Evaluate‑STIG: A system hardening assessment tool
Minnesota IT Services (MNIT), in partnership with the Minnesota National Guard, offers Evaluate Security Technical Implementation Guide (Evaluate-STIG), a proven, configuration scanning tool to help your organization strengthen its cybersecurity posture.
View a PDF summary of Evaluate-STIGHow it works
Evaluate‑STIG assesses your organization’s Windows and Linux systems, then generates detailed compliance reports, and highlights settings that require attention. Evaluate-STIG assessment service leverages a U.S. Navy-developed tool to quickly identify configuration weaknesses and support compliance with the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Benefits
- Provides efficient, automated system scans. The tool runs assessments across multiple systems – locally or remotely – to rapidly identify configuration gaps.
- Creates clear, actionable reports in multiple formats. Save them where your workflow requires, including secure Universal Naming Convention (UNC) paths.
- Supports diverse environments. Evaluate standard systems, as well as the vendor running configurations for broader infrastructure coverage.
- Easily integrates with automation. The tool displays the PowerShell commands it uses, allowing for ongoing scheduled checks.
- Provides enhanced insight with STIG Viewer. For partners who want deeper analysis, STIG Viewer provides visual scoring, detailed finding explanations, severity sorting, NIST references, remediation steps, and the ability to track configuration changes over time. Together, Evaluate‑STIG and STIG Viewer provide a comprehensive approach to system hardening and compliance reporting.
Build your cyber resilience
Evaluate‑STIG helps identify risks, so you can strengthen your environment through clear, prioritized recommendations. Note: When implementing more secure controls, the process might reveal or temporarily impact legacy systems, outdated processes, or unsupported integrations.
As cybersecurity threats increase, use this reliable, standardized, and efficient assessment method to:
- Improve security posture.
- Reduce vulnerabilities.
- Support audit readiness.
- Align with national cybersecurity standards.
- Strengthen intergovernmental cybersecurity cooperation.
The Evaluate‑STIG assessment provides valuable insight – identifying security gaps and highlighting improvement opportunities – so you can build a practical roadmap toward a more resilient, future-ready environment.
Eligibility and cost
Minnesota state, local, and Tribal (SLT) government partners can use the Evaluate-STIG service at no cost to enhance their cybersecurity resilience.
Get started
To learn more or to schedule an onboarding session, contact MNIT’s Cyber Navigator team at CN.MNIT@state.mn.us.