
characteristics. Using CVSS weighted scores can help an organization determine and prioritize
responses to detected vulnerabilities.
Policy Auditor supports all 4 standard SCAP scoring models. By default, it uses a Flat Unweighted
scoring model normalized to 100. The scoring can be changed for comparison purposes.
Statement of XCCDF Implementation
McAfee Policy Auditor 5.0 provides complete implementation of version 1.4.1 of the eXtensible
Configuration Checklist Description Format (XCCDF).
XCCDF supports the exchange of information, results document generation, tailoring, automated
compliance testing, compliance scoring, and provides a data model and format for storing results
of benchmark compliance testing. The goal of XCCDF is to provide a uniform standard for the
expression of benchmarks and other configuration guidance to encourage good security practices.
Policy Auditor uses benchmarks from McAfee or third-party sources to construct audits. Users
can select the benchmark profile, if any, to use for the audit. After a system is audited, the
system agent returns the audit results to Policy Auditor, which analyzes and reports on the
configuration and vulnerability data. The user specifies how long audit data is retained so that
they or auditors can review any changes in the state of a system over time.
Statement of OVAL Implementation
McAfee Policy Auditor 5.0 fully implements and supports the Open Vulnerability and Assessment
Language (OVAL).
OVAL is an international standard that promotes openly-available security content. It is the
common language for security experts to check for the presence of vulnerabilities and
configuration issues on computer systems. OVAL provides a structured model for network and
system administrators to detect vulnerabilities and configuration issues on managed systems.
When a system is audited, the McAfee agent processes the OVAL content according to the
information in the XCCDF benchmarks contained in the audit. The OVAL content captures the
state of the system at the particular point in time that the audit is run. The results are returned
to Policy Auditor for analysis and reporting. The user specifies how long audit data is to be
retained so that they or auditors can review any changes in the state of a system over time.
Complying with SCAP
Statement of XCCDF Implementation
21McAfee Policy Auditor 5.0 Product Guide
Comentarios a estos manuales