Frequently Asked Questions

Search specific questions

  1. What is SCAP?
  2. What is OVAL, XCCDF, CVE, CCE, CPE, CWE, CVSS, OCIL?
  3. Can I use the content free of cost?
  4. Why is there a Login?
  5. Example search queries?
  6. What can I search?
  7. If I found an issue, where to report?
  8. Is there any difference between CVE content available here vs NVD?
  9. Is there any difference between CPE content available here vs NVD?
  10. Is there any difference between CCE content available here vs NVD?
  11. Is there any difference between CWE content available here vs MITRE?
  12. What are the terms of use?
  13. What is the update cycle of the SCAP repo?
  14. What language the repository understands?
  15. What is the difference between Advance Search and regular Search?
  16. What is next?
  17. I did search for somethingi, but I didn't get the result I expected, what should I do?
  18. Can I ask for a new query to be supported? Where do I submit?
  19. I like the search results that I get for my queries, anyway to indicate that?
  20. Is there a web service interface that I can bind to?
  21. What is the difference with accessing the repository as an unregistered user as against a subscriber?
  22. Are there any search techniques that I should be aware of?
  23. What Browsers have been tested?

Product specific questions

  1. What is SCAP repo?
  2. How do I subscribe to the feed? How do I buy the content?
  3. What is the difference between SCAP feed and SCAP repo?
  4. What is the relation between Content Repository and Continuous Monitoring?
  5. What are the different use cases for SCAP repo?
  6. What are the different use cases for SCAP feed?
  7. How do I find out more about SCAP Repo?
  8. How do I find out more about SCAP Feed?
  9. If I need support, what are the options available?
  10. I would like to evaluate SCAP Repo. How do I get a copy?

Search specific questions

What is SCAP?

Security Content Automation Protocol (SCAP) defines a set of standards to enable automated vulnerability management, measurement, and policy compliance evaluation. More information at: http://scap.nist.gov/

What is OVAL, XCCDF, CVE, CCE, CPE, CWE, CVSS, OCIL?

These are a suite of open standards that enumerate software flaws, security related configuration issues, and product names; measure systems to determine the presence of vulnerabilities; and provide mechanisms to rank the results of these measurements in order to evaluate the impact of the discovered security issues.

Can I use the content free of cost?

All the SCAP enumerations (CVE, CCE, CPE, CWE) are available for download. OVAL and XCCDF content is not available for non-subscribers. However, search is on the whole repository.

Why is there a Login?

Login is there for subscribers only. Credentials will be provided once subscribed, which will allow you to download OVAL and XCCDF content apart from managing your preferences.

Example search queries?

"Recently released OVAL definitions". You can certainly be more creative than that.

What can I search?

Search anything SCAP. Some sample search queries to give you ideas:

- biggest threats
- cves that matter
- today cve
- adobe cve
- windows cves
- patch definitions
- adobe oval and adobe cve
- adobe scap
- google chrome cpe
- all vulnerabilities from jan 2011
- list gnome products
- list all products
- microsoft bulletin content
- oval definition for cve-2011-1234
- inventory definition for adobe
- cve access complexity high
- cve availability impact complete
- cves whose cvss score more than 9.3
- Adobe CVEs whose CVSS is more than 8

Some of the queries that will/may not work:

- When is the next SCAP conference
- NISTIR-7799

If I found an issue, where to report?

If you are not satisfied with the search results for a query or if you would like to see a new feature, send an email to:info@secpod.com

Is there any difference between CVE content available here vs NVD?

We might update additional fields that are available in the CVE XML schema based on our research of the vulnerability. We might add some mapping info so that the CVE is more searchable.

Is there any difference between CPE content available here vs NVD?

We intend to submit any new CPE added into our repository or any corrections we make to NVD. There should not be difference.

Is there any difference between CCE content available here vs NVD?

We intend to submit any new CCE added into our repository or any corrections we make to MITRE.

Is there any difference between CWE content available here vs MITRE?

We intend to submit any new CWE added into our repository or any corrections we make to MITRE.

What are the terms of use?

Please refer to Terms page.

What is the update cycle of the SCAP repo?

Updates are done almost daily.

What language does the repository understands?

SCAP technical natural language :)

What is the difference between Advance Search and Regular Search?

We have tried to make it possible to search everything through regular search. Only use Advance Search if you are not satisfied with the results. However, Advance Search is only available for subscribers.

What is next?

There is a lot that we want to do, please stay connected.

I did search for something, but I didn't get the result I expected, what should I do?

We would like to understand the query that didn't yield the desired results. Please share it with us at info@secpod.com and we'll ensure that it is addressed.

Can I ask for a new query to be supported? Where do I submit?

Please submit your query to info@secpod.com.

I like the search results that I get for my queries, anyway to indicate that?

So, you liked it. Thanks! Please do mention at info@secpod.com and we'll certainly be encouraged.

Is there a web service interface that I can bind to?

Yes, a RESTful service at:
https://www.scaprepo.com/SCAPRepoWebService

The interface documentation and also a sample Java based client is available here

What is the difference with accessing the repository as an unregistered user compared to a subscriber?

As an unregistered user, you are allowed to search everything but you are not allowed to download OVAL and XCCDF content. And Personalization is not possible.

Are there any search techniques that I should be aware of?

'and': This is treated as 2 different queries
'+': This is treated as 'containing'
"": Whatever is inside "" will be searched for the exact match after ignoring the case

What Browsers have been tested?

We have tested with the latest versions of Microsoft Internet Explorer, Mozilla Firefox, Google Chrome and Apple Safari.


Product specific questions

What is SCAP Repo?

An SCAP Content Repository, that lets you store, search and manage SCAP content (CVE, CPE, CCE, CWE, OVAL, XCCDF and OCIL). It can act as an organizational content server, hosting content relevant to your organization. It is also an essential component (Content Subsystem) in a Continuous Monitoring framework.

How do I subscribe to the feed? How do I buy the content?

Just mail us at info@secpod.com

What is the difference between SCAP Feed and SCAP Repo?

The SCAP Feed provides professional quality SCAP content available on a subscription model. SCAP Repo is a server that can host and manage the SCAP content, available for OEM integration as well as full-product version.

What is the relation between Content Repository and Continuous Monitoring?

Content Subsystem or Content Repository is a component of Continuous Monitoring framework. It is a repository hosting Digital policies, baselines, enumerations and standards. Please refer to NISTIR-7799.

What are the different use cases for SCAP Repo?

Following are the use cases:

- Product vendor hosting and managing SCAP content
- Organizational content server, hosting and managing SCAP content relevant to specific environment
- Continuous Monitoring solutions needing a Content Subsystem

What are the different use cases for SCAP Feed?

Following are the use cases:
- Information Security product vendors integrating SCAP Content
- Security consulting vendors integrating SCAP Content
- Enterprises hosting Information Security solution

How do I find out more about SCAP Repo?

More information can be found at: http://www.secpod.com/secpod-SCAPRepo.php

How do I find out more about SCAP Feed?

More information can be found at: http://www.secpod.com/scap-feed.html

If I need support, what are the options available?

If you are a subscriber, you will be entitled for technical support.

I would like to evaluate SCAP Repo. How do I get a copy?

Just mail us at info@secpod.com.

About              FAQ              Terms