atsec

The information security provider.

homesitemapblog
  • Services
  • Company
  • News & Events
  • Resources
  • Contact
Deutsch | 汉语

Product Evaluation
and Testing

Common Criteria (ISO/IEC 15408)
FIPS 140-2
Cryptographic Algorithm Testing
SCAP
NPIVP Testing
Biometrics Testing
GSA PIV Evaluation (FIPS 201)

Compliance and Audit
ISO/IEC 27001
SOX and Euro-SOX
FISMA Certification Support
HIPAA and HITECH
NASPO

Consulting and Training
VTDR for GSA FIPS 201
Embedded Systems
Hardware Security Testing and Analysis
Penetration Testing
PCI Consulting
US Export Control for Cryptography
Training

 back to the list of services
 

Security Content Automation Protocol (SCAP)

What atsec offers

The Information Security Automation Program (ISAP) is a U.S. government initiative to enable automation and standardization of technical security operations. The Security Content Automation Protocol (SCAP) combines a number of open standards used to enumerate software flaws and configuration issues related to security. atsec information security is an accredited testing laboratory number 200658, under the NVLAP (National Voluntary Laboratory Accreditation Program). We have extensive expertise in testing, evaluation and validation support of software and hardware products. We offer:

  • Formal laboratory conformance testing using NIST test suites
  • Consultation about SCAP requirements
  • Assessment of test readiness
  • Verification that an application does not change any SCAP relevant settings
  • Support for NIST validation of SCAP testing

Why our services are important to you

NIST recommends the use of SCAP for the integration of security products, the automation of policy compliance, and vulnerability management activities. Agencies and other organizations can automate much of their FISMA technical security control compliance activities by regularly scanning information technology assets using SCAP checklists. Adoption of SCAP will enable agencies and other organizations to integrate and automate disjoint security operations activities and databases.

For more information

Please refer to our resource pages.

 

(c) 2012 atsec information security | Legal Notice | Data Protection Notice | Environmental Policy | Security Policy |  atsec IT security blog atsec on facebook atsec on twitter atsec on LinkedIn atsec on digg.com