STIGQter STIGQter: STIG Summary:

Traditional Security Checklist

Version: 2

Release: 9 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-245722r1138389_ruleCOMSEC Account Management - Equipment and Key Storage
SV-245723r1138390_ruleCOMSEC Account Management - Appointment of Responsible Person
SV-245724r1138391_ruleCOMSEC Account Management - Program Management and Standards Compliance
SV-245725r1138485_ruleCOMSEC Training - COMSEC Custodian or Hand Receipt Holder
SV-245726r1138393_ruleCOMSEC Training - COMSEC User
SV-245727r1138394_ruleClassified Transmission - Electronic Means using Cryptographic System Authorized by the Director, NSA
SV-245728r1138395_ruleProtected Distribution System (PDS) Construction - Point of Presence (PoP) and Terminal Equipment Protection. This requirement concerns security of both the starting and ending points for PDS within proper physically protected and access controlled environments.
SV-245729r1138396_ruleProtected Distribution System (PDS) Construction - Hardened Carrier
SV-245730r1138397_ruleProtected Distribution System (PDS) Construction - Pull Box Security
SV-245731r1138398_ruleProtected Distribution System (PDS) Construction - Buried PDS Carrier
SV-245732r1138399_ruleProtected Distribution System (PDS) Construction - External Suspended PDS
SV-245733r1138400_ruleProtected Distribution System (PDS) Construction - Continuously Viewed Carrier
SV-245734r1138401_ruleProtected Distribution System (PDS) Construction - Tactical Environment Application
SV-245735r1138402_ruleProtected Distribution System (PDS) Construction - Alarmed Carrier
SV-245736r1138403_ruleProtected Distribution System (PDS) Construction - Visible for Inspection and Marked
SV-245737r1138404_ruleProtected Distribution System (PDS) Construction - Sealed Joints
SV-245738r1138405_ruleProtected Distribution System (PDS) Documentation - Signed Approval
SV-245739r1138406_ruleProtected Distribution System (PDS) Documentation - Request for Approval Documentation
SV-245740r1138407_ruleProtected Distribution System (PDS) Monitoring - Daily (Visual) Checks
SV-245741r1138408_ruleProtected Distribution System (PDS) Monitoring - Reporting Incidents
SV-245742r1138409_ruleProtected Distribution System (PDS) Monitoring - Technical Inspections
SV-245743r1138410_ruleProtected Distribution System (PDS) Monitoring - Initial Inspection
SV-245744r1138411_ruleEnvironmental IA Controls - Emergency Power Shut-Off (EPO)
SV-245745r1138412_ruleEnvironmental IA Controls - Emergency Lighting and Exits - Properly Installed
SV-245746r1138413_ruleEnvironmental IA Controls - Emergency Lighting and Exits - Documentation and Testing
SV-245747r1138414_ruleEnvironmental IA Controls - Voltage Control (power)
SV-245748r1138415_ruleEnvironmental IA Controls - Emergency Power
SV-245749r1138416_ruleEnvironmental IA Controls - Training
SV-245750r1138484_ruleEnvironmental IA Controls - Temperature
SV-245751r1138418_ruleEnvironmental IA Controls - Humidity
SV-245752r1138419_ruleEnvironmental IA Controls - Fire Inspections/Discrepancies
SV-245753r1138420_ruleEnvironmental IA Controls - Fire Detection and Suppression
SV-245754r1138421_ruleTEMPEST Countermeasures
SV-245755r1138422_ruleTEMPEST - Red/Black separation (Processors)
SV-245756r1138423_ruleTEMPEST - Red/Black Separation (Cables)
SV-245757r1138486_ruleForeign National System Access - Identification as FN in Email Address
SV-245758r917321_ruleForeign National System Access - Local Access Control Procedures
SV-245759r917322_ruleForeign National (FN) Systems Access - Local Nationals Overseas System Access - (SIPRNet or Other Classified System or Classified Network being Reviewed)
SV-245761r917323_ruleForeign National (FN) Systems Access - Local Nationals Overseas System Access - (NIPRNet User)
SV-245762r917324_ruleForeign National (FN) Systems Access - Delegation of Disclosure Authority Letter (DDL)
SV-245763r1138425_ruleForeign National System Access - FN or Immigrant Aliens (not representing a foreign government or entity) System Access - Limited Access Authorization (LAA)
SV-245764r1138426_ruleForeign National (FN) System Access - FN or Immigrant Aliens (not representing a foreign government or entity) with LAA Granted Uncontrolled Access
SV-245765r1138427_ruleForeign National (FN) Physical Access Control - Areas Containing US Only Information Systems Workstations/Monitor Screens, Equipment, Media or Documents
SV-245766r1136624_ruleForeign National (FN) Physical Access Control - (Identification Badges)
SV-245767r1138428_ruleForeign National (FN) Administrative Controls - Proper Investigation and Clearance for Access to Classified Systems and/or Information Assurance (IA) Positions of Trust
SV-245768r1138429_ruleForeign National (FN) Administrative Controls - Written Procedures and Employee Training
SV-245769r1138430_ruleForeign National (FN) Administrative Controls - Procedures for Requests to Provide Foreign Nationals System Access
SV-245770r1138431_ruleForeign National (FN) Administrative Controls - Contact Officer Appointment
SV-245771r1138433_ruleInformation Assurance - System Security Operating Procedures (SOPs)
SV-245772r1138487_ruleInformation Assurance - COOP Plan and Testing (Not in Place for Information Technology Systems or Not Considered in the organizational Holistic Risk Assessment)
SV-245773r1138488_ruleInformation Assurance - COOP Plan or Testing (Incomplete)
SV-245774r1136637_ruleInformation Assurance - System Security Incidents (Identifying, Reporting, and Handling)
SV-245775r1226291_ruleInformation Assurance - System Access Control Records (DD Form 2875 or equivalent)
SV-245776r1136638_ruleInformation Assurance - System Training and Certification/ IA Personnel
SV-245777r1136641_ruleInformation Assurance/Cybersecurity Training for System Users
SV-245778r1207698_ruleInformation Assurance - Accreditation Documentation
SV-245781r1207700_ruleInformation Assurance - KVM or A/B Switch not listed on the NIAP U.S. Government Approved Protection Products Compliance List (PCL) for Peripheral Sharing Switches
SV-245783r1207701_ruleInformation Assurance - KVM Switch Use of Hot-Keys on SIPRNet Connected Devices
SV-245784r1226312_ruleInformation Assurance - Authorizing Official (AO) and DODIN Connection Approval Office (CAO) Approval Documentation for use of KVM and A/B switches for Sharing of Classified and Unclassified Peripheral Devices
SV-245785r1207705_ruleInformation Assurance - Classified Portable Electronic Devices (PEDs) Connected to the SIPRNet must be Authorized, Compliant with NSA Guidelines, and be Configured for Data at Rest (DAR) Protection
SV-245786r1207708_ruleInformation Assurance - Unauthorized Wireless Devices - Portable Electronic Devices (PEDs) Used in Classified Processing Areas without Certified TEMPEST Technical Authority (CTTA) Review and Authorizing Official (AO) Approval.
SV-245787r1207709_ruleInformation Assurance - Unauthorized Wireless Devices - No Formal Policy and/or Warning Signs
SV-245788r1136644_ruleInformation Assurance - Network Connections - Physical Protection of Network Devices such as Routers, Switches and Hubs (Connected to SIPRNet or Other Classified Networks or Systems Being Inspected)
SV-245789r1136646_ruleInformation Assurance - Network Connections - Wall Jack Security on Classified Networks (SIPRNet or other Inspected Classified Network or System) Where Port Authentication Using IEEE 802.1X IS NOT Implemented
SV-245790r1138489_ruleInformation Assurance - Network Connections - Physical Protection of Unclassified (NIPRNet) Network Devices such as Routers, Switches and Hubs
SV-245791r1207711_ruleIndustrial Security - DD Form 254
SV-245792r1136653_ruleIndustrial Security - Contractor Visit Authorization Letters (VALs)
SV-245793r770041_ruleIndustrial Security - Contract Guard Vetting
SV-245794r770044_ruleInformation Security (INFOSEC) - Safe/Vault/Secure Room Management
SV-245795r1136655_ruleInformation Security (INFOSEC) - Vault/Secure Room Storage Standards - Door Combination Lock Meeting Federal Specification FF-L-2740
SV-245796r1014156_ruleInformation Security (INFOSEC) - Secure Room Storage Standards - Door Construction
SV-245797r1136658_ruleInformation Security (INFOSEC) - Secure Room Storage Standards Wall and Ceiling Structural Integrity (AKA: True Floor to True Ceiling Connection)
SV-245798r1136661_ruleInformation Security (INFOSEC) - Vault/Secure Room Storage Standards - Openings in Perimeter Exceeding 96 Square Inches
SV-245799r1138437_ruleInformation Security (INFOSEC) - Secure Room Storage Standards Windows - Accessible from the Ground Hardened Against Forced Entry and Shielded from Exterior Viewing of Classified Materials Contained within the Area.
SV-245800r1138545_ruleInformation Security (INFOSEC) - Vault Storage/Construction Standards
SV-245801r1138439_ruleInformation Security (INFOSEC) - Secure Room Storage Standards - Intrusion Detection System (IDS)
SV-245802r1138440_ruleInformation Security (INFOSEC) - Secure Room Storage Standards - Balanced Magnetic Switch (BMS) on Perimeter Doors
SV-245803r1136676_ruleInformation Security (INFOSEC) - Secure Room Storage Standards - Interior Motion Detection
SV-245804r1136679_ruleInformation Security (INFOSEC) - Secure Room Storage Standards - Four (4) Hour Random Checks in Lieu of Using Intrusion Detection System (IDS)
SV-245805r1136682_ruleVault/Secure Room Storage Standards - IDS Transmission Line Security
SV-245806r1136685_ruleVault/Secure Room Storage Standards - IDS Access/Secure Control Units Must be Located within the Secure Room Space
SV-245807r1138490_ruleInformation Security (IS) - Continuous Operations Facility: Access Control Monitoring Methods
SV-245808r1136691_ruleVault/Secure Room Storage Standards - Access Control During Working Hours Using Visual Control OR Automated Entry Control System (AECS) with PIN / Biometrics
SV-245809r1138546_ruleVault/Secure Room Storage Standards - Automated Entry Control System (AECS) and Intrusion Detection System (IDS) Head-End Equipment Protection: The physical location (room or area) containing AECS and IDS head-end equipment (server and/or work station/monitoring equipment) where authorization, personal identification or verification data is input, stored, or recorded and/or where system status/alarms are monitored must be physically protected.
SV-245810r1136696_ruleInformation Security (INFOSEC) - Secure Room Storage Standards - Structural Integrity Checks
SV-245811r1136699_ruleVault/Secure Room Storage Standards - IDS Performance Verification
SV-245812r1136701_ruleVault/Secure Room Storage Standards - Masking of IDS Sensors Displayed at the Intrusion Detection System (IDS) Monitoring Station
SV-245813r1136703_ruleVault/Secure Room Storage Standards - IDS Alarm Monitoring Indicators, both audible and visual (Alarm Status) must be displayed for each sensor or alarmed zone at the monitoring station.
SV-245814r1138475_ruleVault/Secure Room Storage Standards - Intrusion Detection System (IDS) / Automated Entry Control System (AECS) Primary and Emergency Power Supply
SV-245815r1138476_ruleVault/Secure Room Storage Standards - Intrusion Detection System and Automated Entry Control System (IDS/AECS) Component Tamper Protection
SV-245816r1138491_ruleVault/Secure Room Storage Standards - Primary IDS Monitoring Location Outside the Monitored Space
SV-245817r1138478_ruleVault/Secure Room Storage Standards - Automated Entry Control System (AECS) Records Maintenance, which includes documented procedures for granting and removal of access.
SV-245818r1138479_ruleVault/Secure Room Storage Standards - Automated Entry Control System (AECS) Transmission Line Security: AECS Transmission lines traversing an uncontrolled area (not within at least a Secret Controlled Access Area (CAA) ) shall use line supervision OR Electrical, mechanical, or electromechanical access control devices, which do not constitute an AECS that are used to control access during duty hours must have all electrical components, that traverse outside minimally a Secret Controlled Access Area (CAA), secured within conduit.
SV-245819r1138480_ruleVault/Secure Room Storage Standards - Automated Entry Control System (AECS) Door Locks: Electric Strikes and/or Magnetic Locking devices used in access control systems shall be heavy duty, industrial grade and be configured to fail secure in the event of a total loss of power (primary and backup).
SV-245820r1138481_ruleInformation Security (INFOSEC) - Secure Room Storage Standards - Perimeter Construction using Proper Permanent Construction Materials for True Ceiling, Walls and Floors.
SV-245821r1138482_ruleVault/Secure Room Storage Standards - Automated Entry Control System (AECS) Keypad Device Protection: Keypad devices designed or installed in a manner that an unauthorized person in the immediate vicinity cannot observe the selection of input numbers.
SV-245822r1138443_ruleMarking Classified - Equipment, Documents or Media: In a classified operating environment, all unclassified items must be marked in addition to all classified items.
SV-245823r1138444_ruleMarking Classified - Local or Enclave Classified Marking Procedures must be developed to ensure employees are familiar with appropriate organization Security Classification Guides (SCG), how to obtain guidance for marking classified documents, media and equipment, and where associated forms, classified cover sheets, labels, stamps, wrapping material for classified shipment, etc. can be obtained.
SV-245824r1138446_ruleClassified Working Papers are properly marked, destroyed when no longer needed, or treated as a finished document after 180 days.
SV-245825r1138447_ruleStorage/Handling of Classified Documents, Media, Equipment - must be under continuous personal protection and control of an authorized (cleared) individual OR guarded or stored in an approved locked security container (safe), vault, secure room, collateral classified open storage area or SCIF.
SV-245826r1138448_ruleNon-Disclosure Agreement - Standard Form 312: no person may have access to classified information unless that person has a security clearance in accordance with DODM 5200.02 and has signed a Standard Form (SF) 312, Classified Information Non-Disclosure Agreement (NDA), and access is essential to the accomplishment of a lawful and authorized Government function (i.e., has a need to know).
SV-245827r1138449_ruleHandling of Classified Documents, Media, Equipment - Written Procedures and Training for when classified material/equipment is removed from a security container and/or secure room.
SV-245828r1138450_ruleHandling of Classified - Use of Cover Sheets on Documents Removed from Secure Storage
SV-245829r1138452_ruleClassified Monitors/Displays (Physical Control of Classified Monitors From Unauthorized Viewing)
SV-245830r1138453_ruleMonitor Screens - Disable Access by CAC or Token Removal, or Lock Computer via Ctrl/Alt/Del
SV-245831r1136751_ruleClassified Monitors/Displays (Procedures for Obscuration of Classified Monitors) - protection from uncleared persons or those without a need-to-know.
SV-245832r1138456_ruleEnd-of-Day Checks - Organizations that process or store classified information must establish a system of security checks at the close of each duty and/or business day to ensure that any area where classified information is used or stored is secure. SF 701, Activity Security Checklist, shall be used to record such checks.
SV-245833r1136757_ruleClassified Reproduction - SIPRNet Connected Classified Multi-Functional Devices (MFD) located in Space Not Approved for Collateral Classified Open Storage.
SV-245834r1136759_ruleClassified Reproduction - Following guidance for System to Media Transfer of Data from systems connected specifically to the SIPRNet In-Accordance-With (IAW) US CYBERCOM CTO 10-133A.
SV-245835r1138458_ruleClassified Reproduction - Written Procedures for SIPRNet Connected Classified Multi-Functional Devices (MFD) located in Space Not Approved for Collateral Classified Open Storage. NOTE: This vulnerability concerns only PROCEDURES for the reproduction (printing, copying, scanning, faxing) of classified documents on Multi-Functional Devices (MFD) connected to the DODIN.
SV-245836r1138492_ruleDestruction of Classified Documents Printed from the SIPRNet Using Approved Devices on NSA Evaluated Products Lists (EPL).
SV-245837r1136765_ruleClassified Material Destruction - Improper Disposal of Automated Information System (AIS) Hard Drives and Storage Media
SV-245838r1156687_ruleClassified Destruction - Hard Drive and Storage Media Sanitization Devices and Plans are not Available for disposal of Automated Information System (AIS) Equipment On-Hand
SV-245839r1136769_ruleDestruction of Classified and Unclassified Documents, Equipment and Media - Availability of Local Policy and Procedures
SV-245840r1136771_ruleClassified Emergency Destruction Plans - Develop and Make Available
SV-245841r1138462_ruleSecurity Incident/Spillage - Lack of Procedures or Training for Handling and Reporting
SV-245842r1138463_ruleClassification Guides Must be Available for Programs and Systems for an Organization or Site
SV-245843r822908_ruleControlled Unclassified Information (CUI) - Employee Education and Training
SV-245844r1138494_ruleControlled Unclassified Information - Document, Hard Drive and Media Disposal
SV-245845r1226309_ruleControlled Unclassified Information - Handling, Storage and Controlling Access to Areas where CUI is Processed or Maintained
SV-245846r1136786_ruleControlled Unclassified Information - Encryption of Data at Rest
SV-245847r1226295_ruleControlled Unclassified Information - Transmission by either Physical or Electronic Means
SV-245848r1226298_ruleControlled Unclassified Information - Posting Only on Web-Sites with Appropriate Encryption; not on Publicly Accessible Web-Sites.
SV-245849r1136791_ruleControlled Unclassified Information (CUI) - Local Policy and Procedure
SV-245850r1226304_ruleControlled Unclassified Information - Marking/Labeling Media within Unclassified Environments (Not Mixed with Classified)
SV-245851r1136793_ruleClassified Annual Review
SV-245852r1136794_rulePosition of Trust - Knowledge of Responsibility to Self Report Derogatory Information
SV-245853r1136797_rulePosition of Trust - Local Policy Covering Employee Personal Standards of Conduct and Responsibilities
SV-245854r1136800_rulePosition of Trust - Training Covering Employee Standards of Conduct and Personal Responsibilities
SV-245856r1008552_ruleValidation Procedures for Security Clearance Issuance (Classified Systems and/or Physical Access Granted)
SV-245860r1138466_ruleOut-processing Procedures for Departing or Terminated Employees (Military, Government Civilian and Contractor)
SV-245861r1136806_ruleIntrusion Detection System (IDS) Monitoring Station Personnel - Suitability Checks
SV-245862r1136809_ruleIntrusion Detection System (IDS) Installation and Maintenance Personnel - Suitability Checks
SV-245863r1138467_rulePhysical Security Program - Physical Security Plan (PSP) and/or Systems Security Plan (SSP) Development and Implementation with Consideration/Focus on Protection of Information System Assets in the Physical Environment
SV-245864r1136815_ruleRisk Assessment -Holistic Review (site/environment/information systems)
SV-245865r1138468_rulePhysical Protection of Unclassified Key System Devices/Computer Rooms in Large Processing Facilities
SV-245866r1136821_ruleRestricted Area and Controlled Area Designation of Areas Housing Critical Information System Components or Classified /Sensitive Technology or Data
SV-245867r1138470_ruleSecurity-in-Depth (AKA: Defense-in-Depth) - Minimum Physical Barriers and Access Control Measures for Facilities or Buildings Containing DODIN (SIPRNet/NIPRNet) Connected Assets.
SV-245868r1138472_ruleVisitor Control - To Facility or Organization with Information System Assets Connected to the DISN
SV-245869r1136830_ruleSensitive Item Control - Keys, Locks and Access Cards Controlling Access to Information Systems (IS) or IS Assets Connected to the DISN
SV-245870r1138474_rulePhysical Penetration Testing - of Facilities or Buildings Containing Information Systems (IS) Connected to the DISN
SV-245871r1136836_ruleSecurity and Cybersecurity Staff Appointment, Training/Certification and Suitability
SV-245872r1138483_ruleSecurity Training - Information Security (INFOSEC) for ALL Employees; Military, Government Civilian and Contractor
SV-245873r770281_ruleCounter-Intelligence Program - Training, Procedures and Incident Reporting