Gold standard for DoD configuration compliance. Machine-readable (SCAP/XCCDF format).
| STIG | Covers |
|---|---|
| Network Infrastructure Router | Cisco IOS/IOS XE/IOS XR, Juniper router hardening |
| Network Infrastructure L2 Switch | Port security, VLAN config, DHCP snooping, dynamic ARP inspection |
| Network Firewall | Firewall rule design, policy management, logging |
| Network WLAN | WPA2/WPA3 Enterprise, rogue AP detection |
| Network VPN | VPN gateway config, cipher requirements |
| Network IDS/IPS | IDS/IPS deployment and tuning |
| Network DNS | DNS server hardening, DNSSEC |
| General Purpose OS (GPOS) | Linux/Unix baseline (RHEL, Ubuntu, SUSE, Oracle) |
| Canonical Ubuntu 24.04 | Latest Ubuntu LTS hardening |
| Cisco ASA | ASA firewall-specific config |