Directory
The SecBaseline suite
Each tool covers one standard and speaks the same language as the rest. Live tools are available now; the remainder are in development.
DISA STIG
STIG Explainer
Translates DISA STIG findings into plain English: what the rule checks, why it matters, the risk, and how to fix it. Maps findings to NIST 800-53 via CCI and prioritizes imported scan results.
Open STIG Explainer
CIS Benchmarks
CIS Benchmark Explainer
Explains CIS Benchmark recommendations in plain English, including operational impact. Maps to CIS Controls and prioritizes findings across Linux, Windows, cloud, and Kubernetes.
Open CIS Benchmark Explainer
OSCAL
OSCAL Bridge
Converts compliance prose to OSCAL, validates it against NIST's published OSCAL JSON Schema, and renders OSCAL back into readable views for catalogs, baselines, SSPs, assessment results, and POA&Ms.
Open OSCAL Bridge
System Security Plans
SSP Studio
Drafts and maintains System Security Plans from your control set, keeping narratives in sync with the baselines actually applied to each system.
Open SSP Studio
POA&M tracking
POAM Guardian
Tracks Plan of Action and Milestones items from open finding through closure, with owners, due dates, and the evidence attached to each remediation.
Open POAM Guardian
CMMC
CMMC Compass
Walks defense suppliers through CMMC readiness, showing which practices are met by existing baselines and which still need work before an assessment.
Shared capabilities
Shared capability
STIG ↔ CIS Crosswalk
The crosswalk pivots DISA STIG rules and CIS Benchmark recommendations against their common NIST 800-53 controls and classifies each relationship as exact, partial, none, or unmappable.
Guides
DISA STIG
RHEL 8 STIG remediation
How the RHEL 8 benchmark is structured, how to scan with OpenSCAP, how to automate the fixes with Ansible or shell, and which rules to review by hand.
SSP Studio
What is CUI?
A plain-English introduction to Controlled Unclassified Information: what counts as CUI, why it matters for compliance, and how it flows through a System Security Plan.
CIS Benchmarks Explainer
GPO mapping for CIS Windows Benchmarks
How CIS Benchmark recommendations map to Group Policy Objects, so you can turn benchmark guidance into enforceable Windows domain policy.
OSCAL Bridge
What is OSCAL?
A plain-English introduction to OSCAL: the NIST data model for machine-readable compliance artifacts and how it replaces spreadsheets and prose.
STIG Explainer
ASD STIG (Application Security)
The Application Security and Development STIG explained in plain English: what it checks, why it matters, and how to apply it across the software lifecycle.