Movatterモバイル変換


[0]ホーム

URL:


You are viewing this page in an unauthorized frame window.

This is a potential security issue, you are being redirected tohttps://csrc.nist.gov.

Official websites use .gov
A.gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
Alock (LockLocked padlock icon) orhttps:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Information Technology Laboratory
Computer Security Resource Center
CSRC Logo
CSRC Logo
    Publications

NIST IR 7275 Rev. 4

Specification for the Extensible Configuration Checklist Description Format (XCCDF) Version 1.2

   Documentation    Topics

Date Published:March 2012

Supersedes:IR 7275 Rev. 4 (09/30/2011)

Author(s)

David Waltermire (NIST),Charles Schmidt (MITRE),Karen Scarfone (Scarfone Cybersecurity),Neal Ziring (DoD)

Abstract

This report specifies the data model and Extensible Markup Language (XML) representation for the Extensible Configuration Checklist Description Format (XCCDF) Version 1.2. An XCCDF document is a structured collection of security configuration rules for some set of target systems. The XCCDF specification is designed to support information interchange, document generation, organizational and situational tailoring, automated compliance testing, and scoring. The specification also defines a data model and format for storing results of security guidance or checklist testing. The intent of XCCDF is to provide a uniform foundation for expression of security checklists and other configuration guidance, and thereby foster more widespread application of good security practices.

This report specifies the data model and Extensible Markup Language (XML) representation for the Extensible Configuration Checklist Description Format (XCCDF) Version 1.2. An XCCDF document is a structured collection of security configuration rules for some set of target systems. The XCCDF...See full abstract

This report specifies the data model and Extensible Markup Language (XML) representation for the Extensible Configuration Checklist Description Format (XCCDF) Version 1.2. An XCCDF document is a structured collection of security configuration rules for some set of target systems. The XCCDF specification is designed to support information interchange, document generation, organizational and situational tailoring, automated compliance testing, and scoring. The specification also defines a data model and format for storing results of security guidance or checklist testing. The intent of XCCDF is to provide a uniform foundation for expression of security checklists and other configuration guidance, and thereby foster more widespread application of good security practices.


Hide full abstract

Keywords

eXtensible Configuration Checklist Description Format;FISMA;security controls;vulnerabilities;XCCDF;benchmarks;checklists
Control Families

Audit and Accountability;Configuration Management;Maintenance

Documentation

Publication:
NISTIR 7275 Rev. 4 (pdf)

Supplemental Material:
NISTIR 7275 Rev. 4 (markup) (pdf)

Related NIST Publications:
SP 800-70 Rev. 4
SP 800-179 Rev. 1(Draft)
SP 800-179
SP 800-179(Draft)
IR 7188
IR 7275
IR 7275 Rev. 2
IR 7275 Rev. 3

Document History:
03/01/12:IR 7275 Rev. 4 (Final)

Topics

Security and Privacy

audit & accountability,maintenance,security automation


[8]ページ先頭

©2009-2025 Movatter.jp