Postby sdnewman » Fri Dec 14, 2012 11:21 am

When benchmark updates are downloaded, what is the best way for me to know the differences between the old benchmark and the updated one?

Postby Randy » Wed Dec 19, 2012 8:52 am

The benchmarks we automatically update with the application come from the authoritative sources of NIST (USGCB/FDCC) and DISA (STIGs). Updates to the benchmarks are done by these sources to keep them in line with the guidance they are derived from. The majority of the updates are to keep up with the latest patch releases. Unfortunately there is no easy automated way to determine the differences between versions.

NIST does a good job of documenting changes to their benchmarks in the "Change History" sections of the benchmark pages. For example, the USGCB Windows 7 Firewall benchmark page is here (scroll down to the change history section):

http://web.nvd.nist.gov/view/ncp/reposi ... ail?id=296
