Skip to content

SCAP

What is SCAP?

Security Content Automation Protocol, a suite of specifications for standardizing the format and nomenclature of security configuration and vulnerability information.

Information Security

Each of these is named in at least one of the same controls as scap. The number is how many controls name both.

What the standards actually require on scap

Requirements naming scap across 4 standards, quoted from the control text.

Use a SCAP-validated tool (e.g. SCAP Compliance Checker / Evaluate-STIG) to automatically assess systems against the applicable STIG benchmarks where automation is available.

STIG-ASSESS-SCAP · SCAP automated benchmark scanning
NIST SP 800-1283 controls

Establish continuous monitoring of configuration items to detect deviations from approved baselines using automated scanning, agent-based reporting, and SCAP content aligned with the organization's monitoring strategy.

SecCM-MONITOR-1 · Continuous Monitoring of Configurations
CIS Controls v82 controls

Perform automated vulnerability scans of externally-exposed enterprise assets using a SCAP-compliant vulnerability scanning tool. Perform scans on a monthly, or more frequent, basis.

CIS-7.6 · Perform Automated Vulnerability Scans of Externally-Exposed Enterprise Assets
NIST SP 800-1372 controls

Monitor vulnerability per Section 4.1 continuously: scanning + assessment + risk prioritisation + remediation tracking aligned with NIST SP 800-40 + NIST SP 800-126 SCAP + Tenable + Qualys + Rapid7 + open-source OpenVAS.

NISTSP137-5 · Vulnerability + Patch + Configuration Status Monitoring

Questions people ask about scap

What is SCAP?
Security Content Automation Protocol, a suite of specifications for standardizing the format and nomenclature of security configuration and vulnerability information.
Why is SCAP important for compliance?
SCAP is a key concept in Information Security. Understanding scap helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address SCAP?
SCAP appears in the requirement text of DISA Security Technical Implementation Guides (STIGs), NIST SP 800-128, CIS Controls v8, NIST SP 800-137. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about SCAP?
Explore our compliance framework pages to see how scap applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how SCAP applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.