![]() |
Compatibility Questionnaire: MMG Security, Inc.
General Capability Questions |
Accuracy Questions |
Documentation Questions |
Capability Specific Questions |
Statements
Organizational InformationName of Your Organization:MMG Security, Inc.
Web Site:Product InformationProduct/Service Name:Sussen 1.0
Compatible Categories: OVAL Systems Characteristics Producer
OVAL Systems Characteristics Consumer OVAL Definition Consumer OVAL Results Producer OVAL Results Consumer Product/Service Home Page:Product AccessibilityProvide a short description of how and
where your capability is made available to your customers and the public:
Sussen is available for download from our web site
(http://dev.mmgsecurity.com/projects/sussen/) under the terms of the
GNU General Public License (GPL).
Language Version IndicationDescribe how and where the capability indicates
the version of the OVAL Language used to validate, create, or update
its content:
The reports generated by the program include the schema version, timestamp and name/version of the product that created the definitions, system characteristics, and results. Approach for Correction of ErrorsIndicate how a user who discovers an error in the capability's use of OVAL can report the error:
We maintain a public bug database that people can use to report issues with our software. The database is available at: http://dev.mmgsecurity.com/bugs/ Describe the approach to responding to the above error reports and how applicable fixes will be applied:
Once we have confirmed the bugs(s), we work with the bug reporter to test our fix(es). When we have a working fix we will make a new release available. Any bugfixes are noted in the release notes by ID in case people want to read more about the issue(s). Users can then download and update their versions. Compatibility DocumentationProvide a copy, or directions to the location, of where the documentation describes OVAL and OVAL Compatibility for any customers:
The documentation on OVAL and OVAL compatibility is available with the software. In Windows it's in our help file and for Linux it's available in the Sussen. Oval man page. Language SupportIndicate the component schemas and/or individual OVAL Tests that the capability does not support for each category of OVAL Compatibility being applied for:
The following are not currently supported in Sussen:
UNIX sccs_test Finding Elements Using OVALProvide details regarding how users can identify and find individual OVAL content (through OVAL-IDs) that is being consumed by the capability. For example, how can a user determine which definitions have been consumed and what the result of each definition is:
The command line programs either output the results in XML or HTML format. That allows the user to see what definitions were consumed and the results. You can also view the collected data and results from the reports section in the web console. OVAL Content Importation Process ExplanationIf the capability does not support consuming OVAL content at runtime, explain the documented process by which users can submit OVAL content for interpretation by the capability, including how quickly submitted content is made available to the capability:
N/A. Sussen can consume OVAL content at runtime.
Statement of CompatibilityHave an authorized individual sign and date the following Compatibility Statement (required): "As an authorized representative of my organization I agree that we will abide by all of the mandatory Compatibility Requirements as well as all of the additional mandatory Compatibility Requirements that are appropriate for our specific type of capability."
Statement of AccuracyHave an authorized individual sign and date the following accuracy Statement (recommended): "As an authorized representative of my organization and to the best of my knowledge, there are no errors in the correctness of our capability's use of OVAL schema and logic."
Statement on Follow-on Correctness Testing SupportHave an authorized individual sign and date the following statement about your organizations willingness to support correctness testing of other capabilities, which will be managed by the Reviewing Authority and kept to reasonable levels of effort for all involved. (required): "As an authorized representative of my organization, we agree to support the Review Authority in follow-on correctness testing activities, where appropriate types of OVAL documents might need to be exchanged with other organizations attempting to prove the correctness of their capabilities."
Page Last Updated: November 02, 2006 |
|
|||||||||||||||||||