<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dod on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/dod/</link><description>Recent content in Dod on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/dod/index.xml" rel="self" type="application/rss+xml"/><item><title>DISA STIG</title><link>https://lesitedefrancois.be/en/compliance/disa-stig/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/disa-stig/</guid><description>&lt;p&gt;&lt;strong&gt;DISA STIGs&lt;/strong&gt; (Security Technical Implementation Guides) are published by the &lt;strong&gt;Defense Information Systems Agency (DISA)&lt;/strong&gt;, the US Department of Defense (DoD) agency responsible for IT infrastructure security standards. STIGs provide extremely prescriptive, line-item security configuration requirements for specific technology products — each STIG contains hundreds of individual &amp;ldquo;findings&amp;rdquo; (rules) specifying exact settings, permissions, and configurations required to harden a system. Unlike flexible frameworks (NIST 800-53) or guideline-oriented benchmarks (CIS), STIGs are &lt;strong&gt;mandatory for all DoD information systems&lt;/strong&gt; and are referenced by the broader US federal government, defense contractors (via CMMC), and intelligence community systems. Each finding is categorized by severity: &lt;strong&gt;CAT I&lt;/strong&gt; (high — failure could directly lead to loss of confidentiality, integrity, or availability), &lt;strong&gt;CAT II&lt;/strong&gt; (medium), and &lt;strong&gt;CAT III&lt;/strong&gt; (low). Systems must achieve full CAT I compliance and substantially address CAT II/III findings to receive an Authority to Operate (ATO). DISA publishes STIGs for hundreds of products and regularly updates them (typically quarterly). STIGs are developed in collaboration with the vendor — Red Hat, for instance, works directly with DISA to produce the RHEL STIG — and are made available to the public through DoD Cyber Exchange (public.cyber.mil). STIG compliance is verified using DISA&amp;rsquo;s &lt;strong&gt;STIG Viewer&lt;/strong&gt; or automated tools like &lt;strong&gt;OpenSCAP&lt;/strong&gt; that consume the machine-readable XCCDF/SCAP content.&lt;/p&gt;</description></item></channel></rss>