New administrators often treat vulnerability scanning and configuration hardening as the same task. They are complementary but distinct, and understanding the division tells you which tool answers which question.
Vulnerabilities versus misconfigurations
ACAS answers whether a host is running software with known weaknesses that need patching. STIGs answer whether the host is configured according to DoD’s hardening requirements. A fully patched host can fail dozens of STIG checks.
The DISA mandate
DoD directs components to use ACAS for vulnerability scanning and to apply DISA STIGs to every covered technology. Both requirements flow into the RMF through controls in the Risk Assessment, Configuration Management and System and Information Integrity families.
The reporting chain
Scan results and STIG checklists become evidence in the authorisation package and feed the continuous monitoring reports the authorising official reviews. What you produce at the console ends up in a risk decision.
Action step
List every operating system, database, web server and network device type in one enclave. For each note whether a STIG exists for it and whether it is currently included in an ACAS scan.
Tech Skills Library is independent and is not affiliated with, accredited by, or endorsed by any employer, government agency, standards body or vendor referenced in this course. This course is for education and skill-building only. It does not guarantee a job, promotion, security clearance or clearance eligibility, and no certification, credential or licence is issued on completion; learners who finish receive a Certificate of Completion badge only. Standards, frameworks and regulatory requirements change; always confirm current details with the issuing body and a qualified professional.