Access member only content, take part in discussions with comments on blogs, news and reviews and receive all the latest security industry news directly to your inbox. Join now for free.
A confirmation email has been sent to your email address - SUPPLIED EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can start posting.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain @scmagazine.com.au to your white-listed senders.
The nonprofit Industry Consortium for Advancement of Security on the Internet (ICASI) this week announced the release of a framework designed to standardise security vulnerability reporting.
The free Common Vulnerability Reporting Framework (CVRF) was created to provide security practitioners and vendors with a common method for the creation, dissemination and consumption of security vulnerability data, said Mike Schiffman, chairman of ICASI's CVRF working group and a computer security researcher at Cisco.
Historically, no accepted standard for security vulnerability reporting has existed, Schiffman said.
Because each vendor uses its own format, security practitioners must manually parse through many ad-hoc bug reports and bulletins to find information that is applicable to their environment, a task that is time consuming and imperfect.
The CVRF assimilates vulnerability reporting into a machine-readable XML format, which allows security professionals to automatically process the bug reports for tasks such as priority escalation, trouble ticketing, patch management and cataloging, Schiffman said.
ICASI has encouraged all vendors that publish security documentation to employ the CVRF.
Specifically, members of the working group – including Cisco, Intel, IBM, Juniper Networks, Microsoft, Nokia, Oracle and Red Hat – are expected to begin using the framework over the next several months. Vendors will still supply vulnerability reports and bulletins through their websites.
“CVRF represents a true milestone in industry efforts to raise and broaden awareness of security vulnerabilities,” Linda Betz, president of ICASI and director of IT policy and information security at IBM, said in a statement.
“The producers of vulnerability reports will benefit from faster and more standardised reporting. End-users will be able to find, process and act upon relevant information more quickly and easily, with a higher level of confidence that the information is accurate and comprehensive."
This article originally appeared at scmagazineus.com
To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.