Which ACAS component performs active vulnerability and compliance scanning? CMRS is a tool to provide DoD component- and enterprise-level situational awareness by quantitatively displaying an organization's security posture.
Which ACAS component performs active vulnerability and compliance?
Nessus is the scanning component of ACAS that is compliant with not only CVE vulnerability identifiers, but also DISA STIGs. This is one of the main advantages of Nessus over DoD's previous scanner, Retina. In the DoD world, the compliance with STIGS is just as important as the compliance with software vulnerabilities.
What is ACAS vulnerability and compliance scanning?
The Assured Compliance Assessment Solution (ACAS) is the mandated enterprise vulnerability scanning capability for networks and components that are owned or operated by the Department of Defense (DoD).