Skip to content

User Guide ​

Comprehensive Vulcan Training ​

For detailed user guidance on using Vulcan, please visit the official MITRE SAF Training site:

🎓 Vulcan User Guide - SAF Training

The SAF Training site provides comprehensive coverage of:

  • Getting Started with Vulcan
  • Creating and Managing Projects
  • Working with Components
  • Writing Security Controls (Rules)
  • Using the InSpec Integration
  • Collaboration Features
  • Importing and Exporting STIGs
  • Best Practices and Workflows

Quick Reference ​

Core Concepts ​

  • Projects: Top-level containers for organizing security documentation work
  • Components: Documents in progress — a STIG being authored for a system element, or an SRG being authored from core SRGs
  • Rules: Individual security controls with check/fix text and InSpec code
  • SRGs: High-level Security Requirements Guides from DISA — the basis STIG components implement, and themselves authorable in Vulcan (see the SRG Authoring Workflow)
  • STIGs: Specific Security Technical Implementation Guides for technologies

Common Tasks ​

TaskDescription
Create ProjectStart a new documentation effort
Import SRGLoad security requirements
Create ComponentAdd system elements
Author an SRGDerive a new SRG from core SRGs
Write ControlsDocument check/fix procedures
Add InSpecCreate automated validation
Export STIGGenerate XCCDF output

Additional Resources ​

For more detailed guidance on specific topics, please visit the SAF Training site.

Getting Help ​

Part of the MITRE Security Automation Framework (SAF)