Resources & Documentation

CompliNIST guides, compliance framework references, and curated external links for RMF and authorization work.

What's in the lite Docker image

Pull and run locally — no subscription required for any of these features:

docker pull ghcr.io/stihelc/complinist-lite:lite

Included

  • Topology editor (drag-and-drop)
  • Terraform importer
  • Hardware/software inventory & PPSM
  • Control narrative editor (manual + templates)
  • SSP wizard + PDF export (LOW, MODERATE, HIGH)
  • Document file cabinet
  • Export to JSON, SVG, PNG, and CSV

Compliance Frameworks

NIST RMF

NIST Risk Management Framework

Comprehensive guide to the 7-step RMF process (NIST SP 800-37 Rev 2)

View Resources

Key Documents:

  • SP 800-37 Rev 2 - Risk Management Framework
  • SP 800-53 Rev 5 - Security and Privacy Controls
  • SP 800-53A Rev 5 - Assessing Security Controls
  • SP 800-53B - Control Baselines

DISA STIGs

Defense Information Systems Agency Security Technical Implementation Guides

Configuration standards for DoD information systems

View Resources

Key Documents:

  • Application Security STIGs
  • Operating System STIGs (RHEL, Windows)
  • Network Device STIGs
  • Database STIGs

FedRAMP

Federal Risk and Authorization Management Program

Standardized approach to security assessment for cloud services

View Resources

Key Documents:

  • FedRAMP Authorization Playbook
  • SSP Template
  • Security Assessment Plan (SAP)
  • Continuous Monitoring Guide

ISO 27001

International Organization for Standardization 27001

International standard for information security management systems

View Resources

Key Documents:

  • ISO/IEC 27001:2022 Standard
  • ISO/IEC 27002:2022 Controls
  • Implementation Guidance
  • Audit Checklist

Need Additional Support?

Our team of cybersecurity experts is here to help you succeed.