Skip to content

InSpec Profiles General Information

George M. Dias edited this page Nov 6, 2024 · 3 revisions

This wiki page is used to document InSpec Profile related information as it applies to the development and implementation of InSpec profile controls.

XCCDF/STIG severity or category Mappings

These values are defined in the @mitre/inspec-objects npm package - file utilities\xccdf.ts. The following tables depict the returned values based on the inputted severity, category, or impact provided.

XCCDF Severity to Control Impact

Severity Impact
none, na, not applicable 0.0
low 0.3
medium 0.5
high 0.7
severe, critical 1.0
any other value 0.5

STIG Category to Control Impact

Category Impact
I (1) 0.7
II (2) 0.5
III (3) 0.3

Control Impact range to Severity

Impact Severity
>= 0.1 <= 0.3 low
>= 0.4 <= 0.6 medium
>= 0.7 <= 0.8 high
>= 0.9 critical
any other value none