2011
DOI: 10.6028/nist.ir.7275r4
|View full text |Cite
|
Sign up to set email alerts
|

Specification for the extensible configuration checklist description format (XCCDF) version 1.2

Abstract: (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation's measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology. ITL's responsibilities include the development of technical, physical, administrative, and management standards and guidelines for… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
12
0

Year Published

2013
2013
2020
2020

Publication Types

Select...
3
3
2

Relationship

0
8

Authors

Journals

citations
Cited by 14 publications
(12 citation statements)
references
References 0 publications
0
12
0
Order By: Relevance
“…In this format, checklist items can be associated with checks, such as OVAL definitions, and preconditions, such as preliminary checks that are represented by the <xccdf:require> element. A common example for an require element highlighted in the XCCDF specification [9] is "<xccdf:requires idref="xccdf_org.example_rule_passwd-exists"/>". This kind of preliminary requirement is found in checklist items to evaluate certain file system privileges.…”
Section: Related Workmentioning
confidence: 99%
See 2 more Smart Citations
“…In this format, checklist items can be associated with checks, such as OVAL definitions, and preconditions, such as preliminary checks that are represented by the <xccdf:require> element. A common example for an require element highlighted in the XCCDF specification [9] is "<xccdf:requires idref="xccdf_org.example_rule_passwd-exists"/>". This kind of preliminary requirement is found in checklist items to evaluate certain file system privileges.…”
Section: Related Workmentioning
confidence: 99%
“…SCAP also employs the eXtensible Configuration Checklist Description Format (XCCDF [9]). In this format, checklist items can be associated with checks, such as OVAL definitions, and preconditions, such as preliminary checks that are represented by the <xccdf:require> element.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…The Extensible Configuration Checklist Description Format (XCCDF) [9], a SCAP specification, specifies a language to describe security checklists and collect compliance results of targeted systems. SCAP also provides a set of measurement and scoring systems to provide universal scores of known vulnerabilities.…”
Section: Introductionmentioning
confidence: 99%
“…While patterns of events [67] (including event counters, conjunction, disjunction and sequences of events) could be readily reuse or extended to reflect the complexity of events of interest to the cloud stakeholders, existing event specification languages such as ETALIS [69], TESLA [70] and YALES [71] are amongst the most expressive languages that can be adopted for the specification of event patterns pertinent to STMA. Furthermore, given most STMA related events would be related to security, candidate format for representing atomic events of interest may include the Extensible Configuration Checklist Description Format -XCCDF [72] and the Intrusion Detection Message Exchange Format-IDMEF (http:// www.rfc-base.org/txt/rfc-4765.txt), both being an XML based format. While IDMEF is intended to be a standard data format that automated intrusion detection systems can use to report alerts about events that they deem suspicious, XCCDF is used to specify security checklists and benchmarks amongst others.…”
Section: Engineering Cloud Services With Stma In Mindmentioning
confidence: 99%