Skip to content

About STIGreviewer

STIGreviewer is a desktop application for reviewing, editing, and managing DISA STIG checklists. It is built as a modern replacement for the free DISA STIG Viewer and is designed to make working with large numbers of checklist files faster and easier.

With STIGreviewer you can:

  • Open and edit STIG Checklist files in both supported formats — CKL (XML) and CKLB (JSON).

  • Load hundreds of checklists at once from individual files, folders, or ZIP archives.

  • Create new, blank checklists from DISA STIG XML or from SCAP scan results.

  • Update checklists when a new version of a STIG is released.

  • Combine, split, copy, and move groups of checklists in bulk.

  • Cross-reference your checklists against your eMASS POA&M to see which findings already have a POA&M entry.

  • See, at a glance, which checklists have data quality issues such as missing host information or outdated STIG versions.

  • Export checklists to PDF, Word, Excel, or CSV for reporting.

This guide is written for the people who use STIGreviewer day-to-day to do STIG reviews. You do not need to be a developer or a deep technical expert. If you are familiar with the idea of a STIG checklist and what a finding is, you have enough background to follow along.

  • Checklist — a CKL or CKLB file that contains the answers (findings) for a single STIG applied to a single host.

  • STIG — Security Technical Implementation Guide. The set of secure configuration requirements published by DISA.

  • CKL — the older XML checklist format.

  • CKLB — the newer JSON checklist format. STIGreviewer can convert CKL to CKLB.

  • POA&M — Plan of Action and Milestones. A tracking record (kept in eMASS) for findings that are not yet remediated.

  • Vulnerability or Vuln ID — the unique identifier (V-numbers) for a single requirement inside a STIG.