The XCCDF component
BMC Server Automation supports the Extensible Configuration Checklist Description Format (XCCDF).
XCCDF is an SCAP XML language for expressing security checklists. The source data stream that BMC Server Automation uses for SCAP compliance scans must be well-formed XCCDF. The result data stream that BMC Server Automation produces is well-formed XCCDF.
To prepare for SCAP scanning, an administrator assembles an SCAP source data stream, including XCCDF content, into a folder on a server that is accessible to BMC Server Automation. Well-formed XCCDF content from any source is acceptable. Using the BMC Server Automation Console, the administrator navigates to the XCCDF file and imports all SCAP content for a benchmark in a single import action. The import process validates all content against appropriate schemas and schematrons. It captures validation errors in a log file which is accessible from the BMC Server Automation Console.
The imported data stream appears as an SCAPBenchmark object in the BMC Server Automation Console. Multiple SCAPBenchmarks are permitted to accommodate usage of multiple XCCDF content sources and versions.
An SCAP Compliance Job produces an XCCDF results file compliant with the XCCDF specifications.