The Extensible Configuration Checklist Description Format (XCCDF) is an
XML
Extensible Markup Language (XML) is a markup language and file format for storing, transmitting, and reconstructing arbitrary data. It defines a set of rules for encoding documents in a format that is both human-readable and machine-readable. ...
format specifying
security checklist
Security is protection from, or resilience against, potential harm (or other unwanted coercive change) caused by others, by restraining the freedom of others to act. Beneficiaries (technically referents) of security may be of persons and social ...
s, benchmarks and configuration documentation.
XCCDF development is being pursued by
NIST
The National Institute of Standards and Technology (NIST) is an agency of the United States Department of Commerce whose mission is to promote American innovation and industrial competitiveness. NIST's activities are organized into physical sc ...
, the
NSA
The National Security Agency (NSA) is a national-level intelligence agency of the United States Department of Defense, under the authority of the Director of National Intelligence (DNI). The NSA is responsible for global monitoring, collectio ...
,
The MITRE Corporation, and the
US Department of Homeland Security
The United States Department of Homeland Security (DHS) is the U.S. federal executive department responsible for public security, roughly comparable to the interior or home ministries of other countries. Its stated missions involve anti-ter ...
.
XCCDF is intended to serve as a replacement for the security hardening and analysis documentation written in prose. XCCDF is used by the
Security Content Automation Protocol
The Security Content Automation Protocol (SCAP) is a method for using specific standards to enable automated vulnerability management, measurement, and policy compliance evaluation of systems deployed in an organization, including e.g., FISMA (Fed ...
.
References
{{Reflist
External links
XCCDF HomepageXCCDF 1.1.2 specification
XCCDF 1.1.3 specification
XCCDF 1.1.4 specification
XCCDF 1.2 specification(current as of October 2011)
Checklists
XML-based standards
Computer security software