National Security Agency, Central Security Service, NSA, CSS, Fort George G. Meade, Maryland 207755-6000
NSA PRESS RELEASE 24 January 2005 For further information, contact: NSA Public and Media Affairs, 301-688-6524
NSA and NIST Announce Public Availability of the Extensible Configuration Checklist Description Format (XCCDF)
The National Security Agency (NSA) and the National Institute of Standards and Technology (NIST) jointly announce the public availability of the specification for the Extensible Configuration Checklist Description Format (XCCDF). To promote the use, standardization, and sharing of effective security checklists, the NSA and NIST collaborated with representatives of private industry to develop the XCCDF specification.
The specification is vendor-neutral, flexible, and suited for a wide variety of checklist applications. The intent of the XCCDF is to provide a uniform foundation for expression of security checklists, benchmarks, and other configuration guidance, thereby fostering a more widespread application of good security practices. Such checklists can markedly reduce the vulnerability exposure of an organization when combined with well-developed guidance, accompanied with tools, and leveraged with high quality security expertise, vendor product knowledge, and operational experience.
The Cyber-Security Research and Development Act of 2002 tasked NIST to “develop and revise, as necessary, a checklist setting forth settings and option selections that minimize the security risks associated with each computer hardware or software system that is, or is likely to become, widely used within the Federal Government.” The XCCDF effort was born out of this mandate. A uniform and widely used format for security benchmarks, checklists, and related documents will help to improve security of government and private IT installations by enabling more timely and effective knowledge sharing and by fostering automated security testing and monitoring. NSA and NIST offer the XCCDF format to the public and the security community as such a format, and are prepared to work with the community to improve the specification.
The XCCDF specification document is available for download from the NIST security checklists web site. The site also offers access to a mailing list where industry and the public can make suggestions and comments about the specification. NSA and NIST look forward to working with the security community to make XCCDF a practical and useful data format for the security needs of the public and private sectors.
About the Organizations:
As a non-regulatory agency of the U.S. Department of Commerce’s Technology Administration, the NIST develops and promotes measurement, standards and technology to enhance productivity, facilitate trade and improve the quality of life.
NSA has served as America’s codemakers and codebreakers for over 50 years. Under its mandate to protect national security communications, the agency conducts research and development activities in the area of information technology and network security.
America's Codemakers and Codebreakers ##
Monday, January 24, 2005
National Security Agency, Central Security Service Extensible Configuration Checklist
Under Secretary Asa Hutchinson’s Resignation
Statement by Homeland Security Secretary Tom Ridge on Under Secretary Asa Hutchinson’s Resignation
U.S. Department of Homeland Security Under Secretary for Border and Transportation Security Asa Hutchinson today announced his resignation effective March 1, 2005.
“Asa Hutchinson has served his country and the Department with great energy, integrity and distinction. He has been an integral and tireless member of my leadership team. Under Secretary Hutchinson championed our biometric technology entry/exit system with the implementation of US-VISIT and has overseen increased detection, detention and removal of illegal immigrants throughout the country. His leadership efforts to provide the latest technology and tools to the 110,000 employees of the Border and Transportation Security directorate, the largest in the Department, have enabled us to keep our country safe and secure. Additionally, he strengthened relationships with foreign governments which has enhanced our partnerships in the fight against terrorism. I thank Asa for the selfless and effective service rendered for his country and wish him and Susan all the best for the future,” said Homeland Security Secretary Tom Ridge. ###
For Immediate Release Office of the Press Secretary Contact: 202-282-8010 January 24, 2005


