Will scans based on Security Content Automation Protocol (SCAP) checklists produce results with 100% of all checks passing?
At present, there are no known discrepancies in the existing FDCC SCAP content. When errors are discovered NIST will actively work to improve the accuracy of the tests as represented in the SCAP data stream, and updated content will be released periodically. NIST uses JTrac to document and monitor the status of known flaws in the FDCC content..
Related Questions
- How can agencies use Security Content Automation Protocol (SCAP) USGCB content to automate FISMA compliance of technical controls?
- Will scans based on Security Content Automation Protocol (SCAP) checklists produce results with 100% of all checks passing?
- Is NIST working exclusively with Microsoft on Security Content Automation Protocol (SCAP)?