openPR Logo
Press release

atsec’s cryptographic and security testing laboratory accredited for SCAP testing by NIST

02-28-2008 12:11 PM CET | Media & Telecommunications

Press release from: atsec information security

Austin, TX – atsec information security is proud to announce the successful accreditation of its cryptographic and security testing laboratory as a SCAP (Security Content Automation Protocol) test laboratory under the NVLAP (National Voluntary Laboratory Accreditation Program) supporting the Information Security Automation Program (ISAP); a U.S. government multi-agency initiative to enable automation and standardization of technical security operations. With this addition to the atsec IT security portfolio we will be able to test our customer’s products against the SCAP standards using derived test requirements provided by the NIST Computer Security Division’s Information Security Automation Program (ISAP) supported by the National Vulnerability Database (NVD) program.

Steve Weingart, Principal Consultant at atsec commented: “SCAP is a new standard that has been created to verify security configuration and vulnerability reporting, for computing systems and software. While the initial motivation is for government users to meet Federal requirements, we expect that the usefulness of this standard will promote its acceptance in industry and education as well.”

The Security Content Automation Protocol (SCAP), pronounced “Ess-Cap”, is a method for using specific standards to enable automated vulnerability management, measurement, and policy compliance evaluation (e.g., FISMA compliance). More specifically, SCAP is a suite of open standards that: enumerates software flaws, security related configuration issues, and product names; measures systems to determine the presence of vulnerabilities; and provides mechanisms to rank (score) the results of these measurements in order to evaluate the impact of the discovered security issues. SCAP defines how these standards are used in unison to accomplish these capabilities.

SCAP includes the following standards:
• Common Vulnerabilities and Exposures (CVE®)
• Common Configuration Enumeration (CCE™)
• Common Platform Enumeration (CPE™)
• Common Vulnerability Scoring System (CVSS)
• eXtensible Configuration Checklist Description Format (XCCDF)
• Open Vulnerability and Assessment Language (OVAL™)

atsec has has longstanding experience with IT security testing, evaluation and validation of software and hardware products. We are accredited as a Common Criteria Evaluation Laboratory, Cryptographic Module Testing Laboratory for FIPS 140-2.

For more information on The Information Security Automation Program and
The Security Content Automation Protocol point your browser at http://nvd.nist.gov/scap.cfm

Media Contact:
Andreas Fabis, fabis@atsec.com
Marketing Director
atsec information security
(512) 615-7317



atsec information security corporation
9130 Jollyville Road, Suite 260
Austin, TX 78759
USA
Phone: +1-512-615-7300
Telefax: +1-512-615-7301
eMail: info@atsec.com

About atsec information security
atsec information security is an independent, standards-based information technology security services company that combines a business-oriented approach to information security with in-depth technical knowledge and global experience. atsec was founded in Munich (Germany) in 2000 and has extensive international operations with offices in the U.S., Germany, Sweden, and China.
atsec offers evaluation and testing services leading to formal certification for IT security including evaluation under Common Criteria schemes in the U.S., Germany, and Sweden; cryptographic module and algorithm testing under the Cryptographic Module Validation Program of the National Institute of Standards and Technology (NIST) in the U.S. and Communications Security Establishment Canada (CSEC) in Canada; and compliance validation to the Payment Card Industry (PCI) Data Security Standard.
atsec also offers secure code review, ISO/IEC 27001 ISMS consulting, and penetration testing and scanning services.
atsec works with leading global companies such as IBM, HP, Oracle, Cray,BMW, SGI, Vodafone, Swisscom, RWE, and Wincor-Nixdorf. For more information please visit www.atsec.com.

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release atsec’s cryptographic and security testing laboratory accredited for SCAP testing by NIST here

News-ID: 38520 • Views:

More Releases from atsec information security

atsec information security is now operating a Certification Body accredited according to ISO/IEC 17065
atsec information security is now operating a Certification Body accredited acco …
AUSTIN, TX - atsec is pleased to announce that atsec information security AB has been accredited as a certification body by SWEDAC, the national accreditation body in Sweden, to provide Common Criteria (CC) certifications of IT products. With over 20 years of experience as a CC evaluation lab, atsec has taken the step to become a CC certification body. We have an experienced and knowledgeable team, that has helped many national schemes
Call for Papers for the Second International Cryptographic Module Conference
Mark Your Calendar: ICMC 2014, November 19-21, Hilton Washington D.C., Rockville, MD ICMC brings together experts from around the world to confer on the topic of cryptographic modules, with emphasis on their secure design, implementation, assurance, and use, referencing both new and established standards such as FIPS 140-2 and ISO/IEC 19790. We are focused on attracting participants from the engineering and research community, test laboratories, government organizations, the procurers, deployers and administrators
atsec information security Opens South East Asia Office
atsec information security Opens South East Asia Office
Bangkok, Thailand – atsec information security is pleased to announce the opening of its atsec South East Asia (atsec SEA) office in Bangkok, Thailand. Since the year 2000, the atsec group of companies have been established experts in information security including Common Criteria, FIPS 140-2, PCI, ISO 27001, and hardware testing. As part of the atsec group of companies, atsec SEA’s objective is to promote information security and information assurance in
atsec completes FIPS 140-2 testing of Watchdata's WatchKey USB Token at Security Level 2
atsec completes FIPS 140-2 testing of Watchdata's WatchKey USB Token at Security …
Austin, TX - atsec information security is pleased to announce that its customer, Watchdata Technologies Pte Ltd. (branded as “Watchdata”), received a FIPS 140-2 validation certificate #1640 for the WatchKey USB Token under the CMVP (Cryptographic Module Validation Program) by the National Institute of Standards and Technology (NIST), USA and the Communication Security Establishment of Canada (CSEC). The successful validation result is published on the CMVP’s official website at: http://csrc.nist.gov/groups/STM/cmvp/validation.html The issued

All 5 Releases


More Releases for SCAP

Skin Adhesives Market Is Booming Worldwide | Scap, TESA, Nitto Denko
HTF MI recently introduced a survey analysis on Global Skin Adhesives Market. The ultimate purpose of this research study is to provide consumer goods and retail companies with the global and local insights about specific behaviours and preferences of their target audience / consumers in Skin Adhesives Industry. By providing insights on market maker i.e different customer segments, companies can tailor their business strategies for maximum success. Some of the
The evolution of energy storage reaches new heights
BATTERYCAPS from SAMWHA available with up to 70,000 farad • BATTERYCAPS as an alternative to ULTRACAPS and lithium batteries • Excellent properties for charging and discharging • SAMWHA pushes development ahead Pleidelsheim, 23rd October 2020. With the new ESD-SCAPs, the Korean manufacturer SAMWHA sets the bar high in the field of capacitor energy storage. For the first time, the hybrid capacitors known as BATTERYCAPs are available with a capacity of 70,000 farads. "With the ESD-SCAP, SAMWHA presents
HPMU, Hybrid Power Management Unit, The Portable Power Solution for Battery & Al …
Scientists and engineers at ESL have developed a solution to improve performance of alternative energy systems and extend the life cycles of typical battery systems. The HPMU, Hybrid Power Management Unit combines the strength of a high-power capacitor and a high energy battery using a power management board to integrate the two. This combined technology enables the battery system to operate at a reduced rate with the recharge
atsec information security completes the CAVP cryptographic algorithm testing fo …
Beijing, China – atsec information security is pleased to announce that the cryptographic algorithms implemented in the Watchdata-FIPS-TimeCOS Hardware Cryptographic Library were tested by atsec information security and validated under the CAVP (Cryptographic Algorithm Validation Program) by NIST (National Institute of Standards and Technology). The implemented algorithms of Watchdata-FIPS-TimeCOS Hardware Cryptographic Library and their validation numbers are as follows: TDES, CMAC (No.1057) AES (No.1616) SHA (No.1425) RSA (No.794) DRBG (No.85) More product and manufacturer information can be
atsec information security completes two GSA FIPS 201 evaluations for EK Ekcesso …
Austin, TX – atsec information security, an accredited laboratory for the GSA FIPS 201 Evaluation Program (GSA EP) which runs a product approval program for PIV-related products destined for the U.S. Government market, is proud to announce the successful GSA FIPS 201 evaluation of two EK Ekcessories, Inc. products: - Guardian (APL #502) - One Hander (APL #518) The successful evaluation of Electromagnetically Opaque Sleeves produces assurance that Federal Government PIV IDs
atsec information security completes SCAP testing for Microsoft System Center Co …
Austin, TX - atsec performed the FDCC Scanner validation testing for Microsoft System Center Configuration Manager 2007 Extensions for SCAP under the current SCAP standard. “Microsoft recognizes the importance of supporting industry standards. For our public sector and government customers, it is important to add support for SCAP-compliant reporting formats. System Center Configuration Manager 2007 provides a strong collection of core functionalities for hardware and software inventory, as well as robust