What is the Security Content Automation Protocol?
The Security Content Automation Protocol (SCAP), pronounced “S-Cap,” combines a number of open standards that are used to enumerate software flaws and configuration issues related to security. They measure systems to find vulnerabilities and offer methods to score those findings to evaluate the possible impact. It is basically a method for using those open standards for automated vulnerability management, measurement, and policy compliance evaluation.
Related Questions
- How can agencies use Security Content Automation Protocol (SCAP) USGCB content to automate FISMA compliance of technical controls?
- Is NIST working exclusively with Microsoft on Security Content Automation Protocol (SCAP)?
- How do I know if a Tool is Security Content Automation Protocol (SCAP)-validated?