> For the complete documentation index, see [llms.txt](https://breachtrace.gitbook.io/vulnkeeper/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://breachtrace.gitbook.io/vulnkeeper/chapter-g/18-18-compliance-baseline-configuration-software-assurance-and-exposure-severity-st.md).

# 18. Compliance, baseline configuration, software assurance & exposure severity standards

These are not vulnerability feeds, but they help assess impact, control failure, configuration exposure, & exploitability in a given environment.

## 18.1 Security configuration & benchmarks

<table><thead><tr><th width="85.828125" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>CIS Benchmarks</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisecurity.org/cis-benchmarks">www.cisecurity.org/cis-benchmarks</a><br><br><strong><code>Access / Cost</code>:</strong> Free with registration for many PDFs; commercial CIS tools/membership available</td><td><strong><code>Relevance</code>:</strong> Secure configuration benchmarks.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for environmental risk scoring &#x26; hardening validation.</td></tr><tr><td align="right">2</td><td><strong>CIS Controls</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisecurity.org/controls">www.cisecurity.org/controls</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Security control framework.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for vulnerability management program alignment.</td></tr><tr><td align="right">3</td><td><strong>NIST National Checklist Program</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://ncp.nist.gov/">ncp.nist.gov</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Repository of security configuration checklists.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for baseline configuration assessment.</td></tr><tr><td align="right">4</td><td><strong>DISA STIGs</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://public.cyber.mil/stigs/">public.cyber.mil/stigs</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Security Technical Implementation Guides.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Important for government/defense compliance.</td></tr><tr><td align="right">5</td><td><strong>OpenSCAP</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.open-scap.org/">www.open-scap.org</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source</td><td><strong><code>Relevance</code>:</strong> SCAP tooling for compliance scanning.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for host-level configuration scanning.</td></tr></tbody></table>

\| 6 | SCAP Security Guide | [github.com/ComplianceAsCode/content](https://github.com/ComplianceAsCode/content) | Free / open-source public GitHub repo | ComplianceAsCode content for SCAP profiles. | Useful for policy-as-code & baseline validation. |

## 18.2 Cloud configuration posture

<table><thead><tr><th width="89.3203125" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>Prowler - AWS/Azure/GCP/Kubernetes</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/prowler-cloud/prowler">github.com/prowler-cloud/prowler</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source core; commercial product available</td><td><strong><code>Relevance</code>:</strong> Cloud &#x26; Kubernetes security posture scanning.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for environmental exposure &#x26; misconfiguration risk.</td></tr><tr><td align="right">2</td><td><strong>CloudSplaining</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/salesforce/cloudsplaining">github.com/salesforce/cloudsplaining</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> AWS IAM policy risk analysis.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for blast-radius &#x26; privilege exposure context.</td></tr><tr><td align="right">3</td><td><strong>ScoutSuite</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/nccgroup/ScoutSuite">github.com/nccgroup/ScoutSuite</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Multi-cloud security auditing.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for cloud misconfiguration assessment.</td></tr><tr><td align="right">4</td><td><strong>Steampipe mods</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://hub.steampipe.io/mods">hub.steampipe.io/mods</a><br><br><strong><code>Access / Cost</code>:</strong> Free/open-source mods; commercial Turbot/Steampipe offerings separate</td><td><strong><code>Relevance</code>:</strong> SQL-based cloud/security posture checks.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for custom exposure queries.</td></tr><tr><td align="right">5</td><td><strong>Cloud Custodian</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://cloudcustodian.io/">cloudcustodian.io</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source</td><td><strong><code>Relevance</code>:</strong> Cloud governance &#x26; policy automation.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for remediation automation.</td></tr><tr><td align="right">6</td><td><strong>Kubernetes CIS benchmark</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisecurity.org/benchmark/kubernetes">www.cisecurity.org/benchmark/kubernetes</a><br><br><strong><code>Access / Cost</code>:</strong> Free with registration for benchmark PDFs; commercial CIS tools/membership available</td><td><strong><code>Relevance</code>:</strong> Kubernetes configuration benchmark.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for cluster hardening &#x26; exposure scoring.</td></tr><tr><td align="right">7</td><td><strong>kube-bench</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/aquasecurity/kube-bench">github.com/aquasecurity/kube-bench</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Kubernetes CIS benchmark scanner.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for automated cluster benchmark checks.</td></tr><tr><td align="right">8</td><td><strong>kube-hunter</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://github.com/aquasecurity/kube-hunter">github.com/aquasecurity/kube-hunter</a><br><br><strong><code>Access / Cost</code>:</strong> Free / open-source public GitHub repo</td><td><strong><code>Relevance</code>:</strong> Kubernetes penetration testing tool.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Use only in authorized environments.</td></tr></tbody></table>

## 18.3 Software assurance, secure development, acquisition & NIST publication libraries

<table><thead><tr><th width="89.80859375" align="right">Sl. #</th><th>Source Title</th><th>Notes</th></tr></thead><tbody><tr><td align="right">1</td><td><strong>CISA Software Acquisition Guide</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.cisa.gov/resources-tools/resources/software-acquisition-guide-government-enterprise-consumers-software-assurance-cyber-supply-chain">cisa.gov/resources-tools/resources/software-acquisition-guide-government-enterprise-consumers-software-assurance-cyber-supply-chain</a><br><br><strong><code>Access / Cost</code>:</strong> Free public; CISA pages may bot-block automated fetchers</td><td><strong><code>Relevance</code>:</strong> Software assurance &#x26; cyber supply-chain acquisition guidance for enterprise/government consumers.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Not a vulnerability feed, but useful for procurement, assurance, &#x26; supplier-risk context.</td></tr><tr><td align="right">2</td><td><strong>NIST Secure Software Development Framework - SSDF</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://csrc.nist.gov/projects/ssdf">csrc.nist.gov/projects/ssdf</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Secure development practice framework for reducing software vulnerabilities.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for SDLC controls, attestation, &#x26; vulnerability-prevention context.</td></tr><tr><td align="right">3</td><td><strong>NIST FIPS publications</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://csrc.nist.gov/publications/fips">csrc.nist.gov/publications/fips</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Federal Information Processing Standards.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Compliance/standards reference, not vuln feed.</td></tr><tr><td align="right">4</td><td><strong>NIST Special Publications root</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://csrc.nist.gov/publications/sp">csrc.nist.gov/publications/sp</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> NIST Special Publication library.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for standards research &#x26; compliance mapping.</td></tr><tr><td align="right">5</td><td><strong>NIST SP 800 series</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://csrc.nist.gov/publications/sp800">csrc.nist.gov/publications/sp800</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Computer/security guidance series.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> High-value for security-control, risk, identity, cryptography, &#x26; vulnerability-management context.</td></tr><tr><td align="right">6</td><td><strong>NIST SP 1800 series</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://csrc.nist.gov/publications/sp1800">csrc.nist.gov/publications/sp1800</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> NIST Cybersecurity Practice Guides.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Practical implementation patterns &#x26; reference architectures.</td></tr><tr><td align="right">7</td><td><strong>NIST SP 500 series</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://csrc.nist.gov/publications/sp500">csrc.nist.gov/publications/sp500</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> Information technology publications.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for supporting standards &#x26; technical guidance.</td></tr><tr><td align="right">8</td><td><strong>NIST AI publication search</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://csrc.nist.gov/publications/search?sortBy-lg=relevance&#x26;viewMode-lg=brief&#x26;ipp-lg=50&#x26;status-lg=Final%2CDraft&#x26;series-lg=AI">csrc.nist.gov/publications/search?sortBy-lg=relevance&#x26;viewMode-lg=brief&#x26;ipp-lg=50&#x26;status-lg=Final%2CDraft&#x26;series-lg=AI</a><br><br><strong><code>Access / Cost</code>:</strong> Free public filtered search</td><td><strong><code>Relevance</code>:</strong> NIST AI-series publication discovery.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Filtered search URL; cite individual publications separately when used for evidence.</td></tr><tr><td align="right">9</td><td><strong>LangGuard SCOPE MCP</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://scope-mcp.langguard.ai">scope-mcp.langguard.ai</a><br><br><strong><code>Access / Cost</code>:</strong> Public web tool/service; terms may apply</td><td><strong><code>Relevance</code>:</strong> AI/agent compliance &#x26; pre-flight risk evaluation for tool use.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for AI/agent security governance, not vulnerability source ingestion.</td></tr><tr><td align="right">10</td><td><strong>FIRST 2026 papers</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.first.org/resources/papers/2026">www.first.org/resources/papers/2026</a><br><br><strong><code>Access / Cost</code>:</strong> Free public</td><td><strong><code>Relevance</code>:</strong> FIRST papers &#x26; security response knowledge base.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Research/training context, not canonical vulnerability data.</td></tr><tr><td align="right">11</td><td><strong>FIRST VulnCon 2026 program</strong><br><br><strong><code>Link(s)</code>:</strong> <a href="https://www.first.org/conference/vulncon26/program">first.org/conference/vulncon26/program</a><br><br><strong><code>Access / Cost</code>:</strong> Free public conference page</td><td><strong><code>Relevance</code>:</strong> Vulnerability management &#x26; disclosure conference content.<br><br><strong><code>Notes &#x26; POIs</code>:</strong> Useful for user stories, emerging practices, &#x26; CVE/PSIRT ecosystem context.</td></tr></tbody></table>

## Discussion

This chapter section keeps the latest table structure, source titles, access/cost fields, relevance notes, & operational notes from the source inventory. Review the table entries as ingestion candidates, then validate source freshness, licensing, authentication requirements, & link-check behavior before production use.

***

#### [Back to Index](/vulnkeeper/index.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://breachtrace.gitbook.io/vulnkeeper/chapter-g/18-18-compliance-baseline-configuration-software-assurance-and-exposure-severity-st.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
