What is Security Content Automation Protocol (SCAP)?
NIST established a suite of interoperable and automatable security specifications known as the Security Content Automation Protocol (SCAP). By virtue of using XML-based standards, SCAP is simultaneously machine and human readable. The FDCC SCAP content is hosted on the National Checklist Program website; the National Vulnerability Database is being expanded to host the SCAP component standards. More information about SCAP may be found at http://scap.nist.gov/.
Related Questions
- How can agencies use Security Content Automation Protocol (SCAP) USGCB content to automate FISMA compliance of technical controls?
- Is NIST working exclusively with Microsoft on Security Content Automation Protocol (SCAP)?
- How do I know if a Tool is Security Content Automation Protocol (SCAP)-validated?