Control Correlation Identifiers CCI
- SRG / STIG Library Compilations – DoD Cyber Exchange
The SRG-STIG Library Compilation .zip files are compilations of DoD Security Requirements Guides (SRGs) and DoD Security Technical Implementation Guides (STIGs), as well as some other content that may be available through the Cyber Exchange website’s STIG pages. Specifically excluded are Security Readiness Review (SRR) Tools (scripts and OVAL Benchmarks), Group policy objects, and draft SRGs and STIGs.
The Library Compilation .zip files will be updated and released during each SRG-STIG Update Release Cycle to capture all newly updated or released SRGs, STIGs, and Tools. New SRG-STIG content released mid-cycle will be individually downloadable from IASE as released. These SRGs-STIGs will appear in the subsequent release of the Library Compilation.
See SRG-STIG Library Compilation READ ME for more information to include download/extraction instructions and a FAQ.
NOTE: While every attempt will be made to provide a complete set of currently in force SRGs, STIGs, and related tools, DISA makes no guarantee as to the completeness of the compilation or the currently in force status of the contents.
NOTE: While every attempt will be made to publish updated compilation files on the SRG-STIG Quarterly Update Release date, publication may lag due to competing workloads. Updated Compilation files will be published on or as soon as possible the published date. We apologize for any inconvenience this may impose.
Concerns or questions related to the contents or format of these compilation files should be directed to the DISA STIG Customer Support Desk at
This email address is being protected from spambots. You need JavaScript enabled to view it. - The Control Correlation Identifier (CCI) provides a standard identifier and description for each of the singular, actionable statements that comprise an IA control or IA best practice.
- CCI bridges the gap between high-level policy expressions and low-level technical implementations. CCI allows a security requirement that is expressed in a high-level policy framework to be decomposed and explicitly associated with the low-level security setting(s) that must be assessed to determine compliance with the objectives of that specific security control.
- This ability to trace security requirements from their origin (e.g., regulations, IA frameworks) to their low-level implementation allows organizations to readily demonstrate compliance to multiple IA compliance frameworks.
- CCI also provides a means to objectively roll up and compare related compliance assessment results across disparate technologies.
Open Vulnerability and Assessment Language (OVAL)
- OVAL® is an information security community effort to standardize how to assess and report machine state of computer systems.
- Tools and services that use OVAL for the three steps of system assessment — representing system information, expressing specific machine states, and reporting the results of an assessment — provide enterprises with accurate, consistent, and actionable information so they may improve their security.
Most of us still lack an effective compliance fabric
- If we constantly fixate on having one standard as an index to all standards, we waste time and are always doing wrong things wrong ways for wrong results
- We have to tie configuration guidelines to standards, and standards to risk scenarios + industry + time.
- All standards and risks have a shelf life.
- We use our fabric to sense and avert danger – so when bad’s about to happen, we can get goosebumps
- What if the elephant in the room could interpret and report cyber security danger?
- What would we want the elephant to sense?
- How might danger change over time?
- Which framework for risk would make the most sense?
- How might we interpret the elephant’s behavior?
- What if the elephant implemented unified best practices?
Security controls and best practices from NIST, the Defense Information Systems Agency (DISA) and International Organization for Standardization (ISO), the Control Objectives for Information and Related Technology (COBIT) framework, and Payment Card Industry Data Security Standards (PCI DSS).
- access control policy
- continuous monitoring
- boundary protection
- event auditing incident detection and reporting
- device authentication
- user authentication
- data encryption
- vulnerability scanning
- track and monitor all resources

Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics