• Fortify SCA 24.4.0 with 2024 Q4 Rulepacks: DISA STIG 6.1 BIRT report not available for export

    I'm using Fortify SCA 24.4.0 with Q4 2024 Rulepacks. The release notes for the 2024 Q4 security content update indicate that the DIS STIG 6.1 report is supported in them. However, I don't see a corresponding item in the Fortify SCA 24.4.0 release notes…
  • Fortify SCA - DISA STIG 5.1 question

    We are currently running Fortify SCA 22.1.1 which only goes up to DISA STIG 5.1. Is it possible to update the DISA STIGs while staying at SCA 22.1.1? Under Fortify Exchange > Premium content > I see several things to download, but I'm not sure which…
  • Fortify not displaying all STIG findings

    Hello, I am trying to see if anyone else has ran into this issue. I am running fortify using commands so Im not able to use the wizard. Everything seems to be working correctly; however, on the STIG report it will display on the top a certain number of…
  • Does anyone know how to customize a Policy to only reflect DoD STIG requirements?

    I'm trying to customize a Policy that only checks for issues pertinent to DoD STIGs in hopes that the scan will be faster and still meet the STIG auditing requirements. Currently some of my scans are running into >18 hours and/or days. Any help is appreciated…