National Vulnerability Database - The National Vulnerability Database (NVD, http://nvd.nist.gov) has expanded its scope to enable organizations to automate and standardize vulnerability management, security measurement, and compliance reporting (e.g., FISMA). Thus, NVD now enables Federal agencies and other organizations to ensure that information technology assets are configured securely, automate technical control FISMA compliance checking, customize secure configuration requirements, standardize the measurement of low-level vulnerabilities, and integrate vulnerability and product databases using a standards-based approach.

https://nvd.nist.gov/

This capability is achieved through the Information Security Automation Program (ISAP). ISAP, pronounced “I Sap”, is a U.S. government multi-agency initiative to enable automation and standardization of technical security operations. While a U.S. government initiative, its standards-based design can benefit all information technology security operations. The ISAP high-level goals include standards-based automation of security checking and remediation as well as automation of technical compliance activities (e.g. FISMA). ISAP’s low-level objectives include enabling standards-based communication of vulnerability data, customizing and managing configuration baselines for various IT products, assessing information systems and reporting compliance status, using standard metrics to weight and aggregate potential vulnerability impact, and remediating identified vulnerabilities.

Main Menu