SCAP
What is SCAP?
Security Content Automation Protocol, a suite of specifications for standardizing the format and nomenclature of security configuration and vulnerability information.
Terms that appear alongside scap
Each of these is named in at least one of the same controls as scap. The number is how many controls name both.
- vulnerability 4 shared controls
- configuration management 3 shared controls
- compliance 2 shared controls
- vulnerability scanning 2 shared controls
Frameworks that govern scap
What the standards actually require on scap
Requirements naming scap across 4 standards, quoted from the control text.
Use a SCAP-validated tool (e.g. SCAP Compliance Checker / Evaluate-STIG) to automatically assess systems against the applicable STIG benchmarks where automation is available.
STIG-ASSESS-SCAP · SCAP automated benchmark scanning →Establish continuous monitoring of configuration items to detect deviations from approved baselines using automated scanning, agent-based reporting, and SCAP content aligned with the organization's monitoring strategy.
SecCM-MONITOR-1 · Continuous Monitoring of Configurations →Perform automated vulnerability scans of externally-exposed enterprise assets using a SCAP-compliant vulnerability scanning tool. Perform scans on a monthly, or more frequent, basis.
CIS-7.6 · Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets →Monitor vulnerability per Section 4.1 continuously: scanning + assessment + risk prioritisation + remediation tracking aligned with NIST SP 800-40 + NIST SP 800-126 SCAP + Tenable + Qualys + Rapid7 + open-source OpenVAS.
NISTSP137-5 · Vulnerability + Patch + Configuration Status Monitoring →Questions people ask about scap
What is SCAP?
Why is SCAP important for compliance?
Which compliance frameworks address SCAP?
Where can I learn more about SCAP?
See how SCAP applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.