Announcing BigFix Compliance SCAP 1.3 Release

Hello BigFix Community,

We are excited to announce the release of BigFix Compliance SCAP 1.3, which includes enhancements across the SCAP Tool, SCAP 1.3 Wizard, and ARF Reporting components. It is now available for all BigFix Compliance license holders.

Overview

BigFix Compliance has successfully achieved SCAP 1.3 Certification under the NIST SCAP Validation Program (Validation Number 148). This certification aligns BigFix with the latest NIST specifications and ensures continued compliance with federal and industry security automation standards.

View our certification here: NIST SCAP CERTIFICATION

New Components and Features

SCAP 1.3 Tool

  • Built on a modernized Python-based architecture for faster and more reliable parsing of XCCDF, OVAL, and CPE files.
  • Supports importing both CIS and DISA STIG benchmarks for Windows 10 and 11 and RHEL 8 and 9 operating systems.
  • Integrated Relevance Library and Relevance Generator for dynamic Fixlet creation.
  • Produces standardized ARF (Asset Reporting Format) outputs for certification and reporting compliance.
  • Provides complete accuracy and validation against SCAP 1.3 schemas and NIST benchmarks.

SCAP 1.3 Wizard

  • Enhanced wizard interface now supports importing and executing SCAP 1.3 content directly from the BigFix Console.
  • Process CIS and DISA content structures.
  • Streamlined benchmark and datastream selection workflow.

ARF Reporting Integration

  • Generates SCAP-compliant ARF XML reports summarizing compliance results across multiple systems.
  • Enables centralized compliance visibility by aggregating rule results per asset.
  • Ensures interoperability with NIST tools, compliance dashboards, and external validation frameworks.
  • Improves traceability and auditing through embedded benchmark metadata, evaluator details, and timestamps.
  • Seamlessly integrates with BigFix Web Reports for SCAP result visualization.

Tool Versions

Type Name Version
SCAP Tool BigFix Compliance SCAP Content v1.0.0

Site Versions

Type Name Version
Fixlet Site SCM Reporting Site version: 162

Prerequisites

Component Supported Versions
BigFix Platform (Core) v11.0 or later
Web Reports BigFix 11.0 Web Reports module

Documentation

For detailed instructions on importing and using SCAP 1.3 content, refer to Importing SCAP content.

Conclusion

If you have any questions or comments, please feel free to reach out or respond here. Thank you!

2 Likes

Very nice addition!

Just to understand what is different between the External Sites you provide and the SCAP Files?

What was the reason for creating this content :index_pointing_up::slightly_smiling_face: