SCAP 1.2

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

SCAP 1.2

Waltermire, David A.

Community Members,

 

We are working to complete the functional changes to SCAP for revision 1.2.  The list of improvements to SCAP is provided at the following link http://scap.nist.gov/revision/1.2/.  NIST will be discussing these and other improvements to SCAP at the upcoming Security Automation Developer Days in Bedford, Mass. on June 14th-17th.  The SCAP session will be on Wednesday, June 15th from 8am to noon and will provide the community with an opportunity to comment on the proposed improvements and raise issues before the changes are submitted as a revision to SP 800-126.

 

Some of the improvements in SCAP 1.2 include:

·         The definition of an SCAP source datastream format

·         The definition of an SCAP result datastream format using the Asset Reporting Format (ARF)

·         Integration of Asset Identification information within an SCAP result datastream

·         Applying XML Digital Signatures to source and result datastreams

·         Use of the CPE 2.3 Naming, Matching, Language and Dictionary specifications

·         Use of OVAL 5.10

·         Addition of the Common Configuration Scoring System (CCSS) 1.0

·         Use of XCCDF 1.1.5

 

We welcome feedback in advance of the discussion.  For more information on the upcomming Security Automation Developer Days please visit: http://scap.nist.gov/events/.

 

Sincerely,

 

David Waltermire

SCAP Architect

National Institute of Standards and Technology

(301) 975-3390

[hidden email]

Reply | Threaded
Open this post in threaded view
|

Re: SCAP 1.2

Brant Cheikes

Dave – Any idea when the Dictionary and Language IRs will be publicly posted?

 

Brant A. Cheikes
The MITRE Corporation
202 Burlington Road, M/S K302
Bedford, MA 01730-1420
Tel. 781-271-7505; Cell. 617-694-8180; Fax. 781-271-2352

 

From: Waltermire, David A. [mailto:[hidden email]]
Sent: Tuesday, May 31, 2011 5:47 PM
To: cpe-discussion-list CPE Community Forum
Subject: [CPE-DISCUSSION-LIST] SCAP 1.2

 

Community Members,

 

We are working to complete the functional changes to SCAP for revision 1.2.  The list of improvements to SCAP is provided at the following link http://scap.nist.gov/revision/1.2/.  NIST will be discussing these and other improvements to SCAP at the upcoming Security Automation Developer Days in Bedford, Mass. on June 14th-17th.  The SCAP session will be on Wednesday, June 15th from 8am to noon and will provide the community with an opportunity to comment on the proposed improvements and raise issues before the changes are submitted as a revision to SP 800-126.

 

Some of the improvements in SCAP 1.2 include:

·         The definition of an SCAP source datastream format

·         The definition of an SCAP result datastream format using the Asset Reporting Format (ARF)

·         Integration of Asset Identification information within an SCAP result datastream

·         Applying XML Digital Signatures to source and result datastreams

·         Use of the CPE 2.3 Naming, Matching, Language and Dictionary specifications

·         Use of OVAL 5.10

·         Addition of the Common Configuration Scoring System (CCSS) 1.0

·         Use of XCCDF 1.1.5

 

We welcome feedback in advance of the discussion.  For more information on the upcomming Security Automation Developer Days please visit: http://scap.nist.gov/events/.

 

Sincerely,

 

David Waltermire

SCAP Architect

National Institute of Standards and Technology

(301) 975-3390

[hidden email]


smime.p7s (4K) Download Attachment