About STIGreviewer
STIGreviewer is a desktop application for reviewing, editing, and managing DISA STIG checklists. It is built as a modern replacement for the free DISA STIG Viewer and is designed to make working with large numbers of checklist files faster and easier.
What it does
Section titled “What it does”With STIGreviewer you can:
-
Open and edit STIG Checklist files in both supported formats — CKL (XML) and CKLB (JSON).
-
Load hundreds of checklists at once from individual files, folders, or ZIP archives.
-
Create new, blank checklists from DISA STIG XML or from SCAP scan results.
-
Update checklists when a new version of a STIG is released.
-
Combine, split, copy, and move groups of checklists in bulk.
-
Cross-reference your checklists against your eMASS POA&M to see which findings already have a POA&M entry.
-
See, at a glance, which checklists have data quality issues such as missing host information or outdated STIG versions.
-
Export checklists to PDF, Word, Excel, or CSV for reporting.
Who this guide is for
Section titled “Who this guide is for”This guide is written for the people who use STIGreviewer day-to-day to do STIG reviews. You do not need to be a developer or a deep technical expert. If you are familiar with the idea of a STIG checklist and what a finding is, you have enough background to follow along.
A few terms used in this guide
Section titled “A few terms used in this guide”-
Checklist — a CKL or CKLB file that contains the answers (findings) for a single STIG applied to a single host.
-
STIG — Security Technical Implementation Guide. The set of secure configuration requirements published by DISA.
-
CKL — the older XML checklist format.
-
CKLB — the newer JSON checklist format. STIGreviewer can convert CKL to CKLB.
-
POA&M — Plan of Action and Milestones. A tracking record (kept in eMASS) for findings that are not yet remediated.
-
Vulnerability or Vuln ID — the unique identifier (V-numbers) for a single requirement inside a STIG.