XCCDF is a standard for creating and sharing machine-readable configuration checklists, and it allows organizations to define and automate the assessment of security configurations. OVAL is a standard for expressing information about vulnerabilities and other security issues, and it can be used to automate the process of evaluating systems for vulnerabilities and other security risks.