[scap-dev] Questions on tracibility with XCCDF Tailoring

7 views
Skip to first unread message

Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

unread,
Sep 9, 2015, 12:29:42 PM9/9/15
to scap...@list.nist.gov
We are adding support for XCCDF Tailoring and are attempting to make the results transparent so anyone parsing the resulting ARF/XCCDF XML results would be aware that the original content was not performed. We have been able to indicate that a tailoring profile was used, but are not sure as to how best to show which rules/values were used.

We currently have added the following to the XCCDF Tailoring XML file (not sure if any of these except the _tailoring as part of #2 below are "required", we are just trying to force the user to document who created the tailoring file and why etc...)

1. Added _tailored to the profile id

2. Added XCCDF_<User Org>_tailoring to the Tailoring ID

3. Added the following metadata to the Tailoring XML file

a. Creator
b. Description
c. Version
d. Status

And we are indicating in the XCCDF TestResult that a tailoring file was used and that a tailored profile was used, however, if a ARF/XCCDF results consumer does not have the matching source XCCDF Tailoring file with the results, it's far from clear what was actually performed, who created the tailoring file, or why.

How do you document which XCCDF rules were performed and which values/refine-values were modified when an XCCDF tailoring file is used?

Do you:

a. Include the XCCDF Tailoring profile as an additional profile as part of the source portion of the XCCDF results?

b. Include the XCCDF Tailoring XML file as part of the ARF results?

c. Other??

Sincerely,

Jack Vander Pol

David Solin

unread,
Sep 9, 2015, 10:56:14 PM9/9/15
to scap...@list.nist.gov
Hi Jack,

The XCCDF TestResult element can have a tailoring-file child element; we put the tailoring there (there are also href, id, version and time attributes already there to describe the origin of the tailoring). The TestResult/profile at idref will match the TestResult/tailoring-file?s profile ID. And, of course, the TestResult is included in the ARF, as expected.

Best regards,
?David Solin
solin at farnamhallventures.com

> _______________________________________________
> scap-dev mailing list
> scap...@list.nist.gov
> To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov.


Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

unread,
Sep 10, 2015, 8:29:05 AM9/10/15
to scap...@list.nist.gov
David,

Thanks for the response, we also use the tailoring-file child element to list the tailoring file, and plan to use the metadata fields to explain why tailoring was used, but are you including which rules and values & refine-values were actually used in the scan? The rules you can infer from which pass & failed, but what was modified in the values and refine-values appears to be opaque at best.

When you say the profile at idref<mailto:profile at idref> will match the TestResult/tailoring-files Profile ID, are you including the Tailoring profile the results in some way?

Thanks

Jack Vander Pol

________________________________
From: David Solin [solin at farnamhallventures.com]
Sent: Wednesday, September 09, 2015 10:56 PM
To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

David Solin

unread,
Sep 10, 2015, 8:45:03 AM9/10/15
to scap...@list.nist.gov
Hi Jack,

The TestResults will results themselves contain the set-values and set-complex-values in addition to the rule results (including, e.g., NOT SELECTED) ? I thought that would be quite sufficient to illustrate the functional result of the tailoring. A tailoring can have multiple profiles (each with their own IDs) and I only mean the selected tailoring profile should be reflected by the value of TestResult/profile at idref.

Adding a tailoring in this way should appear no more mysterious, from a results analysis perspective, than selecting any profile in the original XCCDF benchmark.

Best regards,
?David A. Solin
Co-Founder, Research & Technology
solin at jovalcm.com

Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

unread,
Sep 10, 2015, 9:13:34 AM9/10/15
to scap...@list.nist.gov
Thanks again David, I suspect our group isn't the developers that are researching XCCDF Tailoring. Would you mind sending out sample XCCDF TestResult (imbedded in the email to prevent being stripped from annoying antivirus software...) of something small like the USGCB Win7 Energy without tailoring, and then after tailoring? I think seeing it would help all involved.

Jack Vander Pol

________________________________
From: scap-dev-bounces at nist.gov [scap-dev-bounces at nist.gov] on behalf of David Solin [solin at farnamhallventures.com]
Sent: Thursday, September 10, 2015 8:45 AM
To: scap...@list.nist.gov

David Solin

unread,
Sep 10, 2015, 9:27:37 AM9/10/15
to scap...@list.nist.gov
Sure... Hook me up with a tailoring file and I'll run it! :)

Sent from my iPhone

Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

unread,
Sep 10, 2015, 9:34:27 AM9/10/15
to scap...@list.nist.gov
David,

Here you go, and thanks for your time. Attached as well, renamed to .txt from .xml.

<?xml version="1.0" encoding="UTF-8"?>

<cdf:Tailoring id="xccdf_SPAWAR_tailoring_xccdf_gov.nist_benchmark_USGCB-Windows-7-Energy" xmlns:cdf="http://checklists.nist.gov/xccdf/1.2">
<cdf:benchmark href="scap_gov.nist_comp_USGCB-Windows-7-Energy-2.0.5.1-xccdf.xml" id="xccdf_gov.nist_benchmark_USGCB-Windows-7-Energy"></cdf:benchmark>
<cdf:version time="2015-09-10T08:48:51">1.0</cdf:version>
<cdf:metadata>
<organization>SPAWAR</organization>
<name>Jack Vander Pol</name>
<description>Disabling one rule and changing one value.</description>
<version>1.0</version>
<status>draft</status>
</cdf:metadata>
<cdf:Profile id="xccdf_gov.nist_profile_united_states_government_configuration_baseline_version_2.0.5.1_tailored" extends="xccdf_gov.nist_profile_united_states_government_configuration_baseline_version_2.0.5.1">
<cdf:title>United States Government Configuration Baseline version 2.0.5.1</cdf:title>
<cdf:description>This profile represents guidance for energy conservation for Windows 7 on desktop systems.</cdf:description>
<cdf:select idref="xccdf_gov.nist_rule_Specify_the_System_Hibernate_or_Sleep_Timeout_On_Battery" selected="true"></cdf:select>
<cdf:select idref="xccdf_gov.nist_rule_Specify_the_System_Hibernate_or_Sleep_Timeout_Plugged_in" selected="false"></cdf:select>
<cdf:select idref="xccdf_gov.nist_rule_Turn_off_the_Display_On_Battery" selected="true"></cdf:select>
<cdf:select idref="xccdf_gov.nist_rule_Turn_off_the_Display_Plugged_In" selected="true"></cdf:select>
<cdf:refine-value selector="3600_Seconds" idref="xccdf_gov.nist_value_Specify_the_System_Hibernate_or_Sleep_Timeout_On_Battery_var"></cdf:refine-value>
<cdf:refine-value selector="3600_Seconds" idref="xccdf_gov.nist_value_Specify_the_System_Hibernate_or_Sleep_Timeout_Plugged_in_var"></cdf:refine-value>
<cdf:refine-value selector="1200_seconds" idref="xccdf_gov.nist_value_Turn_off_the_Display_On_Battery_var"></cdf:refine-value>
<cdf:refine-value selector="1200_seconds" idref="xccdf_gov.nist_value_Turn_off_the_Display_Plugged_In_var"></cdf:refine-value>
<cdf:set-value idref="xccdf_gov.nist_value_Specify_the_System_Hibernate_or_Sleep_Timeout_On_Battery_var">1800</cdf:set-value>
</cdf:Profile>
</cdf:Tailoring>

________________________________
From: David Solin [solin at farnamhallventures.com]

Sent: Thursday, September 10, 2015 9:27 AM

Sent from my iPhone

-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: scap_gov.nist_datastream_USGCB-Windows-7-Energy-2.0.5.1.zip_tailoring.txt
Url: https://email.nist.gov/pipermail/scap-dev/attachments/20150910/b0071888/attachment-0001.txt

David Solin

unread,
Sep 10, 2015, 11:32:56 AM9/10/15
to scap...@list.nist.gov
Hi Jack,

I?ve attached a sample. I guess I forgot to mention that we add the tailoring to the datastream.

I?m not entirely happy with the attached result because we should also add the tailoring to the datastream's catalog, and fix the value of the TestResult/tailoring-file at href to refer to the component ID. But it illustrates more or less how we interpreted tailorings should be addressed within an ARF.

Best regards,
?David Solin


Co-Founder, Research & Technology
solin at jovalcm.com

-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...

Name: arf.txt
Url: https://email.nist.gov/pipermail/scap-dev/attachments/20150910/563b9357/attachment-0001.txt
-------------- next part --------------

> <scap_gov.nist_datastream_USGCB-Windows-7-Energy-2.0.5.1.zip_tailoring.txt>

Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

unread,
Sep 10, 2015, 11:51:24 AM9/10/15
to scap...@list.nist.gov
Thanks David, that was helpful, and hoping it was to anyone else going down this path.

Jack Vander Pol

________________________________
From: David Solin [solin at farnamhallventures.com]

Sent: Thursday, September 10, 2015 11:32 AM


To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Hi Jack,

I?ve attached a sample. I guess I forgot to mention that we add the tailoring to the datastream.

I?m not entirely happy with the attached result because we should also add the tailoring to the datastream's catalog, and fix the value of the TestResult/tailoring-file at href to refer to the component ID. But it illustrates more or less how we interpreted tailorings should be addressed within an ARF.

Best regards,
?David Solin
Co-Founder, Research & Technology
solin at jovalcm.com

> On Sep 10, 2015, at 9:34 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL> wrote:

BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP

unread,
Sep 10, 2015, 11:56:19 AM9/10/15
to scap...@list.nist.gov
Curious, why am I getting all these emails for this subject?

Randy

Randall Benefield, CISSP, Security+, Network+, A+
Security Control Assessor
743d ISS/SCPA (IPSecure Contractor)
Comm 210-977-6986/DSN 969-6986
NIPR: randall.benefield.1.ctr at us.af.mil
SIPR: randall.benefield.ctr at lackland.af.smil.mil


-----Original Message-----
From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Sent: Thursday, September 10, 2015 10:51 AM
To: David Solin
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Thanks David, that was helpful, and hoping it was to anyone else going down this path.

Jack Vander Pol

________________________________
From: David Solin [solin at farnamhallventures.com]
Sent: Thursday, September 10, 2015 11:32 AM
To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Hi Jack,

I've attached a sample. I guess I forgot to mention that we add the tailoring to the datastream.

I'm not entirely happy with the attached result because we should also add the tailoring to the datastream's catalog, and fix the value of the TestResult/tailoring-file at href to refer to the component ID. But it illustrates more or less how we interpreted tailorings should be addressed within an ARF.

Best regards,
-David Solin

>> The TestResults will results themselves contain the set-values and set-complex-values in addition to the rule results (including, e.g., NOT SELECTED) - I thought that would be quite sufficient to illustrate the functional result of the tailoring. A tailoring can have multiple profiles (each with their own IDs) and I only mean the selected tailoring profile should be reflected by the value of TestResult/profile at idref.


>>
>> Adding a tailoring in this way should appear no more mysterious, from a results analysis perspective, than selecting any profile in the original XCCDF benchmark.
>>
>> Best regards,

>> -David A. Solin


>> Co-Founder, Research & Technology
>> solin at jovalcm.com
>>
>>
>>
>>> On Sep 10, 2015, at 8:29 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL> wrote:
>>>
>>> David,
>>>
>>>
>>>
>>> Thanks for the response, we also use the tailoring-file child element to list the tailoring file, and plan to use the metadata fields to explain why tailoring was used, but are you including which rules and values & refine-values were actually used in the scan? The rules you can infer from which pass & failed, but what was modified in the values and refine-values appears to be opaque at best.
>>>
>>>
>>>
>>> When you say the profile at idref<mailto:profile at idref> will match the TestResult/tailoring-files Profile ID, are you including the Tailoring profile the results in some way?
>>>
>>>
>>>
>>> Thanks
>>>
>>> Jack Vander Pol
>>>
>>>
>>>
>>>
>>>
>>> ________________________________
>>> From: David Solin [solin at farnamhallventures.com]
>>> Sent: Wednesday, September 09, 2015 10:56 PM
>>> To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
>>> Cc: scap...@list.nist.gov
>>> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>>>
>>> Hi Jack,
>>>

>>> The XCCDF TestResult element can have a tailoring-file child element; we put the tailoring there (there are also href, id, version and time attributes already there to describe the origin of the tailoring). The TestResult/profile at idref will match the TestResult/tailoring-file's profile ID. And, of course, the TestResult is included in the ARF, as expected.
>>>
>>> Best regards,
>>> -David Solin

elmer.espinosa

unread,
Sep 10, 2015, 12:01:06 PM9/10/15
to scap...@list.nist.gov
Remove me from the loop

<div>-------- Original message --------</div><div>From: "BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP" <randall.benefield.1.ctr at us.af.mil> </div><div>Date:09/10/2015 11:56 PM (GMT+08:00) </div><div>To: "Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600" <jack.vanderpol at navy.mil>, David Solin <solin at farnamhallventures.com> </div><div>Cc: scap...@list.nist.gov </div><div>Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring </div><div>
</div>Curious, why am I getting all these emails for this subject?

Hanner, Walter L

unread,
Sep 10, 2015, 12:03:42 PM9/10/15
to scap...@list.nist.gov
Ditto.

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of elmer.espinosa
Sent: Thursday, September 10, 2015 11:01 AM
To: BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: EXTERNAL: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Remove me from the loop

-------- Original message --------
From: "BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP"
Date:09/10/2015 11:56 PM (GMT+08:00)
To: "Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600" , David Solin
Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Curious, why am I getting all these emails for this subject?

Randy

Randall Benefield, CISSP, Security+, Network+, A+
Security Control Assessor
743d ISS/SCPA (IPSecure Contractor)
Comm 210-977-6986/DSN 969-6986

NIPR: randall.benefield.1.ctr at us.af.mil<mailto:randall.benefield.1.ctr at us.af.mil>
SIPR: randall.benefield.ctr at lackland.af.smil.mil<mailto:randall.benefield.ctr at lackland.af.smil.mil>


-----Original Message-----
From: scap-dev-bounces at nist.gov<mailto:scap-dev-bounces at nist.gov> [mailto:scap-dev-bounces at nist.gov] On Behalf Of Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Sent: Thursday, September 10, 2015 10:51 AM
To: David Solin
Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Thanks David, that was helpful, and hoping it was to anyone else going down this path.

Jack Vander Pol

________________________________
From: David Solin [solin at farnamhallventures.com]
Sent: Thursday, September 10, 2015 11:32 AM
To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>


Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Hi Jack,

I've attached a sample. I guess I forgot to mention that we add the tailoring to the datastream.

I'm not entirely happy with the attached result because we should also add the tailoring to the datastream's catalog, and fix the value of the TestResult/tailoring-file at href to refer to the component ID. But it illustrates more or less how we interpreted tailorings should be addressed within an ARF.

Best regards,
-David Solin
Co-Founder, Research & Technology

solin at jovalcm.com<mailto:solin at jovalcm.com>

> Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>


> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>
> Sure... Hook me up with a tailoring file and I'll run it! :)
>
> Sent from my iPhone
>

>> On Sep 10, 2015, at 9:13 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at navy.mil<mailto:jack.vanderpol at navy.mil>> wrote:
>>
>> Thanks again David, I suspect our group isn't the developers that are researching XCCDF Tailoring. Would you mind sending out sample XCCDF TestResult (imbedded in the email to prevent being stripped from annoying antivirus software...) of something small like the USGCB Win7 Energy without tailoring, and then after tailoring? I think seeing it would help all involved.
>>
>>
>>
>> Jack Vander Pol
>>
>> ________________________________

>> From: scap-dev-bounces at nist.gov<mailto:scap-dev-bounces at nist.gov> [scap-dev-bounces at nist.gov] on behalf of David Solin [solin at farnamhallventures.com]


>> Sent: Thursday, September 10, 2015 8:45 AM

>> To: scap...@list.nist.gov<mailto:scap...@list.nist.gov>


>> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>>
>> Hi Jack,
>>
>> The TestResults will results themselves contain the set-values and set-complex-values in addition to the rule results (including, e.g., NOT SELECTED) - I thought that would be quite sufficient to illustrate the functional result of the tailoring. A tailoring can have multiple profiles (each with their own IDs) and I only mean the selected tailoring profile should be reflected by the value of TestResult/profile at idref.
>>
>> Adding a tailoring in this way should appear no more mysterious, from a results analysis perspective, than selecting any profile in the original XCCDF benchmark.
>>
>> Best regards,
>> -David A. Solin
>> Co-Founder, Research & Technology

>> solin at jovalcm.com<mailto:solin at jovalcm.com>


>>
>>
>>
>>> On Sep 10, 2015, at 8:29 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL<mailto:jack.vanderpol at NAVY.MIL>> wrote:
>>>
>>> David,
>>>
>>>
>>>
>>> Thanks for the response, we also use the tailoring-file child element to list the tailoring file, and plan to use the metadata fields to explain why tailoring was used, but are you including which rules and values & refine-values were actually used in the scan? The rules you can infer from which pass & failed, but what was modified in the values and refine-values appears to be opaque at best.
>>>
>>>
>>>
>>> When you say the profile at idref<mailto:profile at idref> will match the TestResult/tailoring-files Profile ID, are you including the Tailoring profile the results in some way?
>>>
>>>
>>>
>>> Thanks
>>>
>>> Jack Vander Pol
>>>
>>>
>>>
>>>
>>>
>>> ________________________________
>>> From: David Solin [solin at farnamhallventures.com]
>>> Sent: Wednesday, September 09, 2015 10:56 PM
>>> To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

>>> Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>


>>> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>>>
>>> Hi Jack,
>>>
>>> The XCCDF TestResult element can have a tailoring-file child element; we put the tailoring there (there are also href, id, version and time attributes already there to describe the origin of the tailoring). The TestResult/profile at idref will match the TestResult/tailoring-file's profile ID. And, of course, the TestResult is included in the ARF, as expected.
>>>
>>> Best regards,
>>> -David Solin

>>> solin at farnamhallventures.com<mailto:solin at farnamhallventures.com>


>>>
>>>
>>>
>>>> On Sep 9, 2015, at 12:29 PM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL<mailto:jack.vanderpol at NAVY.MIL>> wrote:
>>>>
>>>> We are adding support for XCCDF Tailoring and are attempting to make the results transparent so anyone parsing the resulting ARF/XCCDF XML results would be aware that the original content was not performed. We have been able to indicate that a tailoring profile was used, but are not sure as to how best to show which rules/values were used.
>>>>
>>>>
>>>>
>>>> We currently have added the following to the XCCDF Tailoring XML file (not sure if any of these except the _tailoring as part of #2 below are "required", we are just trying to force the user to document who created the tailoring file and why etc...)
>>>>
>>>>
>>>>
>>>> 1. Added _tailored to the profile id
>>>>
>>>> 2. Added XCCDF_<User Org>_tailoring to the Tailoring ID
>>>>
>>>> 3. Added the following metadata to the Tailoring XML file
>>>>
>>>> a. Creator
>>>> b. Description
>>>> c. Version
>>>> d. Status
>>>>
>>>>
>>>>
>>>> And we are indicating in the XCCDF TestResult that a tailoring file was used and that a tailored profile was used, however, if a ARF/XCCDF results consumer does not have the matching source XCCDF Tailoring file with the results, it's far from clear what was actually performed, who created the tailoring file, or why.
>>>>
>>>>
>>>>
>>>> How do you document which XCCDF rules were performed and which values/refine-values were modified when an XCCDF tailoring file is used?
>>>>
>>>>
>>>>
>>>> Do you:
>>>>
>>>> a. Include the XCCDF Tailoring profile as an additional profile as part of the source portion of the XCCDF results?
>>>>
>>>> b. Include the XCCDF Tailoring XML file as part of the ARF results?
>>>>
>>>> c. Other??
>>>>
>>>>
>>>>
>>>> Sincerely,
>>>>
>>>>
>>>>
>>>> Jack Vander Pol
>>>>
>>>> _______________________________________________
>>>> scap-dev mailing list

>>>> scap...@list.nist.gov<mailto:scap...@list.nist.gov>
>>>> To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov<mailto:scap-dev-unsubscribe at nist.gov>.
>>
>>
>> _______________________________________________
>> scap-dev mailing list
>> scap...@list.nist.gov<mailto:scap...@list.nist.gov>
>> To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov<mailto:scap-dev-unsubscribe at nist.gov>.
> <scap_gov.nist_datastream_USGCB-Windows-7-Energy-2.0.5.1.zip_tailoring.txt>


_______________________________________________
scap-dev mailing list
scap...@list.nist.gov<mailto:scap...@list.nist.gov>
To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov<mailto:scap-dev-unsubscribe at nist.gov>.

_______________________________________________
scap-dev mailing list
scap...@list.nist.gov<mailto:scap...@list.nist.gov>
To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov<mailto:scap-dev-unsubscribe at nist.gov>.

Fredericks, James

unread,
Sep 10, 2015, 12:06:24 PM9/10/15
to scap...@list.nist.gov
Please remove me as well.

Thank You,

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Hanner, Walter L
Sent: Thursday, September 10, 2015 12:04 PM
To: elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Ditto.

Randy

Jack Vander Pol

Hi Jack,

---

________________________________
The sender believes that this E-mail and any attachments were free of any
virus, worm, Trojan horse, and/or malicious code when sent. This message and
its attachments could have been infected during transmission. By reading the
message and opening any attachments, the recipient accepts full
responsibility for taking protective and remedial action about viruses and
other defects. The sender's employer is not liable for any loss or damage
arising in any way from this message or its attachments.

---

Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

unread,
Sep 10, 2015, 12:08:18 PM9/10/15
to scap...@list.nist.gov
Walter, Randall, Elmer, etc...

If you are not interested in discussions on SCAP (XCCDF/ARF/etc..), you can unsubscribe from this list at any time by following the instructions at

http://scap.nist.gov/community.html

Sincerely,
Jack Vander Pol

________________________________
From: Hanner, Walter L [walter.l.hanner at lmco.com]
Sent: Thursday, September 10, 2015 12:03 PM
To: elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: RE: EXTERNAL: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

John Fox

unread,
Sep 10, 2015, 12:08:45 PM9/10/15
to scap...@list.nist.gov
Please remove me as well.

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Fredericks, James
Sent: Thursday, September 10, 2015 12:06 PM
To: Hanner, Walter L; elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well.

Thank You,

Ditto.

Randy

Jack Vander Pol

Hi Jack,

---

---

DISCLAIMER:
This e-mail is intended for the use of the addressee(s) only and may contain privileged, confidential, or proprietary information that is
exempt from disclosure under law. If you are not the intended recipient, please do not read, copy, use or disclose the contents of this
communication to others. Please notify the sender that you have received this e-mail in error by replying to the e-mail. Please then
delete the e-mail and destroy any copies of it. Thank you.

Russell, Edward D.

unread,
Sep 10, 2015, 12:10:25 PM9/10/15
to scap...@list.nist.gov
Please remove me as well.


Ed

Johns Hopkins University Applied Physics Lab
LA Office Lead
Thinking is underrated?
ed.russell at jhuapl.edu<mailto:ed.russell at jhuapl.edu>
(310) 426 2208 desk
(240) 461 7849 cell

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of John Fox
Sent: Thursday, September 10, 2015 9:09 AM
To: Fredericks, James; Hanner, Walter L; elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well.

Pifer, Gary L.

unread,
Sep 10, 2015, 12:11:20 PM9/10/15
to scap...@list.nist.gov
Please remove me as well.

Thank You,
Gary

[http://hselaw.com/HSEblock-sm180.bmp]
Gary L. Pifer, Network Engineer
Harter Secrest & Emery LLP, Attorneys and Counselors
1600 Bausch & Lomb Place, Rochester, NY 14604-2711
Firm 585.232.6500 Direct 585.231.1301
Fax 585.232.2152 GPifer at hselaw.com<mailto:GPifer at hselaw.com>

www.hselaw.com<http://www.hselaw.com/>


This e-mail message is from a law firm and may contain information that is privileged or confidential. It is not intended for transmission to, or receipt by, any unauthorized persons. If you have received this electronic mail transmission in error, do not read it. Please delete it from your system without copying it, and notify the sender by reply e-mail at GPifer at hselaw.com or by calling 585.231.1301, so that our address record can be corrected.

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of John Fox
Sent: Thursday, September 10, 2015 12:09 PM
To: Fredericks, James; Hanner, Walter L; elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well.

Felipe Siqueira

unread,
Sep 10, 2015, 12:15:31 PM9/10/15
to scap...@list.nist.gov
You'd think that the people asking to be removed because of the "spam" scenario would do a reply instead of reply all, so that they don't contribute to the "spam" situation, but nope!

Felipe Siqueira | IT Specialist


-----Original Message-----
From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Sent: Thursday, September 10, 2015 12:08 PM
To: scap...@list.nist.gov

Walter, Randall, Elmer, etc...

http://scap.nist.gov/community.html

Sincerely,
Jack Vander Pol

Ditto.

Randy

Jack Vander Pol

Hi Jack,

To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov.

Boucher P (Pierre)@Aera

unread,
Sep 10, 2015, 12:49:16 PM9/10/15
to scap...@list.nist.gov
Me as well,

Thanks,
Pierre

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Pifer, Gary L.
Sent: Thursday, September 10, 2015 9:11 AM
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well.

Thank You,
Gary


[http://hselaw.com/HSEblock-sm180.bmp]

Gary L. Pifer, Network Engineer

Harter Secrest & Emery LLP, Attorneys and Counselors

1600 Bausch & Lomb Place, Rochester, NY 14604-2711

Firm 585.232.6500 Direct 585.231.1301

Fax 585.232.2152 GPifer at hselaw.com<mailto:GPifer at hselaw.com>


www.hselaw.com<http://www.hselaw.com/>

This e-mail message is from a law firm and may contain information that is privileged or confidential. It is not intended for transmission to, or receipt by, any unauthorized persons. If you have received this electronic mail transmission in error, do not read it. Please delete it from your system without copying it, and notify the sender by reply e-mail at GPifer at hselaw.com<mailto:GPifer at hselaw.com> or by calling 585.231.1301, so that our address record can be corrected.

Ross, Rodney *

unread,
Sep 10, 2015, 12:49:25 PM9/10/15
to scap...@list.nist.gov
Notifications and Discussions are two different things. The listsrv served its purpose - put the word out to a lot of people to get input or inform them of an issue. Once the contact is made, I think the appropriate thing would be to take the conversation offline (by taking scap...@list.nist.gov out of the address list) and keep it between your personal or work email accounts.

2?

Ricardo Silva

unread,
Sep 10, 2015, 12:50:17 PM9/10/15
to scap...@list.nist.gov
Please remove me as well.

Thank You,


Ricardo Silva
ricardo.silva at alatur.com<mailto:ricardo.silva at alatur.com>
Infraestrutura de Tecnologia
Alatur JTB
Tel. Direto: 55 11 3217-6322
Tel.: 55 11 3217-6156 | Celular.: 55 11 97421-5925
Atendimento Emergencial: 55 11 3217-6322


[http://www3.alatur.com/a/14/l_alaturjtb.jpg][http://www3.alatur.com/a/14/s_alaturjtb.jpg]<http://click.alatur.com/url/redirecionar/5/5feac1dd50280baf80342c789e728bb4.phtml>

[http://www3.alatur.com/a/p/lkd.jpg]<http://click.alatur.com/url/redirecionar/6/5feac1dd50280baf80342c789e728bb4.phtml> [http://www3.alatur.com/a/p/ytb.jpg] <http://click.alatur.com/url/redirecionar/7/5feac1dd50280baf80342c789e728bb4.phtml> [http://www3.alatur.com/a/p/titt.jpg] <http://click.alatur.com/url/redirecionar/8/5feac1dd50280baf80342c789e728bb4.phtml> [http://www3.alatur.com/a/p/fcb.jpg] <http://click.alatur.com/url/redirecionar/9/5feac1dd50280baf80342c789e728bb4.phtml>


[http://www3.alatur.com/a/15/Banner_Ass_Sphera2.jpg]<http://click.alatur.com/url/redirecionar/23/5feac1dd50280baf80342c789e728bb4.phtml>

*Consulte nossos termos e condi??es.<http://click.alatur.com/url/redirecionar/10/5feac1dd50280baf80342c789e728bb4.phtml>


De: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] Em nome de John Fox
Enviada em: quinta-feira, 10 de setembro de 2015 13:09
Para: Fredericks, James <James.Fredericks at avisbudget.com>; Hanner, Walter L <walter.l.hanner at lmco.com>; elmer.espinosa <elmer.espinosa at juramas.com>; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP <randall.benefield.1.ctr at us.af.mil>; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at navy.mil>; David Solin <solin at farnamhallventures.com>
Cc: scap...@list.nist.gov
Assunto: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well.

image001.jpg
image002.jpg
image003.jpg
image004.jpg
image005.jpg
image006.jpg
image007.jpg

Rupadia Dharmesh

unread,
Sep 10, 2015, 12:53:39 PM9/10/15
to scap...@list.nist.gov
Please remove me as well.

Thanks
Dharmesh Rupadia

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Ricardo Silva
Sent: Thursday, September 10, 2015 12:50 PM
To: John Fox <foxj at mscdirect.com>; Fredericks, James <James.Fredericks at avisbudget.com>; Hanner, Walter L <walter.l.hanner at lmco.com>; elmer.espinosa <elmer.espinosa at juramas.com>; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP <randall.benefield.1.ctr at us.af.mil>; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at navy.mil>; David Solin <solin at farnamhallventures.com>
Cc: scap...@list.nist.gov
Subject: [scap-dev] RES: EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well.

Thank You,


Ricardo Silva
ricardo.silva at alatur.com<mailto:ricardo.silva at alatur.com>
Infraestrutura de Tecnologia
Alatur JTB
Tel. Direto: 55 11 3217-6322
Tel.: 55 11 3217-6156 | Celular.: 55 11 97421-5925
Atendimento Emergencial: 55 11 3217-6322


[http://www3.alatur.com/a/15/Banner_Ass_Sphera2.jpg]<http://click.alatur.com/url/redirecionar/23/5feac1dd50280baf80342c789e728bb4.phtml>

image001.jpg
image002.jpg
image003.jpg
image004.jpg
image005.jpg
image006.jpg
image007.jpg

Paul Duke

unread,
Sep 10, 2015, 6:27:43 PM9/10/15
to scap...@list.nist.gov
And me

Paul Duke

cid:image001.jpg at 01C9DAB5.8F2915E0

New business development

Strategic Consulting Partnerships Pty Limited (SCP)

your innovation partner

p: 0409 980 944

w: <http://www.scpaustralia.com/> http://www.scpaustralia.com

NOTICE: The information contained in this electronic message is privileged and confidential, and is intended only for use of the addressee. If you are not the intended recipient, you are hereby notified that any disclosure, reproduction, distribution or other use of this communication is strictly prohibited. If you have received this communication in error, please notify the sender by reply transmission and delete the message without copying or disclosing it.

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Fredericks, James
Sent: Friday, 11 September 2015 2:06 AM
To: Hanner, Walter L; elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well.

Thank You,

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Hanner, Walter L
Sent: Thursday, September 10, 2015 12:04 PM
To: elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Ditto.

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of elmer.espinosa
Sent: Thursday, September 10, 2015 11:01 AM
To: BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov
Subject: EXTERNAL: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Remove me from the loop

-------- Original message --------

From: "BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP"

Date:09/10/2015 11:56 PM (GMT+08:00)

To: "Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600" , David Solin

Cc: scap...@list.nist.gov

Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Curious, why am I getting all these emails for this subject?

Randy

Randall Benefield, CISSP, Security+, Network+, A+
Security Control Assessor
743d ISS/SCPA (IPSecure Contractor)
Comm 210-977-6986/DSN 969-6986
NIPR: randall.benefield.1.ctr at us.af.mil

SIPR: randall.benefield.ctr at lackland.af.smil.mil


-----Original Message-----
From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Sent: Thursday, September 10, 2015 10:51 AM
To: David Solin
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Thanks David, that was helpful, and hoping it was to anyone else going down this path.

Jack Vander Pol

________________________________
From: David Solin [solin at farnamhallventures.com]
Sent: Thursday, September 10, 2015 11:32 AM
To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Cc: scap...@list.nist.gov

Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Hi Jack,

I've attached a sample. I guess I forgot to mention that we add the tailoring to the datastream.

I'm not entirely happy with the attached result because we should also add the tailoring to the datastream's catalog, and fix the value of the TestResult/tailoring-file at href to refer to the component ID. But it illustrates more or less how we interpreted tailorings should be addressed within an ARF.

Best regards,
-David Solin
Co-Founder, Research & Technology
solin at jovalcm.com

> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>
> Sure... Hook me up with a tailoring file and I'll run it! :)
>
> Sent from my iPhone
>

>> On Sep 10, 2015, at 9:13 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at navy.mil> wrote:
>>
>> Thanks again David, I suspect our group isn't the developers that are researching XCCDF Tailoring. Would you mind sending out sample XCCDF TestResult (imbedded in the email to prevent being stripped from annoying antivirus software...) of something small like the USGCB Win7 Energy without tailoring, and then after tailoring? I think seeing it would help all involved.
>>
>>
>>
>> Jack Vander Pol
>>
>> ________________________________

>> From: scap-dev-bounces at nist.gov [scap-dev-bounces at nist.gov] on behalf of David Solin [solin at farnamhallventures.com]


>> Sent: Thursday, September 10, 2015 8:45 AM
>> To: scap...@list.nist.gov

>> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>>
>> Hi Jack,
>>
>> The TestResults will results themselves contain the set-values and set-complex-values in addition to the rule results (including, e.g., NOT SELECTED) - I thought that would be quite sufficient to illustrate the functional result of the tailoring. A tailoring can have multiple profiles (each with their own IDs) and I only mean the selected tailoring profile should be reflected by the value of TestResult/profile at idref.
>>
>> Adding a tailoring in this way should appear no more mysterious, from a results analysis perspective, than selecting any profile in the original XCCDF benchmark.
>>
>> Best regards,
>> -David A. Solin
>> Co-Founder, Research & Technology
>> solin at jovalcm.com
>>
>>
>>
>>> On Sep 10, 2015, at 8:29 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL> wrote:
>>>
>>> David,
>>>
>>>
>>>
>>> Thanks for the response, we also use the tailoring-file child element to list the tailoring file, and plan to use the metadata fields to explain why tailoring was used, but are you including which rules and values & refine-values were actually used in the scan? The rules you can infer from which pass & failed, but what was modified in the values and refine-values appears to be opaque at best.
>>>
>>>
>>>
>>> When you say the profile at idref<mailto:profile at idref> will match the TestResult/tailoring-files Profile ID, are you including the Tailoring profile the results in some way?
>>>
>>>
>>>
>>> Thanks
>>>
>>> Jack Vander Pol
>>>
>>>
>>>
>>>
>>>
>>> ________________________________
>>> From: David Solin [solin at farnamhallventures.com]
>>> Sent: Wednesday, September 09, 2015 10:56 PM
>>> To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
>>> Cc: scap...@list.nist.gov

>>>> To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov.


>>
>>
>> _______________________________________________
>> scap-dev mailing list
>> scap...@list.nist.gov

>> To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov.
> <scap_gov.nist_datastream_USGCB-Windows-7-Energy-2.0.5.1.zip_tailoring.txt>


_______________________________________________
scap-dev mailing list
scap...@list.nist.gov

To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov.

_______________________________________________
scap-dev mailing list
scap...@list.nist.gov

To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov.


---

not available

Luigi Tassistro

unread,
Sep 10, 2015, 6:44:04 PM9/10/15
to scap...@list.nist.gov
Me too.

Karen Sherman

unread,
Sep 10, 2015, 6:46:46 PM9/10/15
to scap...@list.nist.gov
Please remove me as well

From: Paul Duke <pauld at scpaustralia.com>

To:"'Fredericks, James'" <James.Fredericks at avisbudget.com>, "'Hanner, WalterL'" <walter.l.hanner at lmco.com>, "'elmer.espinosa'" <elmer.espinosa at juramas.com>, "'BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743ISS/SCP'" <randall.benefield.1.ctr at us.af.mil>, "'Vander Pol, Jack R CIVSPAWARSYSCEN-ATLANTIC, 58600'" <jack.vanderpol at navy.mil>, "'David Solin'" <solin at farnamhallventures.com>
CC:<scap...@list.nist.gov>
Date: 9/10/2015 12:28 PM
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

And me

Paul Duke

New business development
Strategic Consulting Partnerships Pty Limited (SCP)
your innovation partner
p: 0409 980 944

w: http://www.scpaustralia.com

Randy

Jack Vander Pol

Hi Jack,

---

not available

Jimenez, Kevin (ITIO AOS Compliance & Risk Management)

unread,
Sep 10, 2015, 6:49:53 PM9/10/15
to scap...@list.nist.gov
For your information, no need to reply all..

To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov

From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of Karen Sherman
Sent: Thursday, September 10, 2015 4:47 PM
To: 'David Solin'; 'elmer.espinosa'; Jack R CIVSPAWARSYSCEN-ATLANTIC 58600' 'Vander Pol; James' 'Fredericks; Paul Duke; RANDALL S CTR USAF ACC 25 AF/743ISS/SCP' 'BENEFIELD; WalterL' 'Hanner
Cc: scap...@list.nist.gov
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well
From:

Paul Duke <pauld at scpaustralia.com<mailto:pauld at scpaustralia.com>>

To:

"'Fredericks, James'" <James.Fredericks at avisbudget.com<mailto:James.Fredericks at avisbudget.com>>, "'Hanner, WalterL'" <walter.l.hanner at lmco.com<mailto:walter.l.hanner at lmco.com>>, "'elmer.espinosa'" <elmer.espinosa at juramas.com<mailto:elmer.espinosa at juramas.com>>, "'BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743ISS/SCP'" <randall.benefield.1.ctr at us.af.mil<mailto:randall.benefield.1.ctr at us.af.mil>>, "'Vander Pol, Jack R CIVSPAWARSYSCEN-ATLANTIC, 58600'" <jack.vanderpol at navy.mil<mailto:jack.vanderpol at navy.mil>>, "'David Solin'" <solin at farnamhallventures.com<mailto:solin at farnamhallventures.com>>

CC:

<scap...@list.nist.gov<mailto:scap...@list.nist.gov>>

Date:

9/10/2015 12:28 PM

Subject:

Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

And me

Paul Duke
[cid:image001.jpg at 01C9DAB5.8F2915E0]


New business development
Strategic Consulting Partnerships Pty Limited (SCP)
your innovation partner
p: 0409 980 944

w: http://www.scpaustralia.com<http://www.scpaustralia.com/>


NOTICE: The information contained in this electronic message is privileged and confidential, and is intended only for use of the addressee. If you are not the intended recipient, you are hereby notified that any disclosure, reproduction, distribution or other use of this communication is strictly prohibited. If you have received this communication in error, please notify the sender by reply transmission and delete the message without copying or disclosing it.

From: scap-dev-bounces at nist.gov<mailto:scap-dev-bounces at nist.gov> [mailto:scap-dev-bounces at nist.gov] On Behalf Of Fredericks, James
Sent: Friday, 11 September 2015 2:06 AM
To: Hanner, Walter L; elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Please remove me as well.

Thank You,

From: scap-dev-bounces at nist.gov<mailto:scap-dev-bounces at nist.gov> [mailto:scap-dev-bounces at nist.gov] On Behalf Of Hanner, Walter L
Sent: Thursday, September 10, 2015 12:04 PM
To: elmer.espinosa; BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>
Subject: Re: [scap-dev] EXTERNAL: Re: Questions on tracibility with XCCDF Tailoring

Ditto.

From: scap-dev-bounces at nist.gov<mailto:scap-dev-bounces at nist.gov> [mailto:scap-dev-bounces at nist.gov] On Behalf Of elmer.espinosa
Sent: Thursday, September 10, 2015 11:01 AM
To: BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; David Solin
Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>
Subject: EXTERNAL: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Remove me from the loop
-------- Original message --------
From: "BENEFIELD, RANDALL S CTR USAF ACC 25 AF/743 ISS/SCP"
Date:09/10/2015 11:56 PM (GMT+08:00)
To: "Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600" , David Solin
Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Curious, why am I getting all these emails for this subject?

Randy

Randall Benefield, CISSP, Security+, Network+, A+
Security Control Assessor
743d ISS/SCPA (IPSecure Contractor)
Comm 210-977-6986/DSN 969-6986

NIPR: randall.benefield.1.ctr at us.af.mil<mailto:randall.benefield.1.ctr at us.af.mil>
SIPR: randall.benefield.ctr at lackland.af.smil.mil<mailto:randall.benefield.ctr at lackland.af.smil.mil>


-----Original Message-----
From: scap-dev-bounces at nist.gov<mailto:scap-dev-bounces at nist.gov> [mailto:scap-dev-bounces at nist.gov] On Behalf Of Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Sent: Thursday, September 10, 2015 10:51 AM
To: David Solin
Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Thanks David, that was helpful, and hoping it was to anyone else going down this path.

Jack Vander Pol

________________________________
From: David Solin [solin at farnamhallventures.com]
Sent: Thursday, September 10, 2015 11:32 AM
To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>


Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Hi Jack,

I've attached a sample. I guess I forgot to mention that we add the tailoring to the datastream.

I'm not entirely happy with the attached result because we should also add the tailoring to the datastream's catalog, and fix the value of the TestResult/tailoring-file at href to refer to the component ID. But it illustrates more or less how we interpreted tailorings should be addressed within an ARF.

Best regards,
-David Solin
Co-Founder, Research & Technology

solin at jovalcm.com<mailto:solin at jovalcm.com>

> Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>


> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>
> Sure... Hook me up with a tailoring file and I'll run it! :)
>
> Sent from my iPhone
>

>> On Sep 10, 2015, at 9:13 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at navy.mil<mailto:jack.vanderpol at navy.mil>> wrote:
>>
>> Thanks again David, I suspect our group isn't the developers that are researching XCCDF Tailoring. Would you mind sending out sample XCCDF TestResult (imbedded in the email to prevent being stripped from annoying antivirus software...) of something small like the USGCB Win7 Energy without tailoring, and then after tailoring? I think seeing it would help all involved.
>>
>>
>>
>> Jack Vander Pol
>>
>> ________________________________

>> From: scap-dev-bounces at nist.gov<mailto:scap-dev-bounces at nist.gov> [scap-dev-bounces at nist.gov] on behalf of David Solin [solin at farnamhallventures.com]


>> Sent: Thursday, September 10, 2015 8:45 AM

>> To: scap...@list.nist.gov<mailto:scap...@list.nist.gov>


>> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>>
>> Hi Jack,
>>
>> The TestResults will results themselves contain the set-values and set-complex-values in addition to the rule results (including, e.g., NOT SELECTED) - I thought that would be quite sufficient to illustrate the functional result of the tailoring. A tailoring can have multiple profiles (each with their own IDs) and I only mean the selected tailoring profile should be reflected by the value of TestResult/profile at idref.
>>
>> Adding a tailoring in this way should appear no more mysterious, from a results analysis perspective, than selecting any profile in the original XCCDF benchmark.
>>
>> Best regards,
>> -David A. Solin
>> Co-Founder, Research & Technology

>> solin at jovalcm.com<mailto:solin at jovalcm.com>


>>
>>
>>
>>> On Sep 10, 2015, at 8:29 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL<mailto:jack.vanderpol at NAVY.MIL>> wrote:
>>>
>>> David,
>>>
>>>
>>>
>>> Thanks for the response, we also use the tailoring-file child element to list the tailoring file, and plan to use the metadata fields to explain why tailoring was used, but are you including which rules and values & refine-values were actually used in the scan? The rules you can infer from which pass & failed, but what was modified in the values and refine-values appears to be opaque at best.
>>>
>>>
>>>
>>> When you say the profile at idref<mailto:profile at idref> will match the TestResult/tailoring-files Profile ID, are you including the Tailoring profile the results in some way?
>>>
>>>
>>>
>>> Thanks
>>>
>>> Jack Vander Pol
>>>
>>>
>>>
>>>
>>>
>>> ________________________________
>>> From: David Solin [solin at farnamhallventures.com]
>>> Sent: Wednesday, September 09, 2015 10:56 PM
>>> To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

>>> Cc: scap...@list.nist.gov<mailto:scap...@list.nist.gov>


>>> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>>>
>>> Hi Jack,
>>>
>>> The XCCDF TestResult element can have a tailoring-file child element; we put the tailoring there (there are also href, id, version and time attributes already there to describe the origin of the tailoring). The TestResult/profile at idref will match the TestResult/tailoring-file's profile ID. And, of course, the TestResult is included in the ARF, as expected.
>>>
>>> Best regards,
>>> -David Solin

>>> solin at farnamhallventures.com<mailto:solin at farnamhallventures.com>


>>>
>>>
>>>
>>>> On Sep 9, 2015, at 12:29 PM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL<mailto:jack.vanderpol at NAVY.MIL>> wrote:
>>>>
>>>> We are adding support for XCCDF Tailoring and are attempting to make the results transparent so anyone parsing the resulting ARF/XCCDF XML results would be aware that the original content was not performed. We have been able to indicate that a tailoring profile was used, but are not sure as to how best to show which rules/values were used.
>>>>
>>>>
>>>>
>>>> We currently have added the following to the XCCDF Tailoring XML file (not sure if any of these except the _tailoring as part of #2 below are "required", we are just trying to force the user to document who created the tailoring file and why etc...)
>>>>
>>>>
>>>>
>>>> 1. Added _tailored to the profile id
>>>>
>>>> 2. Added XCCDF_<User Org>_tailoring to the Tailoring ID
>>>>
>>>> 3. Added the following metadata to the Tailoring XML file
>>>>
>>>> a. Creator
>>>> b. Description
>>>> c. Version
>>>> d. Status
>>>>
>>>>
>>>>
>>>> And we are indicating in the XCCDF TestResult that a tailoring file was used and that a tailored profile was used, however, if a ARF/XCCDF results consumer does not have the matching source XCCDF Tailoring file with the results, it's far from clear what was actually performed, who created the tailoring file, or why.
>>>>
>>>>
>>>>
>>>> How do you document which XCCDF rules were performed and which values/refine-values were modified when an XCCDF tailoring file is used?
>>>>
>>>>
>>>>
>>>> Do you:
>>>>
>>>> a. Include the XCCDF Tailoring profile as an additional profile as part of the source portion of the XCCDF results?
>>>>
>>>> b. Include the XCCDF Tailoring XML file as part of the ARF results?
>>>>
>>>> c. Other??
>>>>
>>>>
>>>>
>>>> Sincerely,
>>>>
>>>>
>>>>
>>>> Jack Vander Pol
>>>>
>>>> _______________________________________________
>>>> scap-dev mailing list

>>>> scap...@list.nist.gov<mailto:scap...@list.nist.gov>
>>>> To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov<mailto:scap-dev-unsubscribe at nist.gov>.
>>
>>

>> _______________________________________________
>> scap-dev mailing list


>> scap...@list.nist.gov<mailto:scap...@list.nist.gov>
>> To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov<mailto:scap-dev-unsubscribe at nist.gov>.

> <scap_gov.nist_datastream_USGCB-Windows-7-Energy-2.0.5.1.zip_tailoring.txt>


_______________________________________________
scap-dev mailing list


scap...@list.nist.gov<mailto:scap...@list.nist.gov>
To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov<mailto:scap-dev-unsubscribe at nist.gov>.

_______________________________________________
scap-dev mailing list


scap...@list.nist.gov<mailto:scap...@list.nist.gov>
To unsubscribe, send an email message to scap-dev-unsubscribe at nist.gov<mailto:scap-dev-unsubscribe at nist.gov>.

---

________________________________

image001.jpg

David Solin

unread,
Nov 10, 2015, 10:55:39 PM11/10/15
to scap...@list.nist.gov
Hi Jack,

Back on the subject of inserting a tailoring into an ARF? Are you going to use a similar approach to ours, of adding the tailoring to the datastream in the ARF?s report-request?

If so, I?m trying to decide where it makes the most sense to put the component reference and catalog cross-reference. I?m thinking that a tailoring should get its own datastream/checklists/component-ref, because a checklist (XCCDF benchmark) is the most closely related thing to a tailoring, and there?s no specific place to put tailoring references in a datastream.

Then, the TestResult/tailoring-file at href attribute value can reference the value of the component-ref/catalog/cat:uri at name attribute.

So, given an example:

<ds:checklists>
<ds:component-ref id=?scap_org.joval_cref_MyBenchmark.xml? xlink:href=?#scap_org.joval_comp_MyBenchmark.xml? />
<ds:component-ref id=?scap_org.joval_cref_MyTailoring.xml? xlink:href=?#scap_org.joval_comp_MyTailoring.xml">
<cat:catalog>
<cat:uri name=?MyTailoring.xml? uri=?#scap_org.joval_cref_MyTailoring.xml"/>
</cat:catalog>
</ds:component-ref>
</ds:checklists>

The tailoring would be located in a component with id=?scap_org.joval_comp_MyTailoring.xml?, and the tailoring-file would have an @href value of ?MyTailoring.xml?.

WDYT? The specification doesn?t seem to offer any guidance.

Best regards,
?David A. Solin
Co-Founder, Research & Technology
solin at jovalcm.com

David Solin

unread,
Nov 10, 2015, 11:19:25 PM11/10/15
to scap...@list.nist.gov
Hi Jack,

Back on the subject of inserting a tailoring into an ARF? Are you going to use a similar approach to ours, of adding the tailoring to the datastream in the ARF?s report-request?

If so, I?m trying to decide where it makes the most sense to put the component reference and catalog cross-reference. I?m thinking that a tailoring should get its own datastream/checklists/component-ref, because a checklist (XCCDF benchmark) is the most closely related thing to a tailoring, and there?s no specific place to put tailoring references in a datastream.

Then, the TestResult/tailoring-file at href attribute value can reference the value of the component-ref/catalog/cat:uri at name attribute.

So, given an example:

<ds:checklists>
<ds:component-ref id=?scap_org.joval_cref_MyBenchmark.xml? xlink:href=?#scap_org.joval_comp_MyBenchmark.xml? />
<ds:component-ref id=?scap_org.joval_cref_MyTailoring.xml? xlink:href=?#scap_org.joval_comp_MyTailoring.xml">
<cat:catalog>
<cat:uri name=?MyTailoring.xml? uri=?#scap_org.joval_cref_MyTailoring.xml"/>
</cat:catalog>
</ds:component-ref>
</ds:checklists>

The tailoring would be located in a component with id=?scap_org.joval_comp_MyTailoring.xml?, and the tailoring-file would have an @href value of ?MyTailoring.xml?.

WDYT? The specification doesn?t seem to offer any guidance.

Best regards,
?David A. Solin


David Solin
solin at farnamhallventures.com

Waltermire, David A.

unread,
Nov 12, 2015, 8:16:30 AM11/12/15
to scap...@list.nist.gov
This sounds like a reasonable approach. If there is consensus on the approach, we will work to clarify this in the SCAP 1.3 release.

Any other thoughts on how to handle tailoring in ARF results?

Dave

-----Original Message-----
From: scap-dev-bounces at nist.gov [mailto:scap-dev-bounces at nist.gov] On Behalf Of David Solin
Sent: Tuesday, November 10, 2015 10:56 PM
To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at navy.mil>
Cc: SCAP-DEV <SCAP-DEV at nist.gov>
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Hi Jack,

Back on the subject of inserting a tailoring into an ARF... Are you going to use a similar approach to ours, of adding the tailoring to the datastream in the ARF's report-request?

If so, I'm trying to decide where it makes the most sense to put the component reference and catalog cross-reference. I'm thinking that a tailoring should get its own datastream/checklists/component-ref, because a checklist (XCCDF benchmark) is the most closely related thing to a tailoring, and there's no specific place to put tailoring references in a datastream.

Then, the TestResult/tailoring-file at href attribute value can reference the value of the component-ref/catalog/cat:uri at name attribute.

So, given an example:

<ds:checklists>
<ds:component-ref id="scap_org.joval_cref_MyBenchmark.xml" xlink:href="#scap_org.joval_comp_MyBenchmark.xml" />
<ds:component-ref id="scap_org.joval_cref_MyTailoring.xml" xlink:href="#scap_org.joval_comp_MyTailoring.xml">
<cat:catalog>
<cat:uri name="MyTailoring.xml" uri="#scap_org.joval_cref_MyTailoring.xml"/>


</cat:catalog>
</ds:component-ref>
</ds:checklists>

The tailoring would be located in a component with id="scap_org.joval_comp_MyTailoring.xml", and the tailoring-file would have an @href value of "MyTailoring.xml".

WDYT? The specification doesn't seem to offer any guidance.

Best regards,
-David A. Solin


Co-Founder, Research & Technology
solin at jovalcm.com

> On Sep 10, 2015, at 10:51 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL> wrote:
>
> Thanks David, that was helpful, and hoping it was to anyone else going down this path.
>
>
>
> Jack Vander Pol
>
> ________________________________
> From: David Solin [solin at farnamhallventures.com]
> Sent: Thursday, September 10, 2015 11:32 AM
> To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
> Cc: scap...@list.nist.gov
> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>
> Hi Jack,
>

> I've attached a sample. I guess I forgot to mention that we add the tailoring to the datastream.
>
> I'm not entirely happy with the attached result because we should also add the tailoring to the datastream's catalog, and fix the value of the TestResult/tailoring-file at href to refer to the component ID. But it illustrates more or less how we interpreted tailorings should be addressed within an ARF.
>
> Best regards,
> -David Solin

>>> The TestResults will results themselves contain the set-values and set-complex-values in addition to the rule results (including, e.g., NOT SELECTED) - I thought that would be quite sufficient to illustrate the functional result of the tailoring. A tailoring can have multiple profiles (each with their own IDs) and I only mean the selected tailoring profile should be reflected by the value of TestResult/profile at idref.


>>>
>>> Adding a tailoring in this way should appear no more mysterious, from a results analysis perspective, than selecting any profile in the original XCCDF benchmark.
>>>
>>> Best regards,

>>> -David A. Solin


>>> Co-Founder, Research & Technology
>>> solin at jovalcm.com
>>>
>>>
>>>
>>>> On Sep 10, 2015, at 8:29 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.vanderpol at NAVY.MIL> wrote:
>>>>
>>>> David,
>>>>
>>>>
>>>>
>>>> Thanks for the response, we also use the tailoring-file child element to list the tailoring file, and plan to use the metadata fields to explain why tailoring was used, but are you including which rules and values & refine-values were actually used in the scan? The rules you can infer from which pass & failed, but what was modified in the values and refine-values appears to be opaque at best.
>>>>
>>>>
>>>>
>>>> When you say the profile at idref<mailto:profile at idref> will match the TestResult/tailoring-files Profile ID, are you including the Tailoring profile the results in some way?
>>>>
>>>>
>>>>
>>>> Thanks
>>>>
>>>> Jack Vander Pol
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> ________________________________
>>>> From: David Solin [solin at farnamhallventures.com]
>>>> Sent: Wednesday, September 09, 2015 10:56 PM
>>>> To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
>>>> Cc: scap...@list.nist.gov
>>>> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring
>>>>
>>>> Hi Jack,
>>>>

>>>> The XCCDF TestResult element can have a tailoring-file child element; we put the tailoring there (there are also href, id, version and time attributes already there to describe the origin of the tailoring). The TestResult/profile at idref will match the TestResult/tailoring-file's profile ID. And, of course, the TestResult is included in the ARF, as expected.
>>>>
>>>> Best regards,
>>>> -David Solin

elmer.espinosa

unread,
Nov 12, 2015, 8:20:49 AM11/12/15
to scap...@list.nist.gov
How to unsubcribe to this email loop?


<div>-------- Original message --------</div><div>From: "Waltermire, David A." <david.waltermire at nist.gov> </div><div>Date:11/12/2015 9:16 PM (GMT+08:00) </div><div>To: David Solin <solin at jovalcm.com>, "Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600" <jack.vanderpol at navy.mil> </div><div>Cc: SCAP-DEV <SCAP-DEV at nist.gov> </div><div>Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring </div><div>
</div>This sounds like a reasonable approach. If there is consensus on the approach, we will work to clarify this in the SCAP 1.3 release.

David Solin

unread,
Nov 19, 2015, 5:39:13 PM11/19/15
to scap...@list.nist.gov
Hi Dave and Jack,

In the interests of complete clarity, I?m attaching an exact example of what I?ve described (how to embed an XCCDF tailoring inside an ARF).

I think this is consistent with the SCAP 1.2 specification, but alternate interpretations might also be consistent, so we should probably document it more precisely in the next version.

Best regards,
?David Solin

-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: arf.txt

Url: https://email.nist.gov/pipermail/scap-dev/attachments/20151119/585f86c0/attachment-0001.txt
-------------- next part --------------

Tanner, Douglas C CIV SPAWARSYSCEN-ATLANTIC, 58510

unread,
Nov 20, 2015, 8:20:32 AM11/20/15
to scap...@list.nist.gov
All -

This seems like a logical means of displaying the Tailoring information. If a tailoring component is included in the original data-stream, this is what you would expect to see in the ARF report. So, it makes sense that an external Tailoring file would be treated the same way for traceability purposes. There definitely needs to be better documentation on this issue.

Doug

________________________________
From: scap-dev-bounces at nist.gov [scap-dev-bounces at nist.gov] on behalf of David Solin [solin at jovalcm.com]
Sent: Thursday, November 19, 2015 5:39 PM
To: Waltermire, David A.
Cc: SCAP-DEV; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600
Subject: [Non-DoD Source] Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

Hi Dave and Jack,

In the interests of complete clarity, I?m attaching an exact example of what I?ve described (how to embed an XCCDF tailoring inside an ARF).

I think this is consistent with the SCAP 1.2 specification, but alternate interpretations might also be consistent, so we should probably document it more precisely in the next version.

Best regards,
?David Solin

> On Nov 12, 2015, at 7:16 AM, Waltermire, David A. <david.waltermire at nist.gov> wrote:

David Solin

unread,
Nov 20, 2015, 10:47:31 AM11/20/15
to scap...@list.nist.gov
I have a follow-up question?

Doug, the profile that you and Jack sent me when we began this discussion had both a <refine-value> and <set-value> for the same variable (i.e., the @idref was the same). I had to comment out the apparent conflict to get Joval to run the tailoring.

There is no schema or schematron restriction preventing this, but it seems very strange to both select a refine value, AND explicitly set the same value. If this is a valid thing to do, then, what exactly should it mean?

(Depending upon the answer, this question gives rise to a similar question about how to interpret Profile inheritance for refine-value and set-value elements.)

Best regards,
?David Solin

Tanner, Douglas C CIV SPAWARSYSCEN-ATLANTIC, 58510

unread,
Nov 20, 2015, 11:43:24 AM11/20/15
to scap...@list.nist.gov
David -

So my thinking on this was that per the XCCDF specification the refine-value is used to modify attributes or properties of a value (looking at it again I see where it states "including selection of the effective value" and set-value is used to change the actual value. Also, I believe the profile I originally took this from had only refine-values so I added the set-value for testing purposes.

Your inheritance question of refine-value vs set-value really does need to be answered then. I see in Table 33 Inheritance Processing Model of the XCCDF Specification 1.2.pdf that it appears to show you in what order they should be inherited. So in this case, ultimately the set-value would say what the actual value should be regardless of anything in the refine-value. Or did I misread that?

On a separate/related side note: What should the ARF report look like for a data-stream that references an external OVAL file? For traceability purposes, I would think it would need to do what you are proposing for XCCDF Tailoring, but the HREF for the external file will be a URL and not be a properly formatted component ID. If we simply use the Check/Component-Ref/id and replace "cref" with "comp" would work, but then it won't directly trace back the href. So what should we do in this situation?

Doug

________________________________
From: David Solin [solin at farnamhallventures.com]

Sent: Friday, November 20, 2015 10:47 AM
To: SCAP-DEV
Cc: Waltermire, David A.; Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600; Tanner, Douglas C CIV SPAWARSYSCEN-ATLANTIC, 58510
Subject: Re: [scap-dev] [Non-DoD Source] Re: Questions on tracibility with XCCDF Tailoring

Юрий Книгин

unread,
Nov 20, 2015, 11:54:16 AM11/20/15
to scap...@list.nist.gov
Please remove me from the loop.

On Fri, Nov 20, 2015 at 7:43 PM, Tanner, Douglas C CIV

David Solin

unread,
Nov 20, 2015, 5:50:44 PM11/20/15
to scap...@list.nist.gov
Hi Doug,

See below?

> On Nov 20, 2015, at 10:43 AM, Tanner, Douglas C CIV SPAWARSYSCEN-ATLANTIC, 58510 <douglas.c.tanner at NAVY.MIL> wrote:
>
> David -
>
>
>
> So my thinking on this was that per the XCCDF specification the refine-value is used to modify attributes or properties of a value (looking at it again I see where it states "including selection of the effective value" and set-value is used to change the actual value. Also, I believe the profile I originally took this from had only refine-values so I added the set-value for testing purposes.
>

That?s interesting. I think you?re right, and a set-value overrides the Value associated with a selector referenced by an active refine-value. (Gee, that?s a mouthful).

>
>
> Your inheritance question of refine-value vs set-value really does need to be answered then. I see in Table 33 Inheritance Processing Model of the XCCDF Specification 1.2.pdf that it appears to show you in what order they should be inherited. So in this case, ultimately the set-value would say what the actual value should be regardless of anything in the refine-value. Or did I misread that?
>

set-value, refine-value, etc. are all defined in that table to conform with the ?Append? model, but that?s not enough. If the ID repeats an inherited ID, for a given element type, it should probably override it.

That way, a set-value in a tailoring might override a set-value for the same variable ID in the base Profile (assuming inheritance, as in your example tailoring).

This needs to be documented, as I think it?s unclear right now.

>
>
> On a separate/related side note: What should the ARF report look like for a data-stream that references an external OVAL file? For traceability purposes, I would think it would need to do what you are proposing for XCCDF Tailoring, but the HREF for the external file will be a URL and not be a properly formatted component ID. If we simply use the Check/Component-Ref/id and replace "cref" with "comp" would work, but then it won't directly trace back the href. So what should we do in this situation?
>

For traceability purposes, there will already be a report containing the OVAL results XML for any external OVAL definitions, and the relevant rules will have hrefs indicating that report ID in the ARF. Since the OVAL results already contain the OVAL definitions, we don?t bother associating another copy with the request, and just allow the external reference to carry forward.

I believe that?s probably sufficient. WDYT?

Tanner, Douglas C CIV SPAWARSYSCEN-ATLANTIC, 58510

unread,
Dec 2, 2015, 2:25:24 PM12/2/15
to scap...@list.nist.gov
That definitely works for me.

________________________________
From: David Solin [solin at farnamhallventures.com]

Sent: Friday, November 20, 2015 5:50 PM
To: Tanner, Douglas C CIV SPAWARSYSCEN-ATLANTIC, 58510
Cc: SCAP-DEV

j...@usprotech.com

unread,
Jul 17, 2026, 11:13:24 AM (14 days ago) Jul 17
to David Solin, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600, scap...@nist.gov

Re. Critical Infrastructure:  XCC, system forensics, and rapid comparison of hashed transactions to deliver CDM on IT and OT systems in near real Time.

 

David and Jack,

 

So many years have past in our SCAP community and so many changes have taken place I'm not even sure if you would remember one of our threads from years ago.  Since then, our InfoSec DevOps teams have written a sophisticated CDM-SIEM platform that's currently deployed on critical infrastructure, mostly being used in Maritime Port Operations which what I was hoping to gain your insight upon. Currently, we're on Ver. 3.1 of Anamo.  Would it be acceptable to ask for your technical advice?  It would a pleasure to set up a conversation if you were available.

 

@ David:  I was also wondering about your advice concerning best practices for running a capital campaign.

 

Thank you,

Jonathan

 

 

Jonathan Goetsch

Sr. Cybersecurity Advisor

US ProTech, Inc.

Phone:  949-629-3900 x 225

signature_357340641

CISA on CDM Explainer Video

What is “CDM-SIEM” www.Anamo.io

 

 

 

 

 

 

-----Original Message-----
From: scap-dev...@nist.gov <scap-dev...@nist.gov> On Behalf Of David Solin
Sent: Thursday, September 10, 6:28
To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.va...@navy.mil>
Cc: scap...@nist.gov
Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

 

Sure... Hook me up with a tailoring file and I'll run it! :)

 

Sent from my iPhone

 

> On Sep 10, at 9:13 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.va...@navy.mil> wrote:

>

> Thanks again David, I suspect our group isn't the developers that are researching XCCDF Tailoring.  Would you mind sending out sample XCCDF TestResult (imbedded in the email to prevent being stripped from annoying antivirus software...) of something small like the USGCB Win7 Energy without tailoring, and then after tailoring?  I think seeing it would help all involved.

>

>

>

> Jack Vander Pol

>

> ________________________________

> From: scap-dev...@nist.gov [scap-dev...@nist.gov] on behalf of David Solin [so...@farnamhallventures.com]

> Sent: Thursday, September 10, 8:45 AM

> To: scap...@nist.gov

> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

>

> Hi Jack,

>

> The TestResults will results themselves contain the set-values and set-complex-values in addition to the rule results (including, e.g., NOT SELECTED) — I thought that would be quite sufficient to illustrate the functional result of the tailoring.  A tailoring can have multiple profiles (each with their own IDs) and I only mean the selected tailoring profile should be reflected by the value of TestResult/profile@idref.

>

> Adding a tailoring in this way should appear no more mysterious, from a results analysis perspective, than selecting any profile in the original XCCDF benchmark.

>

> Best regards,

> —David A. Solin

> Co-Founder, Research & Technology

> so...@jovalcm.com

>

>

>

>> On Sep 10, 2015, at 8:29 AM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.va...@NAVY.MIL> wrote:

>>

>> David,

>>

>>

>>

>> Thanks for the response, we also use the tailoring-file child element to list the tailoring file, and plan to use the metadata fields to explain why tailoring was used, but are you including which rules and values & refine-values were actually used in the scan?  The rules you can infer from which pass & failed, but what was modified in the values and refine-values appears to be opaque at best.

>>

>>

>>

>> When you say the profile@idref<mailto:profile@idref> will match the TestResult/tailoring-files Profile ID, are you including the Tailoring profile the results in some way?

>>

>>

>>

>> Thanks

>>

>> Jack Vander Pol

>>

>>

>>

>>

>>

>> ________________________________

>> From: David Solin [so...@farnamhallventures.com]

>> Sent: Wednesday, September 09, 10:56 PM

>> To: Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600

>> Subject: Re: [scap-dev] Questions on tracibility with XCCDF Tailoring

>>

>> Hi Jack,

>>

>> The XCCDF TestResult element can have a tailoring-file child element; we put the tailoring there (there are also href, id, version and time attributes already there to describe the origin of the tailoring).  The TestResult/profile@idref will match the TestResult/tailoring-file’s profile ID.  And, of course, the TestResult is included in the ARF, as expected.

>>

>> Best regards,

>> —David Solin

>> so...@farnamhallventures.com

>>

>>

>>

>>> On Sep 9, at 12:29 PM, Vander Pol, Jack R CIV SPAWARSYSCEN-ATLANTIC, 58600 <jack.va...@NAVY.MIL> wrote:

>>>

>>> We are adding support for XCCDF Tailoring and are attempting to make the results transparent so anyone parsing the resulting ARF/XCCDF XML results would be aware that the original content was not performed.  We have been able to indicate that a tailoring profile was used, but are not sure as to how best to show which rules/values were used.

>>>

>>>

>>>

>>> We currently have added the following to the XCCDF Tailoring XML file  (not sure if any of these except the _tailoring as part of #2 below are "required", we are just trying to force the user to document who created the tailoring file and why etc...)

>>>

>>>

>>>

>>> 1.  Added _tailored to the profile id

>>>

>>> 2.  Added  XCCDF_<User Org>_tailoring to the Tailoring ID

>>>

>>> 3.  Added the following metadata to the Tailoring XML file

>>>

>>> a.  Creator

>>> b.  Description

>>> c.  Version

>>> d.  Status

>>>

>>>

>>>

>>> And we are indicating in the XCCDF TestResult that a tailoring file was used and that a tailored profile was used, however, if a ARF/XCCDF results consumer does not have the matching source XCCDF Tailoring file with the results, it's far from clear what was actually performed, who created the tailoring file, or why.

>>>

>>>

>>>

>>> How do you document which XCCDF rules were performed and which values/refine-values were modified when an XCCDF tailoring file is used?

>>>

>>>

>>>

>>> Do you:

>>>

>>> a.  Include the XCCDF Tailoring profile as an additional profile as part of the source portion of the XCCDF results?

>>>

>>> b.  Include the XCCDF Tailoring XML file as part of the ARF results?

>>>

>>> c.  Other??

>>>

>>>

>>>

>>> Sincerely,

>>>

>>>

>>>

>>> Jack Vander Pol

>>>

>>> _______________________________________________

>>> scap-dev mailing list

>>> scap...@nist.gov

>>> To unsubscribe, send an email message to scap-dev-u...@nist.gov.

>

>

> _______________________________________________

> scap-dev mailing list

> scap...@nist.gov

> To unsubscribe, send an email message to scap-dev-u...@nist.gov.

 

_______________________________________________

scap-dev mailing list

scap...@nist.gov

To unsubscribe, send an email message to scap-dev-u...@nist.gov.

image001.png
Reply all
Reply to author
Forward
0 new messages