Using OpenSCAP with security profiles for OSPP and PCI DSS
There are several security profiles used for compliance in the industry. Two of the most common, which we will review here, are the OSPP and PCI DSS standards.
The OSPP standard is heavily used in the public sector, serving general-purpose systems and also as a baseline for other more restrictive environments (that is, defense-accredited systems).
PCI DSS is one of the most widely used standards in the finance sector, and also applies to other sectors that want to provide online payments using credit cards.
There are different types of descriptions that can be used with OpenSCAP. We already know OVAL. Let’s check the most important ones here:
- Extensible Configuration Checklist Description Format (XCCDF): XCCDF is used to build security checklists. It’s very common for compliance testing and scoring.
- Common Platform Enumeration (CPE): CPE helps identify systems by assigning unique ID...