Security Content Automation Protocol

This is an old revision of this page, as edited by Steveweingart (talk | contribs) at 15:24, 3 March 2008 (added external links and SCAP summary). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

The Security Content Automation Protocol (SCAP) is a method for using specific standards to enable automated vulnerability management, measurement, and policy compliance evaluation (e.g., FISMA compliance). The National Vulnerability Database (NVD) is the U.S. government content repository for SCAP.


The Security Content Automation Protocol (SCAP), pronounced “S-Cap”, combines a number of open standards that are used to enumerate software flaws and configuration issues related to security. They measure systems to find vulnerabilities and offer methods to score those findings in order to evaluate the possible impact. It is basically a is a method for using those open standards for automated vulnerability management, measurement, and policy compliance evaluation. SCAP defines how the following standards are combined: