3 SCAP and Automated Assessment

STIG Fundamentals · 3:14

Listen on 93

Lyrics

[Verse 1]
When compliance checking takes too long to do by hand
SCAP automation helps you understand
Security Content Automation Protocol's the way
Makes STIG assessment faster every day
Machine-readable benchmarks in XCCDF form
OVAL definitions keep your systems in the norm

[Chorus]
SCAP it up, scan it down
SCC is DISA's crown
Sixty to eighty percent automated
Manual checks still validated
SCAP it up, make it flow
OpenSCAP for Linux, now you know

[Verse 2]
SCAP Compliance Checker is the official tool
DISA built it following every rule
Benchmarks translate STIGs to machine code
XCCDF and OVAL share the load
PowerShell users get Evaluate-STIG
Windows assessment dancing to this jig

[Chorus]
SCAP it up, scan it down
SCC is DISA's crown
Sixty to eighty percent automated
Manual checks still validated
SCAP it up, make it flow
OpenSCAP for Linux, now you know

[Bridge]
Not everything can be scanned automatically
Interviews and documentation need humanity
Architecture analysis requires human eyes
But automation handles most of the tries
Combine both methods for complete review
Manual plus automated gets you through

[Verse 3]
Open-source OpenSCAP in Linux land
Scanning compliance with a steady hand
But remember that gap of twenty to forty
Some findings need review, don't get sporty
Documentation checks and interview time
Human verification keeps you in line

[Chorus]
SCAP it up, scan it down
SCC is DISA's crown
Sixty to eighty percent automated
Manual checks still validated
SCAP it up, make it flow
OpenSCAP for Linux, now you know

[Outro]
Security Content Automation Protocol
Makes compliance checking more practical
Scan the systems, check the findings
Manual review for perfect bindings

← 1 SRG-to-STIG Hierarchy | 2 RHEL / Linux STIG →