Security Technical Implementation Guide

Also known as:STIG

Security Technical ImplementationImplementationThe practical realization of a security design, requirement, or control in a system or process. Guide: Detailed hardening specification from the US defense sector for systems and products. This term is relevant to the assessment and design of modern security architecturesSecurity ArchitectureThe structured design of security controls, trust boundaries, data flows, and operational responsibilities. and should be applied within the specific technical and organizational context.

How it works and where it fits

Security Technical Implementation Guide places security within the lifecycle of software and technical change. Requirements, architecture, implementation, testing, release, and maintenance affect one another. The earlier a weakness or unsafe assumption is identified, the more precisely it can be corrected without relying solely on downstream security products.

Practical security relevance

Practical implementation requires explicit quality criteria, reviewable changes, and a traceable supply chain. Automated checks provide rapid feedback but do not replace threat modeling or manual analysis of security-critical logic. Dependencies, build systems, artifacts, and secrets need protection alongside source code; operational and incident findings feed back into development.

  • HardeningHardeningReduces the attack surface through secure configuration and the deactivation of unnecessary functions.: Reduces the attack surface through secure configuration and the deactivation of unnecessary functions.
  • Baseline ConfigurationBaseline ConfigurationDefined target state for secure system settings and authorized components.: Defined target state for secure system settings and authorized components.
  • Security MisconfigurationSecurity MisconfigurationInsecure or incomplete configuration of systems, applications, or cloud services.: Insecure or incomplete configuration of systems, applications, or cloud services.
  • NIST Cybersecurity FrameworkNIST Cybersecurity FrameworkFramework for structuring cyber risk management via centralized security functions.: Framework for structuring cyber risk management via centralized security functions.