A Framework for Automated STIG Compliance for Navy Ships

Authors

  • Margaret Graves Naval Postgraduate School, Monterey, California
  • Alan Shaffer Naval Postgraduate School, Monterey, California
  • Gurminder Singh Naval Postgraduate School, Monterey, California

DOI:

https://doi.org/10.34190/eccws.25.1.4692

Keywords:

Navy Cybersecurity, STIG Compliance, Automated Remediation, Maritime Operations, DevSecOps, Risk Management Framework

Abstract

Historically, U.S. Navy ships have faced challenges in meeting the requirements of Cybersecurity Inspections (CSIs), with persistent Security Technical Implementation Guide (STIG) compliance gaps as a major contributing factor. Ships have relied on manual remediation processes that are often time-consuming and error-prone, given IT staff and operational constraints. Existing STIG automation tools do not address unique afloat challenges, such as intermittent connectivity, diverse network architectures, integration with cyber-physical systems, and split authorities between ship and Program of Record (PoR) managers. Commercial tools like SteelCloud ConfigOS, Ansible Automation Platform, and Microsoft PowerSTIG demonstrate automation feasibility in traditional enterprise environments, but do not adequately accommodate maritime operational realities, where ships undergo extended periods of limited network connectivity. This research developed an automated STIG compliance toolkit framework to address maritime constraints by systematically analysing existing tools, identifying cybersecurity capability gaps, and deriving requirements from documented CSI deficiency patterns and operational constraints. The framework's modular design includes asset discovery with coverage validation, compliance assessment with baseline deviation detection, risk-stratified automated remediation, and human oversight through Information Systems Security Manager (ISSM) decision support, while respecting authority boundaries between shipboard IT teams and PoR managers. Validation of the framework employed requirements traceability analysis, mapping 48 requirements to design components, workflow analysis, tracking data flow through representative compliance scenarios, and engaged with experts at Naval Information Warfare Center Pacific cybersecurity specialists to evaluate operational feasibility. The results confirmed the framework's validity and practicality while revealing that organizational factors beyond technology, including formal sustainment authority assignment, improvements in PoR baseline documentation processes, and enhanced network inventory data quality, are essential to successful framework deployment. The framework provides a comprehensive requirements baseline, modular architecture supporting platform diversity, and authority-aware decision logic that preserves operational safety. Future work on this research will include developing a system prototype, integrating machine learning for predictive risk management, and expanding research to examine additional CSI improvement factors.

Downloads

Published

2026-06-15