Specification for the Extensible Configuration Checklist Description Format (XCCDF)
Neal Ziring, Author, National Security Agency John Wack, NIST Editor
NISTIR 7188
Specification for the Extensible Configuration Checklist Description Format (XCCDF)
Neal Ziring, NSA Author Information Assurance Directorate National Security Agency Fort Meade, MD 20755-6704
John Wack, NIST Editor Computer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg, MD 20988-8930
January 2005 U.S. DEPARTMENT OF COMMERCE Donald L. Evans, Secretary TECHNOLOGY ADMINISTRATION Phillip J. Bond, Under Secretary of Commerce for Technology NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY Hratch G. Semerjian, Acting Director Abstract
This document specifies the data model and XML representation for the Extensible Configuration Checklist Description Format (XCCDF). An XCCDF document is a structured collection of security configuration rules for some set of target systems. The XCCDF specification is designed to support information interchange, document generation, organizational and situational tailoring, automated compliance testing, and compliance scoring. The specification also defines a data model and format for storing results of benchmark compliance testing. The intent of XCCDF is to provide a uniform foundation for expression of security checklists ...