Subscribe to the Free Print Edition!
Celebrating 25 Years

NIST to release SCAP FDCC scanner list

By Joab Jackson

On Feb. 1 the National Institute of Standards and Technology will release a list of validated scanners that check for Federal Desktop Core Configuration compliance. The scanners all use the Security Content Automation Protocol (SCAP) to automatically scan desktop computers and return the results, said Peter Mell, NIST’s SCAP validation program manager, at an FDCC workshop held yesterday in Gaithersburg, Md.

Last July, the Office of Management and Budget issued a clarification memo stating that agencies must monitor their desktop computers with SCAP tools "as they become available."

The scanners will ensure that the computers' configurations stay within the guidelines set by the FDDC, a group of OMB-mandated security-sensitive configuration settings developed by the NIST and the National Security Agency.

On Feb. 1, agencies will have to submit to OMB a report of all the desktop computers running the Microsoft Windows XP and Windows Vista operating systems, as well as the number of those that are FDCC-compliant, according to OMB FDCC lead Wendy Liberante, who gave an impromptu clarificationat the event. On March 31, agencies must submit a report to NIST of the status of the Windows desktop computers

As of January, however, no SCAP products have been validated by NIST, which just set up the validation program last summer.

SCAP is a framework "for automating and standardizing vulnerability management measurement and policy compliance," Mell said. It predates FDCC and can be used for checking computers to see if they meet other mandates, such as the Federal Information Security Management Act.

Although the SCAP validation process ranges across 12 different functions, this upcoming set of validated tools will be scanners, Mell noted. He did not speculate how many products would be validated, though the final testing is being done on about five.

"NIST is not recommending these products. We are not mandating these products. What we are doing is validating that the products correctly implement SCAP," Mell said. The validation will look at whether all the settings on the FDDC are checked, as well as if they are checked in the procedure that Microsoft and the government recommends.



GCN Popup