This is a potential security issue, you are being redirected to https://csrc.nist.gov.
You have JavaScript disabled. This site requires JavaScript to be enabled for complete site functionality.
SCAP must continually evolve to meet the ever changing needs of the community. This need for continual evolution results in multiple versions of SCAP being available at any given time. The SCAP Release Cycle defines a process for managing change relating to SCAP and the NIST SCAP Validation Program by providing a consistent and repeatable revision work flow.
The following list represents the currently available versions of SCAP. The current effective version of SCAP is SCAP 1.3.
SCAP: Security Content Automation Protocol
Version: 2.0
Status: Initial Design
Specification: TBD
Design Considerations: Transition Whitepaper
SCAP: Security Content Automation Protocol
Version: 1.3
Status: Final
Specification: NIST SP 800-126 Rev. 3
Annex: NIST SP 800-126 Rev. 3 Annex
SCAP: Security Content Automation Protocol
Version: 1.2
Status: Final
Specification: NIST SP 800-126 Rev. 2
SCAP: Security Content Automation Protocol
Version: 1.1
Status: Final
Specification: NIST SP 800-126 Rev. 1
SCAP: Security Content Automation Protocol
Version: 1.0
Status: Final
Specification: NIST SP 800-126
SCAP Content Validation Tool
Location: Content Validation Tool for SCAP 1.0 and 1.1
Location: Content Validation Tool for SCAP 1.0, 1.1, and 1.2
Enhanced SCAP Editor (eSCAPe)
Site: eSCAPe Project Site
Recommendation Tracker (RT)
SCAP Inquiries
[email protected]
Security and Privacy: configuration management, patch management, security automation, security measurement, vulnerability management
Release Cycle SCAP Content SCAP Releases SCAP 1.3 SCAP 1.2 SCAP 1.1 SCAP 1.0 SCAP Specifications Asset Identification Asset Reporting Format (ARF) Common Configuration Enumeration (CCE) Common Platform Enumeration (CPE) Applicability Language Dictionary Name Matching Naming Open Vulnerability Assessment Language (OVAL) Open Checklist Interactive Language (OCIL) Trust Model for Security Automation Data (TMSAD) Extensible Configuration Checklist Description Format (XCCDF) Software Identification (SWID) SCAP Community
SCAP Inquiries
[email protected]
Security and Privacy: configuration management, patch management, security automation, security measurement, vulnerability management