Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable and SCAP 1.1

Tenable recently announced that SecurityCenter 4 has been validated by NIST as conforming to the Security Content Automation Protocol (SCAP) version 1.0. The specifications for the latest version of SCAP, 1.1, have recently been released through NIST’s third public draft of Special Publication 800-126 Rev. 1, and the revision is currently open until January 28 for public comment on implementation, content or functional issues within the specification. Tenable is already focusing on the changes included in SCAP 1.1 and will incorporate them into both SecurityCenter and Tenable’s xTool, which is used to parse XCCDF SCAP content available from NIST and also convert SecurityCenter reports into the FDCC reporting format.

SCAP 1.1 plans to add the Open Checklist Interactive Language (OCIL) to the specification, as well as support the upgrade of the Open Vulnerability and Assessment Language (OVAL) to version 5.8. Other components of SCAP include the eXtensible Configuration Checklist Description Format (XCCDF), Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), Common Platform Enumeration (CPE) and Common Configuration Enumeration (CCE). CVE IDs and CVSS scores are included in Nessus and PVS plugins, which allows for easier identification and risk assessment of vulnerabilities found during monitoring and compliance efforts.

As a finalized version of SCAP 1.1 approaches, government agencies and businesses in the private sector are looking to solidify their security posture and compliance with numerous standards (such as FDCC and USGCB for federal systems, and PCI DSS and HITRUST for the financial and medical sectors, respectively). According to SP 800-126, “SCAP is achieving widespread adoption by major software and hardware manufacturers and has become a significant component of large information security management and governance programs”. More information about how SecurityCenter 4 and the xTool can assist with these goals can be found on NIST’s product validation page for Tenable or by contacting Tenable’s sales team.

Subscribe to the Tenable Blog

Subscribe
Try for Free Buy Now

Try Tenable.io Vulnerability Management

FREE FOR 60 DAYS

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Sign up now and run your first scan within 60 seconds.

Buy Tenable.io Vulnerability Management

Enjoy full access to a modern, cloud-based vulnerability management platform that enables you to see and track all of your assets with unmatched accuracy. Purchase your annual subscription today.

65 assets

Try Nessus Professional Free

FREE FOR 7 DAYS

Nessus® is the most comprehensive vulnerability scanner on the market today. Nessus Professional will help automate the vulnerability scanning process, save time in your compliance cycles and allow you to engage your IT team.