Library

Guides

Plain-English explanations across the SecBaseline suite: how each standard works, how to automate it, and how its artifacts fit together. Guides live on the tool sites; the RHEL 8 STIG guide lives here.

DISA STIG

RHEL 8 STIG remediation

How the RHEL 8 benchmark is structured, how to scan with OpenSCAP, how to automate the fixes with Ansible or shell, and which rules to review by hand.

SSP Studio

What is CUI?

A plain-English introduction to Controlled Unclassified Information: what counts as CUI, why it matters for compliance, and how it flows through a System Security Plan.

CIS Benchmarks Explainer

GPO mapping for CIS Windows Benchmarks

How CIS Benchmark recommendations map to Group Policy Objects, so you can turn benchmark guidance into enforceable Windows domain policy.

OSCAL Bridge

What is OSCAL?

A plain-English introduction to OSCAL: the NIST data model for machine-readable compliance artifacts and how it replaces spreadsheets and prose.

STIG Explainer

ASD STIG (Application Security)

The Application Security and Development STIG explained in plain English: what it checks, why it matters, and how to apply it across the software lifecycle.

POA&M Guardian

What is a POA&M?

A plain-language guide to the Plan of Action and Milestones: what it is, why federal systems need one, how it fits NIST 800-53 and the RMF, and what belongs in every entry.

POA&M Guardian

FedRAMP POA&M Template Guide

The FedRAMP POA&M template explained: required columns, severity-based remediation windows, milestone tracking, and when to automate the spreadsheet.

CIS Benchmarks Explainer

CIS Ubuntu 22.04 Hardening Guide

Map CIS Ubuntu Linux 22.04 LTS Benchmark recommendation families to the exact files administrators edit: sysctl.conf, audit.rules, sshd_config, modprobe.d, PAM, and login.defs.