STIG: Security Technical Implementation Guide in Cybersecurity

Frameworks
ByDecipherU Editorial
How is it pronounced?
stig/stɪɡ/

Rhymes with 'pig'.

STIG stands for Security Technical Implementation Guide. STIGs are configuration standards published by the Defense Information Systems Agency (DISA) for hardening IT products used in DoD environments. Each STIG contains specific settings and checks for operating systems, applications, and network devices.

How STIG Is Used in Cybersecurity

Security engineers apply STIG configurations to servers, workstations, and network devices to meet DoD hardening requirements. GRC analysts validate STIG compliance using automated scanning tools like SCAP and Evaluate-STIG. STIG knowledge is essential for cybersecurity professionals working with military or defense contractor systems.

Read the full glossary entry: DISA STIG in Cybersecurity

Cybersecurity Roles That Work with STIG

Related Cybersecurity Acronyms

Frequently asked questions

What does STIG stand for?

STIG stands for Security Technical Implementation Guide. STIGs are configuration standards published by the Defense Information Systems Agency (DISA) for hardening IT products used in DoD environments. Each STIG contains specific settings and checks for operating systems, applications, and network devices.

What is STIG used for in cybersecurity?

Security engineers apply STIG configurations to servers, workstations, and network devices to meet DoD hardening requirements. GRC analysts validate STIG compliance using automated scanning tools like SCAP and Evaluate-STIG. STIG knowledge is essential for cybersecurity professionals working with military or defense contractor systems.

Last verified: April 2026?Report an inaccuracy