SCAP
SCAP
( = Security Content Automation Protocol,
"turvasisu automaatikaprotokoll")
olemus
metoodika (NIST, 2006), mis võimaldab infoturbe haldust kvantiteerida ja automatiseerida; aluseks on turvasisu etalonmääratlused, nendega võrdlemise vahendid (SCAP skannerid), toetavad andmebaasid (NVD, CVE); rakendab mitmeid avatud standardeid
= a suite of specifications that provide a standardized approach to security automation, enabling organizations to consistently manage security configurations, vulnerabilities, and compliance; it encompasses a collection of open standards
NIST SP 800-126 Rev. 3:
a suite of specifications that standardize the format and nomenclature by which software flaw and security configuration information is communicated, both to machines and humans
ülevaateid
https://www.pcmag.com/encyclopedia/term/scap
https://en.wikipedia.org/wiki/Security_Content_Automation_Protocol
http://energy.gov/sites/prod/files/cioprod/documents/Technical_Introduction_to_SCAP_-_Charles_Schmidt.pdf
https://infosec-jobs.com/insights/scap-explained/
https://scap.nist.gov/