STIG Viewing Tools

XCCDF formatted SRGs and STIGs are intended be ingested into an SCAP validated tool for use in validating compliance of a Target of Evaluation (TOE). As such, getting to the content of a XCCDF formatted STIG to read and understand the content is not as easy as opening a .doc or .pdf file and reading it. The process can be a little confusing and trying.  Below are tools which can be used to view the STIGs and a Whitepaper describing the STIG Viewing processes.

DISA has produced standalone versions of STIG Viewer for the Windows and Linux platforms on 64-bit x86 processors. With the end of free support for Java 8 in early 2019, Oracle Corporation changed the licensing and distribution model for Java software. Users without supported Java 8 SE environments should use the standalone versions of STIG Viewer. Users with supported Java 8 SE environments may still use the current JAR file. DISA will base future STIG Viewer development on open-source software developed by the OpenJDK and OpenJFX projects.

  Title Size Updated
STIG Viewer User Guide (Sep 2022) STIG Viewer User Guide (Sep 2022)
1.77 MB 2022 09 21
STIG Viewer 2.17 Hashes STIG Viewer 2.17 Hashes
1.36 KB 2022 09 21
STIG Viewer 2.17-Win64 STIG Viewer 2.17-Win64
54.03 MB 2022 09 21
STIG Viewer 2.17-Win64 msi STIG Viewer 2.17-Win64 msi
54.26 MB 2022 09 21
STIG Viewer 2.17-Linux STIG Viewer 2.17-Linux
73.38 MB 2022 09 21
STIG Viewer 2.17 STIG Viewer 2.17
1.14 MB 2022 09 21
How to Create and SRG-STIG ID Mapping Spreadsheet How to Create and SRG-STIG ID Mapping Spreadsheet
298.21 KB 2021 02 03
Vendor STIG Acronym List Vendor STIG Acronym List
178.74 KB 2020 01 16
STIG Viewer Video STIG Viewer Video
2018 06 14
STIG Sorted by STIG ID STIG Sorted by STIG ID
103.46 KB 2015 03 30
STIG Sorted by Vulnerability ID STIG Sorted by Vulnerability ID
101.59 KB 2015 03 30

SRG/STIG Applicability Guide and Collection Tool

The purpose of the SRG/STIG Applicability Guide and Collection Tool is to assist the SRG/STIG user community in determining what SRGs and/or STIGs apply to a particular situation or Information System (IS) and to create a fully formatted document containing a “Collection” of SRGs and STIGs applicable to the situation being addressed.

The ISs or situations covered include a Base/Camp/Post/or Station (B/C/P/S), facility, Program /Service/major application, enclave, network, system, device, or vendor’s product.

The Collection document can serve as an artifact in the System Authorization and Risk Management processes.

The SRG/STIG Applicability Guide and Collection Tool will be updated periodically to include the most recent new SRG/STIG releases and sunset products.

For assistance, please contact disa.stig_spt@mail.mil

  Title Size Updated
STIG Applicability Guide - User Guide v2.x STIG Applicability Guide - User Guide v2.x
2.87 MB 2023 02 27
STIG Applicability Guide - Hashes v2.4.0 STIG Applicability Guide - Hashes v2.4.0
2.19 KB 2023 02 27
STIG Applicability Guide - Linux v2.4.0 STIG Applicability Guide - Linux v2.4.0
96.49 MB 2023 02 27
STIG Applicability Guide - Windows MSI v2.4.0 STIG Applicability Guide - Windows MSI v2.4.0
97.34 MB 2023 02 27
STIG Applicability Guide - Windows v2.4.0 STIG Applicability Guide - Windows v2.4.0
98.05 MB 2023 02 27