(SCAP; see http://csrc.nist.gov/groups/SNS/cloud-computing/in-dex.html), which identifies a “suite of specifications for organizing and expressing security related information in standardized ways, as well as related reference data, such as identifiers for software flaws andsecurity configuration issues.”4 Its application includes maintaining enterprise systems’ security. Interestingly, a major concern included in SCAP is the lack of interoperability among systemlevel tools. It states that