Skip to content
AppClap
OpenSCAP is unclaimed —
O

OpenSCAP

Improve security of your infrastructure using open source tools.·open-scap.org

Visit

OpenSCAP is a collection of open source tools for implementing and enforcing the Security Content Automation Protocol (SCAP), a U.S. standard maintained by NIST. It provides tools for security compliance scanning, vulnerability assessment, and automated remediation of systems against customizable security policies and hardening guides. The project has been awarded SCAP 1.2 certification by NIST.

What it's for

Scan systems for security complianceChoose and customize a security policyEvaluate systems against security baselinesAutomated vulnerability checking of software inventoryAutomated remediation of non-compliant systemsScan Atomic images and containers for CVEsInstall PCI-DSS compliant RHEL systems using the Anaconda add-on

Features 14

  • Automated remediation of security rules
  • Automated vulnerability checking
  • C API for building custom applications
  • Container and image (Atomic) CVE scanning
  • Customizable security policy variables and rules
  • Integration with Spacewalk and Foreman for systems management
  • NIST SCAP 1.2 certified tooling
  • OpenSCAP Base scanning tool
  • OpenSCAP Daemon
  • OSCAP Anaconda Addon for install-time compliance
  • OVAL, XCCDF, CPE, and CVE implementation
  • SCAP Security Guide (security policies/baselines)
  • SCAP Workbench GUI for policy customization
  • SCAPTimony

At a glance

free tieropen sourceAPI
TypeCLI tool
DeploymentInstalled (local)
Forgovernment agencies, businesses, open source community, system administrators, auditors
CompanyRed Hat, Inc.

Integrations

SpacewalkForeman

Complianceself-reported

FISMAPCI DSSUSGCBSTIG

Resources

Pricing

OpenSCAP tools are free and open source; no paid plans are listed.

Last checked 3 days ago·