Library
Guides
Plain-English explanations across the SecBaseline suite: how each standard works, how to automate it, and how its artifacts fit together. Guides live on the tool sites; the RHEL 8 STIG guide lives here.
DISA STIG
RHEL 8 STIG remediation
How the RHEL 8 benchmark is structured, how to scan with OpenSCAP, how to automate the fixes with Ansible or shell, and which rules to review by hand.
SSP Studio
What is CUI?
A plain-English introduction to Controlled Unclassified Information: what counts as CUI, why it matters for compliance, and how it flows through a System Security Plan.
CIS Benchmarks Explainer
GPO mapping for CIS Windows Benchmarks
How CIS Benchmark recommendations map to Group Policy Objects, so you can turn benchmark guidance into enforceable Windows domain policy.
OSCAL Bridge
What is OSCAL?
A plain-English introduction to OSCAL: the NIST data model for machine-readable compliance artifacts and how it replaces spreadsheets and prose.
STIG Explainer
ASD STIG (Application Security)
The Application Security and Development STIG explained in plain English: what it checks, why it matters, and how to apply it across the software lifecycle.
POA&M Guardian
What is a POA&M?
A plain-language guide to the Plan of Action and Milestones: what it is, why federal systems need one, how it fits NIST 800-53 and the RMF, and what belongs in every entry.
POA&M Guardian
FedRAMP POA&M Template Guide
The FedRAMP POA&M template explained: required columns, severity-based remediation windows, milestone tracking, and when to automate the spreadsheet.
CIS Benchmarks Explainer
CIS Ubuntu 22.04 Hardening Guide
Map CIS Ubuntu Linux 22.04 LTS Benchmark recommendation families to the exact files administrators edit: sysctl.conf, audit.rules, sshd_config, modprobe.d, PAM, and login.defs.