Yes Foundstone allows user to load custom SCAP contents and scan using them.
The requirements for custom SCAP content are.
1. The content you load should have all the necessary files like XCCDF ,OVAL,CPE dictionary to run the scan successfully.
2. The XML file you upload should be XML well formed and xccdf, oval schema validated
Option to import the SCAP content on UI:
1. After logging in to foundstone as Global administrator navigate to Manage>>XCCDF/OVAL section
2. You can upload the files individually like xccdf,oval,cpe or there is an option to upload the SCAP ZIP file (xccdf,oval,cpe) which contains all the required files at one shot.
3. Please uncheck the "Validate" option before importing the scap content.
In foundstone version 7.0 we support few of OVAL 5.6 probes.
1 of 1 people found this helpful
You can do it with ePO to if you have the Policy Auditor module loaded. On ePO 4.5 go to Risk & Compliance, Benchmarks, Action, Import. Then make the benchmark active. Once it's active you can use it in an audit.
Thank you both very much. The information was very helpful.