Computer Security Resource Center

Computer Security Resource Center

Computer Security
Resource Center

NISTIR 7511 Rev. 5 (DRAFT)

Security Content Automation Protocol (SCAP) Version 1.3 Validation Program Test Requirements

Date Published: January 2018
Comments Due: February 19, 2018 (public comment period is CLOSED)
Email Questions to: ir7511comments@nist.gov

Withdrawn: April 20, 2018

Author(s)

Melanie Cook (NIST), Stephen Quinn (NIST), David Waltermire (NIST), Dragos Prisaca (G2)

Announcement

The NIST Security Content Automation Protocol (SCAP) Validation Program tests the ability of products and modules to use the features and functionality available through SCAP and its components.  SCAP 1.3 consists of a suite of specifications for standardizing the format and nomenclature by which security software communicates information about software flaws and security configurations. The standardization of security information facilitates interoperability and enables predictable results among disparate SCAP enabled security software. The SCAP Validation Program provides vendors an opportunity to have independent verification that security software correctly processes SCAP expressed security information and provides standardized output. NISTIR 7511 Revision 5 describes the test requirements for SCAP version 1.3.

Abstract

Keywords

SCAP derived test requirements (DTR); SCAP validated tools; SCAP validated products; SCAP validated modules; Security Content Automation Protocol (SCAP); SCAP validation
Control Families

Security Assessment and Authorization; System and Services Acquisition;

Documentation

Publication:
Draft NISTIR 7511 Rev. 5

Supplemental Material:
None available

Related NIST Publications:
SP 800-126 Rev. 3
SP 800-126A
SP 800-126 Rev. 3 (DRAFT)
SP 800-126A (DRAFT)

Document History:
Draft NISTIR 7511 Rev. 5 (1/16/18)
NISTIR 7511 Rev. 5 (4/20/18)

Topics

Security and Privacy
acquisition; security automation; testing & validation

Laws and Regulations
OMB Circular A-130