
Complying with SCAP
Policy Auditor uses the Security Content Automation Protocol (SCAP) to perform automated
audits, including policy compliance evaluations such as FISMA.
Contents
Statement of FDCC Compliance
Statement of SCAP Implementation
Statement of CVE Implementation
Statement of CCE Implementation
Statement of CPE Implementation
Statement of CVSS Implementation
Statement of XCCDF Implementation
Statement of OVAL Implementation
Statement of FDCC Compliance
McAfee asserts that Policy Auditor 5.0 does not alter or conflict with the Federal Desktop Core
Configuration (FDCC) settings on Microsoft Windows XP and Vista systems.
Statement of SCAP Implementation
The Security Content Automation Protocol (SCAP) is a collection of six open standards developed
jointly by various government organizations and the private sector. Security content conforming
to the SCAP standard can be used by any product that supports the standard and the results
can be shared between these products. This openness and standardization allows regulatory
authorities and security administrators to construct more definitive security guidance and to
reliably and repeatedly compare results.
McAfee Policy Auditor 5.0 was designed exclusively around SCAP. The product provides complete
implementation of and support for all six SCAP standards. It uses the eXtensible Configuration
Checklist Description Format (XCCDF) and Open Vulnerability and Assessment Language (OVAL)
assessment protocols to determine what items to check on a system and how to check them.
It uses the Common Vulnerabilities and Exposures (CVE), Common Configuration Enumeration
(CCE), Common Platform Enumeration (CPE), and Common Vulnerability Scoring System (CVSS)
reference protocols to ensure all rules are accurately and appropriately processed and the results
properly shown in reports and export files.
19McAfee Policy Auditor 5.0 Product Guide
Comentarios a estos manuales