Performing Vulnerability Analysis Flashcards
Security Content Automation Protocol(SCAP)
A NIST framework that outlines various accepted practices for automating vulnerability scanning.
Open Vulnerability and Assessment Language(OVAL)
An XML schema, maintained by MITRE, for describing system security state and querying vulnerability reports and information.
Common Platform Enumeration(CPE)
Scheme for identifying hardware devices, operating systems, and applications developed by MITRE
Common Vulnerabilities and Exposures(CVE)
Scheme for identifying vulnerabilities developed by MITRE and adopted by NIST.
Common Configuration Enumeration(CCE)
Scheme for provisioning secure configuration checks across multiple sources developed by MITRE and adopted by NIST.
Common Vulnerability Scoring System (CVSS)
A risk management approach to quantifying vulnerability data and then taking into account the degree of risk to different types of systems or information.