What is Vulnerability Assessment

Vulnerability assessment is an information security community standard to promote open and publicly available security content, and to standardize the transfer of this information across security tools and services. Also, vulnerability assessment is an XML specification for exchanging technical details on how to check systems for security-related software flaws, configuration issues, and patches. In addition, vulnerability assessment standardizes the three main steps of the assessment process: representing configuration information of systems for testing; analyzing the system for the presence of the specified machine state (vulnerability, configuration, patch state, etc.); and, reporting the results of the assessment. In this way, vulnerability assessment enables open and publicly available security content and standardizes the transfer of this content across the entire spectrum of information security tools and services. The capabilities and requirements described in this chapter have been derived from the vulnerability assessment process.