2 Lab 2 — Automated SCAP Scanning

STIGs and Compliance Framework · 4:04

Listen on 93

Lyrics

[Verse 1]
Time to automate our STIG compliance checking
Download SCC or OpenSCAP for scanning
SCAP Compliance Checker is the tool we need
Install it first, then we can proceed
Get your benchmark from the DISA site
Make sure the version matches just right

[Chorus]
Scan, check, review - automated way
Open findings, Not a Finding, Not Reviewed today
Import to STIG Viewer when the scan is done
Manual review completion has just begun
S-C-A-P scanning makes compliance clear
Automated checking keeps our systems secure

[Verse 2]
Fire up your virtual machine for testing
Run the scan command, no more guessing
Watch as SCAP evaluates each control
System configuration under its patrol
Red means Open, needs immediate care
Green Not a Finding, system's prepared there

[Chorus]
Scan, check, review - automated way
Open findings, Not a Finding, Not Reviewed today
Import to STIG Viewer when the scan is done
Manual review completion has just begun
S-C-A-P scanning makes compliance clear
Automated checking keeps our systems secure

[Bridge]
Not Reviewed items need human eyes
Manual validation, no surprise
STIG Viewer helps you track it all
Mark each finding, big or small
From automated scan to final report
Compliance checking of every sort

[Verse 3]
Generate reports when scanning's complete
Documentation makes your audit neat
Every vulnerability clearly displayed
Security posture properly weighed
Remediate the Opens, document the rest
Your system's ready for the compliance test

[Final Chorus]
Scan, check, review - automated way
Open findings, Not a Finding, Not Reviewed today
Import to STIG Viewer when the scan is done
Manual review completion has just begun
S-C-A-P scanning makes compliance clear
Automated checking keeps our systems secure
Lab two complete, you've learned it here

← 5 STIGs and the Canadian Context (CPCSC / ITSG-33) | 3 Lab 3 — Manual STIG Assessment →