Hello BigFix Community,
We are excited to announce the release of BigFix Compliance SCAP 1.3, which includes enhancements across the SCAP Tool, SCAP 1.3 Wizard, and ARF Reporting components. It is now available for all BigFix Compliance license holders.
Overview
BigFix Compliance has successfully achieved SCAP 1.3 Certification under the NIST SCAP Validation Program (Validation Number 148). This certification aligns BigFix with the latest NIST specifications and ensures continued compliance with federal and industry security automation standards.
View our certification here: NIST SCAP CERTIFICATION
New Components and Features
SCAP 1.3 Tool
- Built on a modernized Python-based architecture for faster and more reliable parsing of XCCDF, OVAL, and CPE files.
- Supports importing both CIS and DISA STIG benchmarks for Windows 10 and 11 and RHEL 8 and 9 operating systems.
- Integrated Relevance Library and Relevance Generator for dynamic Fixlet creation.
- Produces standardized ARF (Asset Reporting Format) outputs for certification and reporting compliance.
- Provides complete accuracy and validation against SCAP 1.3 schemas and NIST benchmarks.
SCAP 1.3 Wizard
- Enhanced wizard interface now supports importing and executing SCAP 1.3 content directly from the BigFix Console.
- Process CIS and DISA content structures.
- Streamlined benchmark and datastream selection workflow.
ARF Reporting Integration
- Generates SCAP-compliant ARF XML reports summarizing compliance results across multiple systems.
- Enables centralized compliance visibility by aggregating rule results per asset.
- Ensures interoperability with NIST tools, compliance dashboards, and external validation frameworks.
- Improves traceability and auditing through embedded benchmark metadata, evaluator details, and timestamps.
- Seamlessly integrates with BigFix Web Reports for SCAP result visualization.
Tool Versions
| Type | Name | Version |
|---|---|---|
| SCAP Tool | BigFix Compliance SCAP Content | v1.0.0 |
Site Versions
| Type | Name | Version |
|---|---|---|
| Fixlet Site | SCM Reporting | Site version: 162 |
Prerequisites
| Component | Supported Versions |
|---|---|
| BigFix Platform (Core) | v11.0 or later |
| Web Reports | BigFix 11.0 Web Reports module |
Documentation
For detailed instructions on importing and using SCAP 1.3 content, refer to Importing SCAP content.
Conclusion
If you have any questions or comments, please feel free to reach out or respond here. Thank you!