Extensible Configuration Checklist Description Format (XCCDF) Requirements
- XXCDF.V.1: The product's documentation (printed or electronic) must state that it uses XCCDF and explain the relevant details to the users of the product.
See Standards.
- XXCDF.V.3: The vendor shall provide instructions on how and where XCCDF schema errors will be displayed within the product output.
In Reports tab, search for the report called SCAP Data Validation Issues.
- XXCDF.V.4: The vendor shall provide instructions on how to import XCCDF files for execution and provide instructions on where the XCCDF Results can be located for visual inspection. Use of any XCCDF-capable check system(s) is permitted. The purpose of this requirement is to ensure that the product produces valid XCCDF Results and a matching pass/fail result for a given Rule.
Right-click on the computer in the view at the bottom of the policy that has completed an assessment, then click Resource Manager. Under the Data tab, navigate to the Event Classes accordion item, then to Data Classes > Arellia > Security Analysis > OVAL Analysis. Select the assessment in the list, then right-click and click View Raw Xccdf Results.
- XXCDF.V.5: The vendor shall provide instructions on how the user can select an XCCDF Profile when executing a valid XCCDF content file.
See Create a Security Analysis Policy.
- XXCDF.V.6: The vendor shall provide instructions on how the product generates human-readable prose from valid XCCDF documents.
See View profiles.
{"serverDuration": 187, "requestCorrelationId": "d405eb9e649a43e3ae34933fcb5f8e9d"}