• Skip to main content
  • Skip to primary sidebar

ConvoCourses

Cyber Security Compliance and IT Jobs

  • Cyber Security Training
  • about me.
  • Information Assurance Jobs

SCAP Compliance Checker SCC)

March 13, 2014 by Bruce Brown 3 Comments

SCAP Compliance Checker SCC Tool 3.1.2

 

SCAP Compliance Checker SCC
SCAP Compliance Checker (SCC)

SPAWAR Systems Center Atlantic has released an updated version to the SCAP Compliance Checker SCC Tool.  The updated features include recent DISA STIG content for both Windows and Red Hat systems and NIST USGCB patch content.  In addition, several defects have been resolved in the 3.1.2 release.

SCAP Content
+ AIX
+ Dot Net Framework
+ Google Chrome
+ HP-UX
+ Internet Explorer Benchmarks
+ Red Hat
+ Solaris
+ Windows 8 Benchmarks
+ Windows 2008 R2 Benchmarks
+ Windows 2008 Benchmarks
+ Windows 2003 Benchmarks
+ Windows 7 Benchmarks
+ XP Benchmarks
+ Vista Benchmarks
+ Audit
+ SCAP Tools

The SCAP Tools are located at http://iase.disa.mil/stigs/scap/index.html#scc

 Security Content Automation Protocol (SCAP) Windows Benchmarks

DISA Field Security Operations (FSO) is releasing updated automated compliance benchmarks for Windows Operating Systems outside of the normal quarterly release schedule.  The latest benchmarks will correct a problem with importing the content into the HBSS Policy Auditor tool. The Benchmarks are located at http://iase.disa.mil/stigs/scap/index.html

 

More on the feature of SPAWAR SCAP Compliance Checker SCC Tool:

Primary Features:

  • No per seat license costs for Federal government/contractor computers
  • Performs compliance scanning using SCAP content
  • Performs vulnerability scanning using OVAL content
  • Performs manual interview checks using OCIL content
  • Creates XCCDF XML results
  • Creates OVAL XML results
  • Creates ARF XML results
  • Creates Cyberscope Autofeed XML results
  • Creates HTML and text based single computer reports
  • Creates HTML and spreadsheet based multi-computer summary reports
  • Allows for installation of custom SCAP and OVAL content
  • Allows for automatic downloading of updated patch content from Internet/Intranet
  • Allows for organizational deviations
  • Allows for organizationally defined compliance thresholds
  • Has graphical and command line interfaces
  • Native executables per platform (no runtime requirements such as Java

Filed Under: diarmf - implement, RDIT, Risk Management For DoD IT Tagged With: diarmf - implement, rmf, rmf assessment, rmf implementation, SCAP Compliance Checker, scap compliance tool, scap tool, scc

Reader Interactions

Comments

  1. Bill says

    June 20, 2014 at 1:38 pm

    When will your tool be SCAP 1.2 compliant? Since 1.0 tools expired on Dec 31, 2013 under NIST validation it leaves a lean field of choices for validated scanners.

    Log in to Reply
    • Rob Elamb says

      June 20, 2014 at 5:06 pm

      Hey Bill,
      We don’t own SCC Tool. Its SPARWAR’s baby: http://www.public.navy.mil/spawar/Atlantic/ProductsServices/Pages/SCAP.aspx

      I think you can get an updated (SCAP 1.2 compliant) copy on iase.disa.mil under SCAP TOOLS (check the drop down.. i think that is all 2014 stuff) http://iase.disa.mil/stigs/scap/index.html
      I cannot access those tools

      more:
      http://scap.nist.gov/validation/

      Approved Validation Programs According to NIST (all use SCAP 1.2):
      https://nvd.nist.gov/SCAP-Validated-Tools/

      slides on SCAP 1.2
      http://scap.nist.gov/events/2011/itsac/presentations/day2/Scarfone%20-%20SCAP%201.2%20Overview.pdf

      Log in to Reply

Trackbacks

  1. horloge says:
    April 8, 2020 at 11:10 pm

    horloge

    SCAP Compliance Checker SCC

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Social connect:

Primary Sidebar

search


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book


This book is an overview of how the NIST SP 800-37 risk management framework works from the perspective of an information system security officer (ISSO).

also available on Amazon!

View Book

NIST RMF 800-37 templates
Free 800-37 templates

The NIST 800 Template download contains a .doc file template and xls templates for POAMs, Federal, State, cloud based and a legacy template as well as resources where you can find more on NIST 800-37 documents for your use.

View Book

Learn to Make 6 Figures in CyberSecurity

RMF ISSO Foundations Training
RMF ISSO Foundations Training

RMF ISSO Foundations

I was an Information System Security Officer (ISSO) doing Risk Management Framework (NIST SP 800-37) for over a decade. I am a Cybersecurity veteran and I can explain (in plain English) what you DO in the Risk Management Framework process as an ISSO.

View Course

NIST SP 800-37 Presentation
NIST SP 800-37 Presentation

View Course

login

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Posts

  • Convocourses Podcast: Plan of Action and Milestone
  • Start with These IT Certifications (Part 1)
  • How to Tailor Security Controls in NIST 800
  • #cybersecurityjobs are recession proof
  • What IT Certifications for Information Security (part 2) (8140)

Meta

  • Register
  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Comments

  • http://Www.Finance.Ipt.Pw/ on SRG/STIG Applicability Guide and Collection Tool Update
  • Elsa7 on ConvoCourses podcast: Cyber Security day to day activity
  • Tony on STIG Update – DISA has released the Microsoft SQL Server 2016 STIG Version 1
  • horloge on SCAP Compliance Checker SCC)
  • 218 Information assurance Success Criteria – ITSECURITYSURVIVAL.COM on Information Assurance Vulnerability Alert

Tags

8140 8570 ArcSight c&a CISSP convocourses cyber cybersecurity cyber security DIACAP DIARMF diarmf - implement disa DISA STIG dodd 8140 dodd 8140 cyberspace workforce IA implement implementation info assurance information assurance information security ISSO IT it jobs it jobs in usa job jobs Linux mcafee network nist nist risk management framework nist risk management framework 800-37 podcast risk risk assessment risk management risk management framework rmf security STIG stigs unix windows


This is a breakdown of each of the NIST 800-53 security control families and how they relate to each step in the NIST 800-37 risk management framework process.

also available on Amazon!

View Book

Copyright © 2023 · Author Pro on Genesis Framework · WordPress · Log in