Title :
SCAP benchmark for Cisco router security configuration compliance
Author :
Chit Nyi Nyi Hlyne;Pavol Zavarsky;Sergey Butakov
Author_Institution :
Department of Information Systems Security and Assurance Management, Concordia University of Edmonton Edmonton T5B 4E4, Alberta, Canada
Abstract :
Information security management is time-consuming and error-prone. Apart from day-to-day operations, organizations need to comply with industrial regulations or government directives. Thus, organizations are looking for security tools to automate security management tasks and daily operations. Security Content Automation Protocol (SCAP) is a suite of specifications that help to automate security management tasks such as vulnerability measurement and policy compliance evaluation. SCAP benchmark provides detailed guidance on setting the security configuration of network devices, operating systems, and applications. Organizations can use SCAP benchmark to perform automated configuration compliance assessment on network devices, operating systems, and applications. This paper discusses SCAP benchmark components and the development of a SCAP benchmark for automating Cisco router security configuration compliance.
Keywords :
"Security","Benchmark testing","Automation","Operating systems","NIST"
Conference_Titel :
Internet Technology and Secured Transactions (ICITST), 2015 10th International Conference for
DOI :
10.1109/ICITST.2015.7412104