# STIGs

Published articles for STIGs.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run

DevFeed: [Introducing the Chainguard cinc-auditor image: STIG scanning for Chainguard Containers, ready to run](<https://devfeed.tech/articles/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run-13123.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-the-chainguard-cinc-auditor-image-stig-scanning-for-chainguard-containers-ready-to-run>)

Published: 2026-06-18T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [anchore](<https://devfeed.tech/topics/anchore.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [anchore](<https://devfeed.tech/tags/anchore.md>), [anchore-enterprise](<https://devfeed.tech/tags/anchore-enterprise.md>), [apache](<https://devfeed.tech/tags/apache.md>), [built-from-source](<https://devfeed.tech/tags/built-from-source.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cinc-auditor](<https://devfeed.tech/tags/cinc-auditor.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [pipeline](<https://devfeed.tech/tags/pipeline.md>), [scanner](<https://devfeed.tech/tags/scanner.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>)

### AI overview

Chainguard introduces a ready-to-run cinc-auditor container image for STIG scanning of Chainguard Containers. The image includes a maintained GPOS SRG InSpec profile, removes separate profile and dependency setup, and supports production compliance pipelines, including FedRAMP workflows.

### Source excerpt

Chainguard launches a ready-to-run STIG scanner with a built-in GPOS SRG InSpec profile, simplifying compliance scans for containers and FedRAMP workflows.

## CMMC Phase 2, explained: Requirements, deadlines, and who's affected

DevFeed: [CMMC Phase 2, explained: Requirements, deadlines, and who's affected](<https://devfeed.tech/articles/cmmc-phase-2-explained-requirements-deadlines-and-who-s-affected-13009.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cmmc-phase-2-explained>)

Published: 2026-04-29T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [MFA](<https://devfeed.tech/topics/mfa.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cmmc](<https://devfeed.tech/tags/cmmc.md>), [cmmc-container-images](<https://devfeed.tech/tags/cmmc-container-images.md>), [cmmc-phase-2](<https://devfeed.tech/tags/cmmc-phase-2.md>), [cmvp](<https://devfeed.tech/tags/cmvp.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity-maturity-model-certification](<https://devfeed.tech/tags/cybersecurity-maturity-model-certification.md>), [fips](<https://devfeed.tech/tags/fips.md>), [nist](<https://devfeed.tech/tags/nist.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [u-s-dod](<https://devfeed.tech/tags/u-s-dod.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains the requirements, deadlines, and scope of CMMC Phase 2. It describes the CMMC Level 2 certification requirements for organizations handling Controlled Unclassified Information or supporting Department of Defense and certain civilian agency contracts, including MFA, encryption, vulnerability scanning, supported systems, independent assessments, and compliance documentation.

### Source excerpt

CMMC Phase 2 and NIST 800-171 are here. Learn how Chainguard helps teams meet compliance with FIPS, STIGs, and zero-CVE containers.

## FedRAMP vulnerability scanning requirements explained

DevFeed: [FedRAMP vulnerability scanning requirements explained](<https://devfeed.tech/articles/fedramp-vulnerability-scanning-requirements-explained-13042.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fedramp-vulnerability-scanning-requirements-explained>)

Author: Can secure-by-default container images or VMs speed up FedRAMP authorization

Published: 2024-11-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Containers](<https://devfeed.tech/topics/containers.md>)

Tags: [audits](<https://devfeed.tech/tags/audits.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [automated](<https://devfeed.tech/tags/automated.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fips](<https://devfeed.tech/tags/fips.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [security](<https://devfeed.tech/tags/security.md>), [stigs](<https://devfeed.tech/tags/stigs.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

This article explains FedRAMP vulnerability scanning requirements, including the required scan scope, recurring authenticated scans, reporting expectations, remediation timelines, and the role of scan data in continuous monitoring, authorization evidence, POA&Ms, and risk reviews.

### Source excerpt

Understand FedRAMP vulnerability scanning rules, scope, and SLAs. Get compliance clarity and learn how to simplify audits.

## Chainguard's STIG-Hardened FIPS Images now generally available

DevFeed: [Chainguard's STIG-Hardened FIPS Images now generally available](<https://devfeed.tech/articles/chainguard-s-stig-hardened-fips-images-now-generally-available-12996.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-stig-hardened-fips-images-now-generally-available>)

Published: 2024-07-11T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [fips](<https://devfeed.tech/tags/fips.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [html](<https://devfeed.tech/tags/html.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [security-technical-implementation-guide](<https://devfeed.tech/tags/security-technical-implementation-guide.md>), [stig](<https://devfeed.tech/tags/stig.md>), [stigs](<https://devfeed.tech/tags/stigs.md>)

### AI overview

Chainguard announced the general availability of STIG-hardened FIPS Images. The release maps applicable GPOS SRG controls to containers and provides the STIG in XCCDF format for validation with SCAP tools, supporting FedRAMP compliance workflows.

### Source excerpt

Enhance your container security with Chainguard's STIG-hardened FIPS images, now generally available, offering unparalleled compliance and protection.