Skip to content

Export Requirements

How Vulcan's exports map to what DISA actually requires from a vendor STIG submission.

What DISA Requires

The DISA Vendor STIG Process Guide specifies that vendors submit a spreadsheet — not XCCDF XML. DISA converts the spreadsheet to XCCDF internally during finalization. The per-field rules for that spreadsheet (which fields are required, blank, or conditional for each status) are catalogued in Field Requirements.

Publication Model

DISA publishes STIGs in two tiers:

TierContentDistributionClassification
Public STIGAC rules onlyCyber Exchange (public)Unclassified
Confidential PackageNA, AIM, ADNM rules + compliance reportAuthorizing Officials upon requestCUI

SRG Publication Model

SRG components (see the SRG Authoring Workflow) publish differently from STIGs:

  • The published document is XCCDF, not a spreadsheet — there is no spreadsheet intermediary and no two-tier public/CUI split. The SRG XCCDF is the single published artifact.
  • Only Applicable requirements publish. Not Applicable requirements and their justifications stay on the component as the working record; Not Yet Determined requirements block release entirely.
  • Releasing an SRG component generates its XCCDF and stores it in Vulcan's SRG catalog, where it becomes a base for STIG components. An SRG component's XCCDF export produces the same published-SRG shape.

How Vulcan's Export Purposes Map to the Process

Project exports are purpose-first: you pick why you are exporting, and the mode applies the matching rules. The how-to lives in Import & Export; this table maps each purpose to its place in the DISA process:

PurposeDISA roleWhat the mode enforces
DISA Vendor SubmissionThe vendor deliverableExactly the 17 DISA template columns; STIGID blank (DISA fills it during finalization); Check/Fix blank for non-AC statuses; VulnDiscussion and Severity blank for NA; NYD rules excluded (not a DISA-recognized status)
STIG-Ready Publish DraftMatches the public STIG tierAC rules only, rules satisfied by other rules excluded — the shape DISA publishes on Cyber Exchange (XCCDF, InSpec)
Working CopyNot a DISA artifactEverything as authored, for internal review and round-trip editing (CSV, Excel)
BackupNot a DISA artifactFull-fidelity archive for restore and migration (JSON)

Submission readiness

Components containing only "Not Yet Determined" rules show a warning in DISA modes — they produce empty output, because NYD is not a status DISA accepts.

Reference

Part of the MITRE Security Automation Framework (SAF)