Platform Features

Unified Compliance OperationsIn One Platform

One platform. Unified compliance operations — centralize STIGs, findings, remediation, evidence, POA&Ms, assignments, and eMASS preparation, built for on-premises, air-gapped, and classified environments.

Systems & Environments

Create and manage systems representing enclaves or RMF package boundaries.

  • Define classification and metadata
  • Control visibility based on user roles
  • View system-wide STIG findings
  • Compliance metrics dashboard

Asset Management

Comprehensive asset tracking with multiple import options.

  • Manual or bulk eMass import (.xlsx/.csv)
  • Automated asset creation during uploads
  • Asset grouping for shared STIGs
  • Complete audit history

STIG & Checklist Management

Full STIG lifecycle management from upload to export.

  • Upload STIGs individually or in batches
  • Associate STIGs with assets or groups
  • Generate new checklists from findings
  • View STIG version changes and impact

Findings Management

Central findings table with powerful filtering and bulk operations.

  • Filter by host, vulnerability, severity, status
  • Inline editing with real-time updates
  • Rule viewer with Discussion, Check, Fix
  • Bulk update capabilities

Dashboards & Reporting

Visual compliance insights and system-specific overviews.

  • Compliance graphs and severity breakdowns
  • System-specific overview panels
  • Quick navigation to assets and STIGs

User Roles & Access Control

Role-based access with tailored visibility and permissions.

  • Super Admin capabilities
  • ISSM and ISSO/System Admin roles
  • Asset Group Admin access
  • View-Only user support

eMASS Integration & Scan Imports

Seamless data exchange with eMASS and automated vulnerability scan imports.

  • Import/Export assets and POA&Ms from eMASS
  • Import ACAS scan results
  • Import SAST scans (Fortify)
  • Automated vulnerability mapping to STIGs

POA&M Management

Comprehensive Plan of Action & Milestones tracking with full RMF alignment.

  • Create POA&Ms linked to findings, assets, and systems
  • Auto-generate from STIG findings or scan results
  • Track remediation progress, milestones, and due dates
  • Export in eMASS-aligned formats with full traceability

Email Notifications & Reminders

Automated alerts for assignments, deadlines, overdue work, and compliance activity.

  • Alerts for new assignments and upcoming deadlines
  • Overdue work reminders
  • Compliance activity digests
  • Configurable notification preferences

Task Assignments / My Tasks

Assign compliance work to individual users and track completion from a personalized task view.

  • Assign findings and remediation tasks to users
  • Personalized task view per user
  • Track completion status and history
  • Role-based task visibility

Document Repository

Centralize compliance evidence, supporting documentation, diagrams, reports, and artifacts.

  • Centralize evidence and artifacts in one place
  • Attach diagrams, reports, and supporting docs
  • Link documents to systems, hardware assets, software assets, and POA&Ms
  • Versioned document storage

STIG Version Management

Identify changes between STIG releases and understand their impact on existing findings.

  • Compare changes between STIG releases
  • Impact analysis on existing findings
  • Track rule additions, removals, and modifications
  • Automated re-evaluation guidance

And Much More...

Asset Grouping

Group assets for bulk STIG allocations

Batch Uploads

Batch import assets, STIGs and checklists

Advanced Search

Find any asset, STIG, or finding instantly

Bulk Editing

Update multiple findings simultaneously

Export Options

Support for Assets, Checklists, and Findings exports

ACAS Scan Import

Direct import of ACAS vulnerability scans

SAST Integration

Import Fortify static analysis results

Air-Gap Ready

No internet access required

Version Control

SemVer with change control and audits

Technical Overview

Deploy in Minutes

Asset Guard installs quickly using a scripted Docker deployment, designed for air-gapped and secure environments.

Ubuntu 22.04+

Server Requirements

Docker & Docker Compose

Container Platform

SSL Support

Security Layer

Apache Reverse Proxy

Web Access

Prepackaged Images

Easy Deployment

Backup/Restore

Data Safety

Ready to Simplify YourRMF Compliance?

See how Asset Guard can transform your compliance workflow, reduce manual workload, and strengthen your security posture.