San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

NIST SP 800-53 controls, mapped to STIG rules

Each control below lists the Control Correlation Identifiers that map to it and the DISA STIG rules that implement those CCIs. Built from the same data as our STIG mapper and served by the compliance API.

What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

ControlTitleFamilyCCIsSTIG rules
CM-6Configuration SettingsConfiguration Management26525
AU-12Audit Record GenerationAudit and Accountability18270
CM-7Least FunctionalityConfiguration Management40234
AC-6Least PrivilegeAccess Control25184
IA-5Authenticator ManagementIdentification and Authentication101113
AC-3Access EnforcementAccess Control6592
MA-4Nonlocal MaintenanceMaintenance2776
AU-3Content of Audit RecordsAudit and Accountability1476
AC-17Remote AccessAccess Control2555
SC-8Transmission Confidentiality and IntegritySystem and Communications Protection1144
CM-5Access Restrictions for ChangeConfiguration Management3541
AU-9Protection of Audit InformationAudit and Accountability2141
AC-7Unsuccessful Logon AttemptsAccess Control1640
IA-2Identification and Authentication (Organizational Users)Identification and Authentication3339
AC-2Account ManagementAccess Control9337
SC-3Security Function IsolationSystem and Communications Protection637
IA-11Re-authenticationIdentification and Authentication437
AU-4Audit Log Storage CapacityAudit and Accountability434
SC-4Information in Shared System ResourcesSystem and Communications Protection328
SC-23Session AuthenticitySystem and Communications Protection727

Of the 307 controls carrying a CCI mapping in this data, 60 have at least one STIG rule behind them in these benchmarks. We publish a page only where there is enough underlying data to be worth reading; the rest are served by the API.