5.6

Table Of Contents
This release of VCM is compatible with the SCAP 1.0 validation program and is for Windows platforms
only.
Conduct SCAP Compliance Assessments
You import a benchmark, run an SCAP assessment on the managed machines in your environment,
review the results, and have the option to export the results.
Procedure
1. "Import an SCAP Benchmark" on page 172
Add the SCAP benchmark to VCM so that you have the industry-approved set of compliance checks
against which to assess your managed machines.
2. "Run an SCAP Assessment" on page 172
Run an SCAP assessment that compares your managed machine configuration against a profile in a
standard SCAP benchmark.
3. "View SCAP Assessment Results" on page 173
Open and search SCAP assessment results through access in the data grid for the profile against which
you measured managed machines.
4. "Export an SCAP Assessment" on page 173
You can export assessment result output to HTML, XML, CSV, and log files.
Import an SCAP Benchmark
Add the SCAP benchmark to VCM so that you have the industry-approved set of compliance checks
against which to assess your managed machines.
Prerequisite
Obtain a copy of the Tier III or Tier IV benchmark bundle ZIP file that you want. The National Institute of
Standards and Technology (NIST) National Vulnerability Database (NVD) provides benchmarks for
download.
http://web.nvd.nist.gov/view/ncp/repository
Procedure
1. Copy the bundle ZIP file to the following folder.
\\{machine-name}\CMFiles$\SCAP\Import
2. Click Compliance.
3. Select SCAP Compliance > Benchmarks.
4. Click Import.
5. Highlight the bundle, and click the right arrow to select it for import.
6. Click Next.
7. Review your selections and click Finish.
Run an SCAP Assessment
Run an SCAP assessment that compares your managed machine configuration against a profile in a
standard SCAP benchmark.
vCenter Configuration Manager Administration Guide
172
VMware, Inc.