From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 24,300 courses taught by industry experts.

Security content automation protocol (SCAP)

Security content automation protocol (SCAP)

From the course: CompTIA SecurityX (CAS-005) Cert Prep

Security content automation protocol (SCAP)

- Security Content Automation Protocol, SCAP, is a suite of standards that support automated configuration, vulnerability and patch management. It was developed by NIST, and SCAP helps organizations, lots of different organizations automate the process of identifying, assessing, and remediating security vulnerabilities. By using SCAP, organizations can improve their security posture through automation, helping ensure that systems are consistently configured, vulnerabilities are promptly identified, and patches are applied in an efficient and effective manner. Common vulnerabilities and exposures, CVE, is a standardized list of publicly known information security vulnerabilities and exposures. The CVE system has been around since the turn of the century. It was launched in 1999 by the MITRE Corporation to identify and categorize vulnerabilities in software and firmware. Let's look at some key points about CVE. You have CVE identifiers. Each CVE entry has a unique identifier, often…

Contents