Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)

The Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) is a set of rigorous cybersecurity standards and configuration guidelines defined by the U.S. Department of Defense (DoD). STIGs outline specific technical controls ranging from password complexity and audit logging to session timeouts and encryption protocols designed to harden software, hardware, and network components against unauthorized access and cyber threats.

STIG compliance is usually required for the following use cases:

  • DoD and federal deployments

    Systems operating within the DoD Information Network (DoDIN) or handling defense-related data must strictly comply with applicable STIG baselines.

  • Defense contractors

    Service-level agreements require vendors and system integrators selling into federal and defense sectors to maintain STIG-compliant software configurations.

  • Enterprise-grade hardening

    Non-government enterprises adopt STIG baselines as an operational standard to achieve a zero-trust security posture.

MOSK applies non-impactful DISA STIG controls in the default host operating system configuration. For remaining controls that might affect operations and are therefore considered environment-specific, Mirantis provides host OS configuration recipes that cloud operators can apply to the cluster. For the latest validation results and documented exceptions, see DISA STIG compliance in MOSK. To apply the recipes, see Apply DISA STIG hardening on host operating systems.