usnistgov / SCAP

The repository will be used to track issues and post specifications related to the Security Automation Protocol (SCAP).
1 stars 0 forks source link

Update NIST 800-126 to make it clear that SCAP 3.0 does not support backwards compatibility to SCAP 1.x or OVAL 5.x #5

Open vanderpol opened 4 weeks ago

vanderpol commented 4 weeks ago

In order to promote more adoption of SCAP and OVAL, SCAP 3.0 going to reference OVAL 6.0, and OVAL 6.0 is intentionally not backwards compatible with OVAL 5.x, as many old/obsolete test types from 5.x have been dropped in 6.0. The goal here is not to decrease functionality of OVAL but to decrease the cost to support OVAL. Currently OVAL 5.12 development is tracking deprecating 120+ OVAL test (in addition to 20+ OVAL tests deprecated between OVAL 5.3 and 5.11), bringing the totals for planned removal in OVAL 6.0 to around 140 OVAL 5.x tests.

The OVAL tests planned for removal have either been replaced by more modern/improved tests, or have no documented usage.

Refer to OVAL-Community ticket tracking OVAL tests to be deprecated in 5.12 and removed in 6.0 https://github.com.mcas-gov.us/OVAL-Community/OVAL/issues/154