Installation guide

Table Of Contents
vulnerabilities
To calculate CVSS scores that apply to your unique environment, go to the CVSS scoring Web site, fill
in the form, and click the Update Scores button.
http://nvd.nist.gov/cvss.cfm?calculator&adv&version=2
This release of VCM is compatible with the SCAP 1.0 validation program and is for Windows platforms
only.
Conduct SCAP Compliance Assessments
You import a benchmark, run an SCAP assessment on the managed machines in your environment,
review the results, and have the option to export the results.
Procedure
1. "Import an SCAP Benchmark" on page 195
Add the SCAP benchmark to VCM so that you have the industry-approved set of compliance checks
against which to assess your managed machines.
2. "Run an SCAP Assessment" on page 196
Run an SCAP assessment that compares your managed machine configuration against a profile in a
standard SCAP benchmark.
3. "View SCAP Assessment Results" on page 196
Open and search SCAP assessment results through access in the data grid for the profile against which
you measured managed machines.
4. "Export an SCAP Assessment" on page 196
You can export assessment result output to HTML, XML, CSV, and log files.
Import an SCAP Benchmark
Add the SCAP benchmark to VCM so that you have the industry-approved set of compliance checks
against which to assess your managed machines.
Prerequisites
Obtain a copy of the Tier III or Tier IV benchmark bundle ZIP file that you want. The National Institute of
Standards and Technology (NIST) National Vulnerability Database (NVD) provides benchmarks for
download.
http://web.nvd.nist.gov/view/ncp/repository
Procedure
1. Copy the bundle ZIP file to the following folder.
\\machine-name\CMFiles$\SCAP\Import
2. Click Compliance.
3. Select SCAP Compliance > Benchmarks.
4. Click Import.
5. Highlight the bundle, and click the right arrow to select it for import.
6. Click Next.
7. Review your selections and click Finish.
Running and Enforcing Compliance
VMware, Inc.
195