This document discusses SCAP datastreams, which can contain linked security checklist content like XCCDF and OVAL files. It describes source datastreams that define how a system should be configured and result datastreams that provide scan results. It also discusses the National Checklist Program and Repository maintained by NIST, which provides security configuration checklists at different tiers of structure and automation to help users select the appropriate checklist for their needs.