Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 7275 Rev. 4

Specification for the Extensible Configuration Checklist Description Format (XCCDF) Version 1.2

Date Published: September 2011


David Waltermire (NIST), Charles Schmidt (MITRE), Karen Scarfone (Scarfone Cybersecurity), Neal Ziring (DoD)



benchmarks; checklists; eXtensible Configuration Checklist Description Format; FISMA; security controls; vulnerabilities; XCCDF
Control Families

Audit and Accountability; Configuration Management; Maintenance


Download URL

Supplemental Material:
None available

Document History:
09/30/11: IR 7275 Rev. 4 (Final)