CCE and Configuration Baselines: Standardizing How Systems Are Hardened
Common Configuration Enumeration assigns a unique identifier to a specific security configuration setting, so that "the password history requirement on this operating system" means the same thing across every tool, benchmark, and report that references it. It is the configuration equivalent of what CVE does for vulnerabilities, and the distinction between the two is the concept most worth getting straight. CCE versus CVE A CVE identifies a flaw in software — a defect the vendor must fix and you must patch. You did not cause it and you cannot configure it away. A CCE identifies a configuration setting you control. Nothing is defective; the software is working as designed, and the question is whether your chosen setting is the secure one. The remedy is a configuration change rather than a patch. That difference drives different processes. Vulnerabilities flow through patch management with testing and change windows. Configuration findings flow through baseline management...