Security Content Automation Protocol (SCAP)
SCAP is an open standard and is used by many vendors within the industry to support a common security reporting language. It is supported by the National Vulnerability Database (NVD), which is a US government-funded organization that produces content that can be used within a SCAP scanner.
It is used extensively within US government departments, including the Department of Defence (DoD), and meets Federal Information Security Management Act (FISMA) requirements.
Extensible Configuration Checklist Description Format (XCCDF)
XCCDF specifies a format for configuration files. These are the checklists that the SCAP scanner (the vulnerability assessment tool) will use. They are written in an XML format. Within the US government and DoD, these files are more commonly known as Secure Technical Implementation Guide (STIG). More information can be obtained from the following public site: https://public.cyber.mil/stigs/.
Important Note
...