DEV Community

Cover image for Free DISA STIG checklists, sorted by product
TickYouOff
TickYouOff

Posted on Originally published at tickyouoff.com

Free DISA STIG checklists, sorted by product

A FortiGate goes in at the edge, an OpenShift 4.12 cluster comes up, and each ticket says to apply the STIG. DISA writes a separate Security Technical Implementation Guide for every product, so the first job is finding the one that matches the exact product and version you were handed.

I run TickYouOff, a free checklist app, and its STIG page groups 43 checklists by what you are hardening. 38 are STIG checklists, and the other five are general security checklists, labelled as such. Every checklist opens in the browser, with no signup wall and no ads.

What the page covers

  • Operating systems: Windows Server 2019, 2022 and 2025, Ubuntu 20.04, 22.04 and 24.04, AlmaLinux 9, macOS 26 Tahoe, iOS/iPadOS 17, iOS 18, Android 15 and 16.
  • Network: FortiGate, Juniper SRX, Cisco ISE, Windows Defender Firewall, and four Cisco checklists split by OS (IOS router, IOS XE switch, IOS XR router, NX-OS switch).
  • Web and database servers: IIS 10.0, Apache 2.4 on Windows, SQL Server 2022, Oracle Database 19c, Crunchy Data PostgreSQL 16, MongoDB 7.x and 8.x.
  • Virtualization and appliances: VMware vSphere 8.0, Kubernetes, OpenShift 4.12, Nutanix Acropolis, Axonius AX-OS, RGS MCM.
  • Desktop: Firefox, Chrome, Edge, Acrobat Reader DC and Defender Antivirus.

The general security checklists cover Amazon Linux 2023, two macOS releases, Teams and .NET Framework 4.

A checklist here is not a .ckl

In DoD work, "checklist" also names the file STIG Viewer saves for one system's review: .ckl in STIG Viewer 2.x, .cklb in 3.x. That file is the formal record of which requirements passed, failed or don't apply. The TickYouOff lists cover the hands-on part, one requirement per line, ticked off as each setting goes in. The result still gets recorded in STIG Viewer.

Check which release a checklist follows

Some pages carry the release in their address. The Defender Antivirus one says "ver 2 rel 7", and three of the Cisco ones say "y26m01". Where a page doesn't say, compare it with the current release on the DoD Cyber Exchange (cyber.mil) before you sign anything off. DISA revises STIGs, and a requirement's wording can change between releases.

The full directory, with a link to every checklist and a note on what to do when your product is missing, is on TickYouOff.

Top comments (0)