How can agencies use Security Content Automation Protocol (SCAP) USGCB content to automate FISMA compliance of technical controls?
The XCCDF-based SCAP content contains Common Configuration Enumeration (CCE) identifiers. The CCEs are mapped to the 800-53 controls and posted to the National Vulnerability Database (NVD) data feed located at http://nvd.nist.gov/cce.cfm. CCE to 800-53 mappings can also be obtained on a per checklist basis for Tier III checklists at checklists.nist.gov. This data can be used to demonstrate NIST Special Publication (SP) 800-53 assessment and compliance evidence.
Related Questions
- How can agencies use Security Content Automation Protocol (SCAP) FDCC content to automate FISMA compliance of technical controls?
- How can agencies use SCAP FDCC content to automate FISMA compliance of technical controls?
- Is NIST working exclusively with Microsoft on Security Content Automation Protocol (SCAP)?