6 hostname(s) are not mapped to OCA assessment areas. Unmapped hostnames will appear under "Unmapped" in the scoring.
NIPR
SIPR
Overall OCA Score
LAB BASELINES (BASELINE)
Percentages shown in score cards are open rates (`Open / Total`). Closed/compliance rate is `100% - open rate`.
Assessment Area Breakdown
Scores by OCA assessment area
| Assessment Area | Hosts | CAT I | CAT II | CAT III | Weighted Score | Concern Level |
|---|---|---|---|---|---|---|
|
Boundary Security
Firewalls, DMZ, perimeter security
|
- |
-
|
-
|
-
|
- | N/A |
|
Internal Network
Internal network switches, routers, VLANs
|
- |
-
|
-
|
-
|
- | N/A |
|
Combined Vulnerability Scan
ACAS/Nessus vulnerability scan results
|
- |
-
|
-
|
-
|
- | N/A |
|
Domain Name System
DNS servers and configuration
|
- |
-
|
-
|
-
|
- | N/A |
|
Host Based Security System
HBSS/Trellix endpoint security
|
- |
-
|
-
|
-
|
- | N/A |
|
Traditional Security
Physical security, access control
|
- |
-
|
-
|
-
|
- | N/A |
|
Wireless Communications/Mobility
WiFi, mobile devices
|
- |
-
|
-
|
-
|
- | N/A |
|
Cross Domain Solutions - Admin
CDS administrative controls
|
- |
-
|
-
|
-
|
- | N/A |
|
Cross Domain Solutions - Technical
CDS technical implementation
|
- |
-
|
-
|
-
|
- | N/A |
|
Exchange
Microsoft Exchange email servers
|
- |
-
|
-
|
-
|
- | N/A |
|
Web Server
IIS, Apache, web applications
|
- |
-
|
-
|
-
|
- | N/A |
|
Database
SQL Server, Oracle, database security
|
- |
-
|
-
|
-
|
- | N/A |
|
Video and Voice Over Internet Protocol (VVOIP)
VoIP phones, video conferencing
|
- |
-
|
-
|
-
|
- | N/A |
|
Windows OS
SCHR-P3-DP-001
|
1 |
0/0
0%
|
0/1
0%
|
0/0
0%
|
0.0% | No Concern |
|
Unix OS
Linux, Unix, macOS systems
|
- |
-
|
-
|
-
|
- | N/A |
|
Releaseable Networks
Networks for coalition/external use
|
- |
-
|
-
|
-
|
- | N/A |
|
Virtual Environment
VMware, Hyper-V, containers
|
- |
-
|
-
|
-
|
- | N/A |
|
Other Review
Uncategorized or specialized systems
|
- |
-
|
-
|
-
|
- | N/A |
|
Unmapped
SCHR-P3-DP-001
|
1 |
0/38
0%
|
0/379
0%
|
0/26
0%
|
0.0% | No Concern |
Concern Level Thresholds
ACAS Vulnerability Scans (VPH)
VPH = Open Findings / Hosts Scanned. Combined = (CAT I VPH × 10 + CAT II VPH × 4 + CAT III VPH × 1) / 15
STIG Checklists (Open Rate)
Weighted score = (CAT I % × 10 + CAT II % × 4 + CAT III % × 1) / 15
CAT percentages in STIG areas are open-rate percentages (`Open / Total`), not inverse percentages.