The following topics describe how the Security Content Automation Protocol (SCAP) content components are used in TrueSight Server Automation:
The XCCDF component
TrueSight Server Automation supports the Extensible Configuration Checklist Description Format (XCCDF).
XCCDF is an SCAP XML language for expressing security checklists. The source data stream that TrueSight Server Automation uses for SCAP compliance scans must be well-formed XCCDF. The result data stream that TrueSight Server Automation produces is well-formed XCCDF.
To prepare for SCAP scanning, an administrator assembles an SCAP source data stream, including XCCDF content, into a folder on a server that is accessible to TrueSight Server Automation. Well-formed XCCDF content from any source is acceptable. Using the TrueSight Server Automation console, the administrator navigates to the XCCDF file and imports all SCAP content for a benchmark in a single import action. The import process validates all content against appropriate schemas and schematrons. It captures validation errors in a log file which is accessible from the TrueSight Server Automation Console.
The imported data stream appears as an SCAP benchmark object in the TrueSight Server Automation console. Multiple SCAP benchmarks are permitted to accommodate usage of multiple XCCDF content sources and versions.
An SCAP Compliance Job produces an XCCDF results file compliant with the XCCDF specifications.
The OVAL component
TrueSight Server Automation supports the Open Vulnerability and Assessment Language (OVAL). OVAL is an SCAP XML language for representing system configuration information, assessing machine state, and reporting assessment results. The following OVAL versions are supported: 5.10.1, 5.11.1, and 5.11.2
A proprietary OVAL interpreter based on the open-source OVAL Definition Interpreter (ovaldi) processes the OVAL tests. The OVAL interpreter is bundled with the RSCD agent, a BMC component installed on every server managed by TrueSight Server Automation.
OVAL content is imported into the TrueSight Server Automation Console as part of the SCAP data stream. The import process validates the OVAL content against its schema and captures validation errors in a log file which is accessible from the TrueSight Server Automation Console.
To initiate an SCAP scan, administrators create an SCAP Compliance Job. On each target server selected in the job, an OVAL interpreter performs the vulnerability processing and creates an OVAL results file that is compliant with the OVAL results schema.
The process then synthesizes the results file into a small-sized file and sends it to the Application Server. The Application Server creates the XCCDF results file from the collected results. By default, the process deletes the OVAL result files from each target server; however, administrators can configure the SCAP Compliance Jobs to retain those files.
Users can view the XCCDF results in the TrueSight Server Automation Console. They can also export results from the Console to an XML file. The export includes a .xslt file which enables a fully formatted view of the results in a web browser. In the browser-displayed report, users can click a specific Benchmark rule to view details about the rule, including OVAL IDs associated with the rule. Each listed OVAL ID is an active link to the specific web page about that test on .
For a list of probes supported by ovaldi, see the Probes supported by OVAL Definition Interpreter (ovaldi).
Probes supported by OVAL Definition Interpreter (ovaldi)
The following probes are supported by different Ovaldi versions: