. What is the definition of 'Not Applicable'?
12. Other than STIG Viewer, how can you view the STIG file?
13. What is SCAP in terms of SCC?
14. Does SCC Scan for all configuration settings?
15. Which requires a CAC to download?