DocumentCode :
398064
Title :
Integrating your information security vulnerability management capabilities through industry standards (CVE&OVAL)
Author :
Martin, Robert A.
Author_Institution :
Software Eng. Sect., MITRE Corp., Bedford, MA, USA
Volume :
2
fYear :
2003
fDate :
5-8 Oct. 2003
Firstpage :
1528
Abstract :
There are important changes to the cyber-security industry, being fostered by the Common Vulnerability Exposures (CVE®) and Open Vulnerability Assessment Language (OVAL™) Initiatives, a pair of international, community-based effort amongst industry, government, and academia. These changes will transform the way your enterprise deals with vulnerabilities in the commercial and open source components of your enterprise infrastructure and mission systems. With approximately 150 organizations working to support the CVE standard in more than 250 cyber-security products and services, CVE is quickly becoming an organizing mechanism that can make enterprise management of information security vulnerabilities less of a labor intensive art and more of an engineered practice. The OVAL effort builds upon CVE to create a means for making vulnerability alerts more applicable to individual enterprises. OVAL is aimed to provide the means for standardized vulnerability assessment and result in consistent and reproducible information assurance metrics for systems.
Keywords :
information management; security of data; standards; CVE standards; Common Vulnerability Exposures; OVAL standards; Open Vulnerability Assessment Language; commercial components; community based effort; cyber-security industry; enterprise management; individual enterprises; industry standards; information assurance metrics; information security; labor intensive art; management capabilities; mission systems; open source components; vulnerability; Computer errors; Computer hacking; Computer industry; Computer security; Information management; Information security; Intrusion detection; Open source software; Protection; Software tools;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systems, Man and Cybernetics, 2003. IEEE International Conference on
ISSN :
1062-922X
Print_ISBN :
0-7803-7952-7
Type :
conf
DOI :
10.1109/ICSMC.2003.1244628
Filename :
1244628
Link To Document :
بازگشت