Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

Extensible Configuration Checklist Description Format (XCCDF) Requirements

  • The product's documentation (printed or electronic) must state that it uses XCCDF and explain the relevant details to the users of the product.
  • The vendor shall provide instructions on how and where XCCDF schema errors will be displayed within the product output.
  • The vendor shall provide instructions on how to import XCCDF files for execution and provide instructions on where the XCCDF Results can be located for visual inspection. Use of any XCCDF-capable check system(s) is permitted. The purpose of this requirement is to ensure that the product produces valid XCCDF Results and a matching pass/fail result for a given Rule.
  • The vendor shall provide instructions on how the user can select an XCCDF Profile when executing a valid XCCDF content file.
  • The vendor shall provide instructions on how the product generates human-readable prose from valid XCCDF documents.

XCCDF + OVAL Requirements

  • (Input) The vendor shall provide documentation and instruction on how to import an SCAP-expressed data stream for the target platform, including XCCDF and OVAL content, into the product.
  • (Output) The vendor shall provide instruction on where the corresponding XCCDF and OVAL results files can be located for inspection.

XCCDF + CCE Requirements

  • The vendor shall provide instructions on where the XCCDF Rules and their associated CCE IDs can be visually inspected within the product output.

XCCDF + OVAL + CPE Requirements

  • The vendor shall provide instructions on how the product indicates the validity of the imported SCAP-expressed data stream to a target platform. Instructions should also describe how the imported data stream is indicated to not be valid for a target platform. This requirement is testing the use of the OVAL check associated with a CPE name via the CPE dictionary to determine applicability of the data stream.
  • No labels