{"id":30,"date":"2006-02-18T12:27:19","date_gmt":"2006-02-18T17:27:19","guid":{"rendered":"http:\/\/raffy.ch\/blog\/?p=30"},"modified":"2006-02-18T12:29:34","modified_gmt":"2006-02-18T17:29:34","slug":"xccdf-p","status":"publish","type":"post","link":"https:\/\/raffy.ch\/blog\/2006\/02\/18\/xccdf-p\/","title":{"rendered":"XCCDF-P"},"content":{"rendered":"<p>A horrible acronym. I know. We had a working session during the RSA conference to talk about XCCDF-P. For those not familiar with <a HREF=\"http:\/\/csrc.nist.gov\/checklists\/xccdf.html\">XCCDF<\/a>, it has to do with policy definitions and uses OVAL to implement the checks. <\/p>\n<p>XCCDF-P (which will hopefully get renamed pretty soon to something else, and hopefully not to CPN (Common Platform Names) [We already have CVE, CME, and CCE]) is an effort to standardize platform names. What&#8217;s the problem? Well, if I have two scanners analyzing a system of mine, one of them might report that I am running a &#8220;Windows 2000&#8221;, the other one might say &#8220;Win2K&#8221;. This is really the same, but how would a machine know? That&#8217;s where the standard is trying to clean things up. You wouldn&#8217;t belive how much discussion this topic actually involves. We met for about an hour and had plenty of things to discuss, not even closely getting to an agreed-upon solution. However, the problem is defined and we all agreed upon the the necessity to solve the problem! Stay put for an update soon and hopefully a quick turn around with a solution draft.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A horrible acronym. I know. We had a working session during the RSA conference to talk about XCCDF-P. For those not familiar with XCCDF, it has to do with policy definitions and uses OVAL to implement the checks. XCCDF-P (which will hopefully get renamed pretty soon to something else, and hopefully not to CPN (Common [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-30","post","type-post","status-publish","format-standard","hentry","category-log-analysis"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/posts\/30","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/comments?post=30"}],"version-history":[{"count":0,"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/posts\/30\/revisions"}],"wp:attachment":[{"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/media?parent=30"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/categories?post=30"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/raffy.ch\/blog\/wp-json\/wp\/v2\/tags?post=30"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}