Red Hat Continues to Drive Open Security Standards; OpenSCAP Receives NIST Certification

Community project certified under the National Institute of Standards and Technology’s Security Content Automation Protocol 1.2

RALEIGH, N.C. -

RALEIGH, N.C. – April 29, 2014 – Red Hat Inc. (NYSE: RHT), the world’s leading provider of open source solutions, today announced that OpenSCAP 1.0.8 has been certified by the National Institute of Standards and Technology’s (NIST) Security Content Automation Protocol (SCAP) 1.2 in the Authenticated Configuration Scanner category with the Common Vulnerabilities and Exposure (CVE) option. The new certification adds Red Hat to a short list of vendors qualified for the large, complex SCAP standard, making OpenSCAP and Red Hat driving forces in the security space.

A synthesis of interoperable specifications based on in-depth community collaboration, SCAP provides an overarching security checklist that all security vendors supporting the standard can utilize. The standard defines common operations for security scanners, providing for security content that can be written once and run correctly on another certified scanner, allowing repeatable security assessments to be done quickly and continuously for policy compliance. Created more than five years ago, OpenSCAP is Red Hat’s open source community project to address these standards.

Delivered as part of the Red Hat Enterprise Linux platform, OpenSCAP provides a library that can parse and evaluate each component of the SCAP standard. The library approach allows for the swift creation of new SCAP tools rather than spending extensive time learning existing file structure and content. OpenSCAP offers a multi-purpose tool designed to format content into documents or scan the system based on this content. DISA STIG, NIST's USGCB, and Red Hat's Security Response Team's content (as well as anything authored to SCAP standards) are all supported by OpenSCAP, and the project has also been integrated with Red Hat Satellite and a content tailoring program called scap-workbench.

Supporting Quotes
Gunnar Hellekson, chief strategist, U.S. Public Sector, Red Hat
“SCAP is a valuable tool for maintaining a secure, consistent computing environment, and it would be a shame if you could only take advantage of this open standard with expensive, proprietary tools.” We believe in open standards, and we believe in the continuous, repeatable security process SCAP makes possible. That's why we're proud to offer this certified, open source SCAP tool. OpenSCAP will make it much easier for agencies to add verifiable, repeatable scanning to their security process.”

Stephan Mueller, atsec, Team Lead
“Red Hat's development team did a great job implementing the sizable and challenging requirements from the SCAP standard for 32 bit and 64 bit Linux systems.”

Additional Resources

  • About Red Hat
  • Red Hat is the world’s leading provider of open source software solutions, using a community-powered approach to reliable and high-performing cloud, Linux, middleware, storage and virtualization technologies. Red Hat also offers award-winning support, training, and consulting services. As the connective hub in a global network of enterprises, partners, and open source communities, Red Hat helps create relevant, innovative technologies that liberate resources for growth and prepare customers for the future of IT. Learn more at http://www.redhat.com.



  • Forward-Looking Statements
  • Certain statements contained in this press release may constitute "forward-looking statements" within the meaning of the Private Securities Litigation Reform Act of 1995. Forward-looking statements provide current expectations of future events based on certain assumptions and include any statement that does not directly relate to any historical or current fact. Actual results may differ materially from those indicated by such forward-looking statements as a result of various important factors, including: risks related to delays or reductions in information technology spending; the effects of industry consolidation; the ability of the Company to compete effectively; the integration of acquisitions and the ability to market successfully acquired technologies and products; uncertainty and adverse results in litigation and related settlements; the inability to adequately protect Company intellectual property and the potential for infringement or breach of license claims of or relating to third party intellectual property; the ability to deliver and stimulate demand for new products and technological innovations on a timely basis; risks related to data and information security vulnerabilities; ineffective management of, and control over, the Company’s growth and international operations; fluctuations in exchange rates; and changes in and a dependence on key personnel, as well as other factors contained in our most recent Quarterly Report on Form 10-Q (copies of which may be accessed through the Securities and Exchange Commission’s website at http://www.sec.gov), including those found therein under the captions "Risk Factors" and "Management’s Discussion and Analysis of Financial Condition and Results of Operations". In addition to these factors, actual future performance, outcomes, and results may differ materially because of more general factors including (without limitation) general industry and market conditions and growth rates, economic and political conditions, governmental and public policy changes and the impact of natural disasters such as earthquakes and floods. The forward-looking statements included in this press release represent the Company’s views as of the date of this press release and these views could change. However, while the Company may elect to update these forward-looking statements at some point in the future, the Company specifically disclaims any obligation to do so. These forward-looking statements should not be relied upon as representing the Company’s views as of any date subsequent to the date of this press release.