security content automation protocol (SCAP)
Term · Cybersecurity · MLC-T-CYB-003792
1. A suite of specifications that standardize the format and nomenclature by which software flaw and security configuration information is communicated, both to machines and humans.
Note: There are six individual specifications incorporated into SCAP: CVE (common vulnerabilities and exposures); CCE (common configuration enumeration); CPE (common platform enumeration); CVSS (common vulnerability scoring system); OVAL (open vulnerability assessment language); and XCCDF (eXtensible configuration checklist description format).
2. A suite of specifications that standardize the format and nomenclature by which software flaw and security configuration information is communicated, both to machines and humans.
3. A protocol currently consisting of a suite of seven specifications that standardize the format and nomenclature by which security software communicates information about software flaws and security configurations.
| Identifier | MLC-T-CYB-003792 |
|---|---|
| Field | Cybersecurity |
| Abbreviation | SCAP |
| References | CNSSI 4009-2022 from NIST SP 800-126 Rev. 3 (adapted); NIST SP 800-126 Rev. 2; NIST SP 800-126 Rev. 3; NIST SP 800-128; NIST SP 800-128; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-003792",
"term": "security content automation protocol (SCAP)",
"field": "Cybersecurity",
"definition": "1. A suite of specifications that standardize the format and nomenclature by which software flaw and security configuration information is communicated, both to machines and humans.\nNote: There are six individual specifications incorporated into SCAP: CVE (common vulnerabilities and exposures); CCE (common configuration enumeration); CPE (common platform enumeration); CVSS (common vulnerability scoring system); OVAL (open vulnerability assessment language); and XCCDF (eXtensible configuration checklist description format).\n\n2. A suite of specifications that standardize the format and nomenclature by which software flaw and security configuration information is communicated, both to machines and humans.\n\n3. A protocol currently consisting of a suite of seven specifications that standardize the format and nomenclature by which security software communicates information about software flaws and security configurations.",
"abbreviation": "SCAP",
"references": [
"CNSSI 4009-2022 from NIST SP 800-126 Rev. 3 (adapted)",
"NIST SP 800-126 Rev. 2; NIST SP 800-126 Rev. 3",
"NIST SP 800-128; NIST SP 800-128",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/security-content-automation-protocol-scap/"
}
Record 3,792 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.