Skip to main content

Overview

OpenSCAP is the open standard for automated security compliance scanning. It evaluates your system against machine-readable SCAP (Security Content Automation Protocol) content — including CIS Benchmarks, DISA STIGs, PCI-DSS, HIPAA, and ANSSI profiles. Each scan produces detailed HTML and XML reports that map every test to a specific compliance requirement. Xloud Platform ships OpenSCAP tooling on XOS and supports fleet-wide compliance scanning via the XDeploy automation pipeline. You can forward scan reports to SIEM systems or store them as audit artifacts for regulatory reviews.
Xloud-Developed — OpenSCAP is one of three independent scanners in Xloud SIEM — Wazuh, Lynis, and OpenSCAP run in parallel across all nodes for layered compliance coverage. Results are aggregated on the Security Posture page in Monitor Center.
Prerequisites
  • openscap-scanner and scap-security-guide packages installed (pre-installed on XOS nodes)
  • Guest VMs: apt install openscap-scanner ssg-debderived on Ubuntu/Debian
  • Root access on the target system
  • Target profile selected from the SCAP Security Guide (SSG)

Available Profiles

The SCAP Security Guide ships dozens of profiles for common compliance frameworks. Key profiles for Xloud environments:
List all available profiles for your OS

Run a Compliance Scan

Identify the SCAP content file

Locate SSG content for Ubuntu 22.04

Run the scan against a profile

Scan against CIS Level 1 Server profile
The scan evaluates each rule and produces:
  • results-cis-l1.xml — machine-readable XCCDF results
  • report-cis-l1.html — human-readable HTML report

Review the HTML report

Copy the report to a location accessible from a browser:
Copy report to web-accessible path
The report shows each rule with a pass, fail, or not applicable result, linked to the compliance requirement ID and remediation guidance.
Check the score at the top of the report. A score above 80% indicates strong compliance posture for that profile.

Interpreting Results

Each rule in the HTML report maps to a specific compliance control:

Score Interpretation


Scheduled Scanning

Run scans on a weekly schedule and archive results:
/etc/cron.weekly/openscap-scan

Profile Selection Guide

Start with CIS Level 1 for all new deployments. Escalate to Level 2 or framework-specific profiles for regulated workloads.
You can create tailored profiles by extending existing SSG content using SCAP Workbench or editing the XCCDF XML directly. Custom profiles allow you to:
  • Disable rules that conflict with your application requirements
  • Add organization-specific controls
  • Override severity levels for risk-accepted findings
Store custom profiles in /etc/scap/custom-profiles/ and reference them with --profile-id in scan commands.

Next Steps

Xloud SIEM Overview

Back to the unified Xloud SIEM hub — Security Posture and Alerts dashboards

Wazuh HIDS

Complement SCAP scans with continuous real-time host intrusion detection

Lynis Auditing

Run OS security audits with hardening index scoring

Compliance Frameworks

Map SCAP results to SOC 2, ISO 27001, and HIPAA audit requirements