Directory

The SecBaseline suite

Each tool covers one standard and speaks the same language as the rest. Live tools are available now; the remainder are in development.

Shared capabilities

Shared capability

STIG ↔ CIS Crosswalk

The crosswalk pivots DISA STIG rules and CIS Benchmark recommendations against their common NIST 800-53 controls and classifies each relationship as exact, partial, none, or unmappable.

Guides

DISA STIG

RHEL 8 STIG remediation

How the RHEL 8 benchmark is structured, how to scan with OpenSCAP, how to automate the fixes with Ansible or shell, and which rules to review by hand.

SSP Studio

What is CUI?

A plain-English introduction to Controlled Unclassified Information: what counts as CUI, why it matters for compliance, and how it flows through a System Security Plan.

CIS Benchmarks Explainer

GPO mapping for CIS Windows Benchmarks

How CIS Benchmark recommendations map to Group Policy Objects, so you can turn benchmark guidance into enforceable Windows domain policy.

OSCAL Bridge

What is OSCAL?

A plain-English introduction to OSCAL: the NIST data model for machine-readable compliance artifacts and how it replaces spreadsheets and prose.

STIG Explainer

ASD STIG (Application Security)

The Application Security and Development STIG explained in plain English: what it checks, why it matters, and how to apply it across the software lifecycle.