• DocumentCode
    398064
  • Title

    Integrating your information security vulnerability management capabilities through industry standards (CVE&OVAL)

  • Author

    Martin, Robert A.

  • Author_Institution
    Software Eng. Sect., MITRE Corp., Bedford, MA, USA
  • Volume
    2
  • fYear
    2003
  • fDate
    5-8 Oct. 2003
  • Firstpage
    1528
  • Abstract
    There are important changes to the cyber-security industry, being fostered by the Common Vulnerability Exposures (CVE®) and Open Vulnerability Assessment Language (OVAL™) Initiatives, a pair of international, community-based effort amongst industry, government, and academia. These changes will transform the way your enterprise deals with vulnerabilities in the commercial and open source components of your enterprise infrastructure and mission systems. With approximately 150 organizations working to support the CVE standard in more than 250 cyber-security products and services, CVE is quickly becoming an organizing mechanism that can make enterprise management of information security vulnerabilities less of a labor intensive art and more of an engineered practice. The OVAL effort builds upon CVE to create a means for making vulnerability alerts more applicable to individual enterprises. OVAL is aimed to provide the means for standardized vulnerability assessment and result in consistent and reproducible information assurance metrics for systems.
  • Keywords
    information management; security of data; standards; CVE standards; Common Vulnerability Exposures; OVAL standards; Open Vulnerability Assessment Language; commercial components; community based effort; cyber-security industry; enterprise management; individual enterprises; industry standards; information assurance metrics; information security; labor intensive art; management capabilities; mission systems; open source components; vulnerability; Computer errors; Computer hacking; Computer industry; Computer security; Information management; Information security; Intrusion detection; Open source software; Protection; Software tools;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systems, Man and Cybernetics, 2003. IEEE International Conference on
  • ISSN
    1062-922X
  • Print_ISBN
    0-7803-7952-7
  • Type

    conf

  • DOI
    10.1109/ICSMC.2003.1244628
  • Filename
    1244628