Visible IT: SCAP, XCCDF, and Compliance Orchestration

 Posted by calvin on April 7, 2008 at 2:47 pm  Uncategorized  Add comments  Tagged with:
Apr 072008
 

Howdy,

I just posted the latest entry in my Visible IT blog, titled: “SCAP, XCCDF, and Compliance Orchestration.” In this entry I point out some of the limitations of the XCCDF spec that are relevant to compliance orchestration.

Here’s the teaser:

So there’s this open question about how to know where a particular XCCDF file applies. The XCCDF specification simply says in the abstract:

This document specifies the data model and Extensible Markup Language (XML) representation for the Extensible Configuration Checklist Description Format (XCCDF) Version 1.1.4. An XCCDF document is a structured collection of security configuration rules for some set of target systems.

As far as I can tell, and I’d welcome being corrected on this front, XCCDF can’t express where it’s configuration rules should be applied other than the relevant operating system “platform”.

As always, I welcome your comments either here or at the original entry at the Visible IT Blog.

 Leave a Reply

(required)

(required)

* Copy this password:

* Type or paste password here:

861 Spam Comments Blocked so far by Spam Free Wordpress

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

   
© 2011 Stuck In Traffic Suffusion theme by Sayontan Sinha