Security Technical Implementation Guide
A DISA STIG is a configuration guide that tells organizations how to securely set up a specific piece of technology, such as an operating system or application, for use in Department of Defense environments. These guides are maintained by the Defense Information Systems Agency (DISA) and are geared to a particular product and version. They translate security requirements into concrete, product-specific settings so that systems are hardened in a consistent way.
A Security Technical Implementation Guide (STIG) is a product- and version-specific configuration hardening standard developed and maintained by the Defense Information Systems Agency (DISA) for Department of Defense information technology. Per NIST's glossary, STIGs are based on DoD policy and security controls and provide implementation guidance geared to a specific product and version, typically accompanied by more general Security Requirements Guides (SRGs). STIGs are living documents subject to ongoing maintenance; according to DISA guidance, discontinued DISA support for a given STIG means no active maintenance and therefore no updates for newly discovered vulnerabilities in that product. Access to authoritative STIG content on DoD Cyber Exchange NIPR generally requires a Common Access Card (CAC) with DoD certificates. Practitioners should note that applying a STIG addresses configuration hardening only and does not by itself constitute authorization; STIG compliance is one input to broader assessment and authorization activities, and readers should verify the current applicable STIG revision against official DISA sources.
Why it matters
STIGs are the mechanism by which broad Department of Defense security policy and controls become concrete, product-specific configuration settings. Without this translation layer, two teams deploying the same operating system or application could interpret the same high-level requirement in very different ways, producing inconsistent hardening across DoD environments. STIGs reduce that variance by prescribing settings geared to a specific product and version, which helps assessors, system owners, and authorizing officials evaluate systems against a common, documented baseline.
Because STIGs are living documents, their value depends on staying current. According to DISA guidance, when DISA discontinues support for a given STIG there is no active maintenance and therefore no updates, meaning newly discovered vulnerabilities in that product will not be reflected. Practitioners relying on an unmaintained or superseded STIG may believe a system is hardened when it no longer reflects current risk, so the applicable revision should always be verified against official DISA sources.
A common and important mistake is to treat STIG compliance as equivalent to security or to authorization. STIGs address configuration hardening only. Meeting a STIG does not by itself constitute an Authority to Operate, and it is not a substitute for the broader assessment and authorization activities that determine whether a system may operate. STIG compliance is one input into those activities, not the conclusion of them.
Who it's relevant to
Inside STIG
Common questions
Answers to the questions practitioners most commonly ask about STIG.