The Security Content Automation Protocol (SCAP) is an effort by the security community, led by the National Institute of Standards and Technology ([[National Institute of Standards and Technology|NIST]]), to *create a standardised approach for communicating security-related information.* This standardisation is important to the automation of interactions between security components. The SCAP standards include the following:
- **Common Configuration Enumeration** (**CCE**) Provides a standard nomenclature for discussing system configuration issues
- **Common Platform Enumeration** (**CPE**) Provides a standard nomenclature for describing product names and versions
- **Common Vulnerabilities and Exposures** (**[[Common Vulnerabilities and Exposures|CVE]]**) Provides a standard nomenclature for describing security related software flaws
- **Common Vulnerability Scoring System** (**[[Common Vulnerability Scoring System|CVSS]]**) Provides a standardised approach for measuring and describing the severity of security-related software flaws
- **Extensible Configuration Checklist Description Format** (**XCCDF**) A language for specifying checklists and reporting checklist results
- **Open Vulnerability and Assessment Language** (**OVAL**) A language for specifying low-level testing procedures used by checklists