DI-MGMT-81842
Vulnerability Scan Compliance (VSC) Report
The VSC Report is used by the government to assess the security vulnerability and residual risks of a major information system software build against applicable DISA STIGs.
Approval DateNovember 8, 2011
AMSC NumberN9219
Preparing Activity—
Project Number—
OPRSH/PEO IWS 1.0
DTIC Applicable—
GIDEP Applicable—
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatdd_form_1664
963C CompliantNo
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The VSC Report will be used by the government to assess the security vulnerability and residual risks of a major information system software build.
This Data Item Description (DID) contains the format and content preparation instructions for the data resulting from the work task specified in the contract.
The reference document cited in this DID can be obtained from http://iase.disa.mil/stigs/index.html
Preparation Instructions
1ReferenceThe applicable issue of documents cited herein, including their approval dates and dates of any applicable amendments, notices and revisions, shall be as reflected in the contract.
2FormatThe VSC Report shall be presented in Microsoft Office Excel spreadsheet format similar to that of Figure 1.
3ContentThe VSC Report shall contain the following headings:
3.1Title of Security Technical Implementation Guide (STIG) Reference including STIG Version
3.2STIG Reference Paragraph
3.3Applicable IA Controls from DoDI 8500.2
3.4Severity Risk Rating (Cat I, II, III)
3.5Compliance Statusshall be specified as one of the following:
3.6.1identify design implementation to satisfy compliance
3.6.2identify procedures taken to satisfy compliance
3.6.3identify document used to satisfy compliance
3.6.4identify why compliance is not met and the consequence of non-compliance
3.7System Impact (for non-compliant items only)
3.7.1identify impact to capability to execute mission
3.7.2identify risk exposure to threat
3.8Mitigation Recommendations (for non-compliant items only)
3.9The VSC Report shall identify all open findingswith recommendations on how the findings will be mitigated based on the approved applicable DISA STIGs and shall include the following:
3.9.1Application Security and Development STIG
3.9.3Application Services STIG
3.9.5Desktop Application STIG
3.9.6Defense Switched Network (DSN) STIG
3.9.7Directory Services STIG
3.9.8DISA Instruction Enclave STIG
3.9.9Domain Name System (DNS) STIG
3.9.14Instant Messaging STIG
3.9.16Personal Computer Communications Client (Voice-Video-Collaboration) STIG
3.9.17Sharing Peripherals Across the Network (SPAN) STIG
3.9.18Secure Remote Computing STIG
3.9.20Virtual Machine STIG
3.9.21Voice Over Internet Protocol (VOIP) STIG
3.9.23NSA Windows NT Guide
3.9.24NSA Windows 2000 Guides
3.9.25Windows 2000/XP/2003/Vista Addendum
4Media RequirementsThe electronic media for the VSC Report shall be Microsoft Excel Version 2003-2007.
Figures

Figure 1. VULNERABILITY SCAN COMPLIANCE (VSC) REPORT
Schema v3.0Community-maintained · Verify against ASSIST