Vendor Provided Validation Details - nCircle IP360 version 6.61
The following text was provided by the vendor during testing to describe how the product implements the specific capabilities.

Statement of FDCC Compliance:
Not applicable for the validated capabilities.

Statement of SCAP Implementation:
nCircle IP360 implements the SCAP standard by implementing Common Vulnerability Enumeration (CVE), Common Platform Enumeration (CPE), and the Common Vulnerability Scoring System (CVSS). nCircle IP360 implements the CVE standard by assigning appropriate CVE identifiers to every detectable vulnerability for which such an identifier exists, and by given users access to this identifier via vulnerability search. nCircle IP360 implements the CPE standard by assigning appropriate CPE identifiers to every detectable application for which such an identifier exists, and by providing a product-generated list of these applications nCircle IP360 implements the CVSS standard by assigning a CVSS (Version 2) score to every detectable vulnerability for which such a score exists. For those vulnerabilities whose scores have not yet been officially calculated by NIST, nCircle calculates scores based on NIST guidelines. Whenever new scores are calculated by NIST, nCircle replaces its scores with the official NIST-calculated scores. In addition, CVSS Temporal Scores are calculated using NIST guidelines.

Statement of CVE Implementation:
nCircle IP360 implements the CVE standard by assigning appropriate CVE identifiers to every detectable vulnerability for which such an identifier exists. IP360 provides user access to this implementation via the following mechanisms:
Statement of CCE Implementation:
Not applicable for the validated capabilities.

Statement of CPE Implementation:
nCircle IP360 uses various application detection techniques in order to enhance the accuracy and reliability of vulnerability determination. Moreover, detected applications can be used to improve overall network security by identifying unauthorized or unexpected applications. IP360 uses CPE to label these detected applications. Specifically, nCircle IP360 implements the CPE standard by assigning appropriate CPE identifiers to every detectable application for which such an identifier exists. Whenever the official CPE dictionary is revised, new CPE identifiers are appended to application descriptions that did not previously have associated CPE identifiers, based on the dictionary revisions.

IP360 provides user access to this implementation via the following mechanisms:
Statement of CVSS Implementation:
nCircle IP360 implements the CVSS standard by assigning a CVSS (Version 2) score to every detectable vulnerability for which such a score exists. For those vulnerabilities whose scores have not yet been officially calculated by NIST, nCircle calculates scores based on NIST guidelines. Whenever new scores are calculated by NIST, nCircle replaces its scores with the official NIST- calculated scores.

IP360 provides user access to this implementation via the following mechanisms:

Statement of XCCDF Implementation:
Not applicable for the validated capabilities.

Statement of OVAL Implementation:
Not applicable for the validated capabilities.