Security Requirements Guide
A Security Requirements Guide (SRG) is a Department of Defense (DoD) document that lays out the security requirements applicable to a particular category of technology, such as operating systems or cloud computing services. It serves as a foundational, technology-general set of requirements from which more specific implementation guidance is later derived. SRGs are published as tools to help improve the security of DoD information systems.
An SRG is a DoD-published set of security requirements organized at a technology-family or capability level (for example, general-purpose operating systems or cloud computing). According to NIST's glossary, an SRG generally contains all requirements flagged as applicable from the parent level, regardless of whether they are selected on a specific DoD baseline. SRGs are typically the intermediate layer between broader security controls and product-specific Security Technical Implementation Guides (STIGs), which provide the detailed, product-tailored implementation requirements derived from an applicable SRG. A notable specialized example is the Cloud Computing Security Requirements Guide (CC SRG), which outlines the security model for DoD's use of cloud computing and supports a standardized assessment and authorization process for cloud service providers. Practitioners should verify the current revision and applicability of any given SRG against the official DoD sources, as content and structure evolve across versions and this entry does not address specific implementation, contractual, or authorization details.
Why it matters
Security Requirements Guides sit at a critical point in the DoD's layered approach to system hardening. Because they define security requirements at a technology-family level, such as general-purpose operating systems or cloud computing, they establish the common baseline from which product-specific Security Technical Implementation Guides (STIGs) are derived. For compliance officers and information system security managers, understanding the SRG-to-STIG relationship matters because implementation guidance you apply to a specific product traces back to the requirements set out in its applicable SRG. Misunderstanding that lineage can lead teams to treat STIG compliance as self-contained rather than as an implementation of a broader requirement set.
The Cloud Computing Security Requirements Guide (CC SRG) is a particularly consequential specialized example, as it outlines the security model for DoD's use of cloud computing and supports a standardized assessment and authorization process for cloud service providers. Practitioners working with cloud offerings should note an expert distinction here: participation in that DoD-oriented process is not automatically the same as, nor a substitute for, other authorizations a provider may hold. A FedRAMP authorization, for instance, does not by itself satisfy DoD requirements, and readers should confirm the specific authorization pathway and impact level applicable to their use case against current official DoD sources.
A further common mistake this guidance helps correct is conflating assessment with authorization and treating compliance as a static, one-time achievement. SRGs and their derived STIGs are tools to improve system security, but applying them does not by itself confer an Authority to Operate, which remains time-bound and subject to continuous monitoring. Because SRG content and structure evolve across revisions, relying on an outdated version can quietly undermine an otherwise sound compliance posture.
Who it's relevant to
Inside SRG
Common questions
Answers to the questions practitioners most commonly ask about SRG.