<?xml version="1.0" encoding="UTF-8"?>
<AssetReport xmlns="http://scap.nist.gov/schema/asset-reporting-format/1.0"
    xmlns:ai="http://scap.nist.gov/schema/asset-identification/1.0"
    xmlns:sr="http://scap.nist.gov/schema/lightweight-asset-summary-results/1.0"
    xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
    xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
    xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
    xsi:schemaLocation="http://scap.nist.gov/schema/asset-identification/1.0 http://scap.nist.gov/schema/asset-identification/1.0/asset-identification_1.0.0-ea1.xsd
    http://scap.nist.gov/schema/asset-reporting-format/1.0 http://scap.nist.gov/schema/asset-reporting-format/1.0/asset-reporting-format_1.0.0-ea1.xsd
    http://scap.nist.gov/schema/lightweight-asset-summary-results/1.0 http://scap.nist.gov/schema/lightweight-asset-summary-results/1.0/lightweight-asset-summary-results_1.0.0-ea1.xsd">
    <Subject>
        <ai:Organization>
            <xnl:OrganisationName>Department of Commerce</xnl:OrganisationName>
            <xnl:OrganisationName>National Institute of Standards and Technology</xnl:OrganisationName>
            <xnl:OrganisationName>Information Technology Laboratory</xnl:OrganisationName>
            <xnl:OrganisationName>Computer Security Division</xnl:OrganisationName>
        </ai:Organization>
    </Subject>
    <ReportInformation>
        <Report>
            <ReportMetadata>
                <DateTime>2006-05-04T18:13:51.0Z</DateTime>
                <Tool>
                    <ai:Software>
                        <ai:CPE>cpe:/a:vendor_a:management_platform:1.2.3.45</ai:CPE>
                    </ai:Software>
                </Tool>
            </ReportMetadata>
            <ReportPayloads>
                <ReportPayload>
                    <sr:SummaryReport id="FISMA_auto_feed_fy10" version="1.0beta1">
                        <sr:DataPoint id="configuration_management_agency_deviations">
                            <sr:GroupedData>
                                <sr:NamedAttribute name="checklist_name">USGCB-Windows-7</sr:NamedAttribute>
                                <sr:GroupedData> 
                                    <sr:NamedAttribute name="checklist_version">v0.1.0.6</sr:NamedAttribute>
                                    <sr:GroupedData>
                                        <sr:NamedAttribute name="checklist_profile">united_states_government_configuration_baseline_1.0.1.0</sr:NamedAttribute>
                                        <sr:AggregateValue name="number_of_systems" type="COUNT">100</sr:AggregateValue>
                                        <sr:GroupedData>
                                            <sr:NamedAttribute name="http://cce.mitre.org">CCE-9289-0</sr:NamedAttribute>
                                            <sr:AggregateValue name="non_compliant_systems" type="COUNT">90</sr:AggregateValue>
                                            <sr:AggregateValue name="number_of_exceptions" type="COUNT">5</sr:AggregateValue>
                                        </sr:GroupedData>
                                    </sr:GroupedData>
                                    <sr:GroupedData>
                                        <sr:NamedAttribute name="checklist_profile">agency_profile</sr:NamedAttribute>
                                        <sr:AggregateValue name="number_of_systems" type="COUNT">100</sr:AggregateValue>
                                        <sr:GroupedData>
                                            <sr:NamedAttribute name="http://cce.mitre.org">CCE-9289-0</sr:NamedAttribute>
                                            <sr:AggregateValue name="non_compliant_systems" type="COUNT">90</sr:AggregateValue>
                                            <sr:AggregateValue name="number_of_exceptions" type="COUNT">5</sr:AggregateValue>
                                        </sr:GroupedData>
                                    </sr:GroupedData>
                                </sr:GroupedData>
                            </sr:GroupedData>
                        </sr:DataPoint>
                        <sr:DataPoint id="vulnerability_management_product_vulnerabilities">
                            <sr:GroupedData>
                                <sr:NamedAttribute name="http://cve.mitre.org/">CVE-2010-1234</sr:NamedAttribute>
                                <sr:AggregateValue name="number_of_affected_systems" type="COUNT">90</sr:AggregateValue>
                            </sr:GroupedData>
                            <sr:GroupedData>
                                <sr:NamedAttribute name="http://cve.mitre.org/">CVE-2010-5678</sr:NamedAttribute>
                                <sr:AggregateValue name="number_of_affected_systems" type="COUNT">90</sr:AggregateValue>
                            </sr:GroupedData>
                        </sr:DataPoint>
                        <sr:DataPoint id="inventory_management_product_inventory">
                            <sr:GroupedData>
                                <sr:AssetAttribute name="operating_system">
                                    <ai:Software>
                                        <ai:CPE>cpe:/o:microsoft:windows_xp::sp2</ai:CPE>
                                    </ai:Software>
                                </sr:AssetAttribute>
                                <sr:AggregateValue name="number_of_systems" type="COUNT">100</sr:AggregateValue>
                            </sr:GroupedData>
                        </sr:DataPoint>
                    </sr:SummaryReport>
                </ReportPayload>
            </ReportPayloads>
        </Report>
    </ReportInformation>
</AssetReport>
