On 2/17/16 2:06 PM, Jan Lieskovsky wrote:
Hello Mike,
thank you for contacting us.
----- Original Message -----
>From: "Mike Kuhnkey"<[email protected]>
>To:[email protected]
>Sent: Monday, February 15, 2016 1:29:47 AM
>Subject: [Open-scap] Suspect Error in ssg_rhel6-ds.xml: Incorrect reference to
NIST SP 800-53r4 control category
>
>In the DataStream referred to above:
>
>line# 25738 <reference href="http://nvlpubs.nist.gov/nistubs/SpecialPub
>lications/NIST.SP.800-53r4.pdf">194</reference>;
>line# 25739 <reference href="http://iase.disa.mil/stigs/cci/Pages/index
>.aspx">194</reference>;
>
>Appears to be incorrect format for NIST SP-800-53r4 control
>category....reference format should be of type AA-N. Not NNN?
Can you clarify what those "AA-N" and "NNN" abbreviations refer to?
Or select an example from e.g.:
[1]http://linguistics.byu.edu/faculty/henrichsenl/apa/APA10.html
you would like the SSG upstream to follow when creating the references?
Feel free to file an upstream RFE with an example wrt to this:
[2]https://github.com/OpenSCAP/scap-security-guide/issues/new
A DISA CCI reference snuck into the NIST ref tag:
RHEL/6/input/xccdf/system/accounts/pam.xml:309:<ref
nist="IA-5(b),IA-5(c),194" disa="194"/>
Submitted patch upstream:
https://github.com/OpenSCAP/scap-security-guide/pull/1043
_______________________________________________
Open-scap-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/open-scap-list