Using the Create SCAP 1.3 Compatible Report wizard

The SCAP Compatible Report wizard helps users make reports that follow SCAP standards. It guides the process of compiling compliance and vulnerability scan results in a standard format, making it easier to share, analyze, and meet regulatory requirements. This guide explains how to use the Web Reports interface to create a compliance report in the Asset Reporting Format (ARF).

About this task

For optimal performance and compatibility, use Microsoft Edge or Google Chrome as your browser when running ARF reports.

To generate an SCAP 1.3 ARF file, see the instructions on how to use the SCAP command line tools located here: SCAP 1.3.

How to Launch Web Reports from BigFix console:
  • Open the BigFix Console.
  • Navigate to ToolsLaunch Web Reports.
  • Enter your web report credentials when prompted.


  • Click on Report List.
  • Select ARF Report Generator 1.0.71b from the list.

Follow the steps below to generate the ARF report:

Procedure

  1. Click the dropdown arrow beside BigFix SCAP Reporting to expand the menu.

  2. Click the Import Source Data Stream and choose a datastream file to import.

  3. Click on Import Source Site Data and select the Custom Site from the dropdown menu.



  4. Click the Run button.

  5. Once the run is complete, select the report view titled Single Machine Full Results with System Characteristics to generate the ARF report.

    BigFix SCAP Reporting - ARF Report Types Summary
    Note: Single Machine With This Results
    • Key Data Included: Evaluation Results (TestResult) ONLY.
    • System Characteristics: No (Minimal Data).
    • Best Use Case: Quick verification, debugging, minimal metadata needs.
    Note: Single Machine Full Results With System Characteristics
    • Key Data Included: Evaluation Results (TestResult) + System Characteristics (oval-system-characteristics).
    • System Characteristics: Yes (Full Data).
    • Best Use Case: Official NIST SCAP 1.3 certification, compliance submissions, full audit.
    Note: Single Machine Full Results Without System Characteristics
    • Key Data Included: Evaluation Results (TestResult) ONLY.
    • System Characteristics: No (Anonymized Data).
    • Best Use Case: Privacy-conscious export, combining reports (aggregation), data redaction.
  6. Select the specific endpoint (machine) for which you wish to generate the compliance report.



  7. On the generated report view, click the Download Report button. The ARF result file will be downloaded with the generic name: xmlresult.xml.

  8. It is essential to rename the generated xmlresult.xml to a more meaningful name based on the datastream used. For example: If the datastream is r.400.1.1, rename the file to r.400.1.1.xml.

Results

You now have a properly generated and named ARF report ready for use or submission.