Publications
July 19, 2023: URLs for CSRC publication details pages have changed. Legacy URLs should automatically redirect to the new URLs. However, links to the actual publications have NOT changed (e.g., DOIs and PDFs on nvlpubs.nist.gov). Please send inquiries to
csrc-inquiry@nist.gov.
Withdrawn on November 27, 2018.
The Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.0
Documentation
Topics
Date Published: November 2009
Planning Note (11/27/2018):
SCAP v1.0 is no longer supported. For additional details, see information about SCAP Releases and the SCAP Release Cycle.
Author(s)
Stephen Quinn (NIST), David Waltermire (NIST), Christopher Johnson (NIST), Karen Scarfone (NIST), John Banghart (NIST)
This document defines the technical specification for Version 1.0 of the Security Content Automation Protocol (SCAP). SCAP consists of a suite of specifications for standardizing the format and nomenclature by which security software communicates information about software flaws and security configurations. This document describes the basics of the SCAP component specifications and their interrelationships, the characteristics of SCAP content, as well as SCAP requirements not defined in the individual SCAP component specifications. This guide provides recommendations on how to use SCAP to achieve security automation for organizations seeking to implement SCAP.
This document defines the technical specification for Version 1.0 of the Security Content Automation Protocol (SCAP). SCAP consists of a suite of specifications for standardizing the format and nomenclature by which security software communicates information about software flaws and security...
See full abstract
This document defines the technical specification for Version 1.0 of the Security Content Automation Protocol (SCAP). SCAP consists of a suite of specifications for standardizing the format and nomenclature by which security software communicates information about software flaws and security configurations. This document describes the basics of the SCAP component specifications and their interrelationships, the characteristics of SCAP content, as well as SCAP requirements not defined in the individual SCAP component specifications. This guide provides recommendations on how to use SCAP to achieve security automation for organizations seeking to implement SCAP.
Hide full abstract
Keywords
Security automation; security configuration; Security Content Automation Protocol; vulnerabilities; SCAP; security content automation
Control Families
Audit and Accountability; Assessment, Authorization and Monitoring; Configuration Management; Maintenance; Risk Assessment; System and Services Acquisition; System and Communications Protection