ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Oasis to create an XML security standard

Martin LaMonica CNET News.com

Published: 28 May 2003 15:56 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The Organisation for the Advancement of Structured Information Standards, or Oasis, on Wednesday announced the formation of the Web Application Security (WAS) technical committee, which will develop a model and a data format for describing security problems.

The planned standard will convey information via an XML document to classify and rate the risks of vulnerabilities once they are discovered. The companies participating in the Oasis WAS technical committee include NetContinuum, Qualys, Sanctum, and SPI Dynamics.

Right now, security advisories are published in a variety of formats, something that hampers effective communication across different organisations, Mark Curphey, chair of the Oasis WAS Technical Committee, said in a statement. Corporations, as well as government institutions and law enforcement agencies count on rapid access to security information in order to patch network holes that are vulnerable to hacks or break-ins.

"WAS will allow vulnerabilities to be published and received in a consistent manner. Risks will be universally understood by law enforcement agencies, government representatives, companies and organisations, regardless of which tools or technologies are used," Curphey said.

The need for a better way of sharing data on security risks is becoming increasingly important, particularly as the use of Web services takes hold, said Ron Schmelzer, an analyst at ZapThink.

Web services applications use standardised means to make it easier to share information between applications. That simplified data exchange will usher in many more security problems, which creates a growing need to effectively communicate vulnerabilities, he said.

Web services applications "will continuously need to be on the lookout for security vulnerabilities and interact with each other to provide a cohesive network of secured systems," said Schmelzer.

The proposed WAS specification will work in conjunction with other standards under development at Oasis, including the Application Vulnerability Description Language (AVDL). The WAS specification will define how information will be shared, while AVDL will describe the potential vulnerability.

By combining the WAS with AVDL, companies that track network security problems and have a common format to understand the severity of vulnerabilities, according to Oasis.

The WAS Technical Committee will consider related work from other groups and companies, including a similar language under development at the open-source Open Web Application Security Project.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
58 out of 131 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Contract Specialist - Newcastle-00051050

Key Responsibilities: Supports the lead Contract Manager in reviewing and managing the contractual obligations of Accenture and other contractual ...

QTP Tester Law Sector London 40K 45K

A leading company providing software and information services to the legal sector require an QTP specialist to work on testing their web based ...

Senior Project Manager

CALLS FROM AGENCIES Your main responsibilities will include: - Creating a Project Scope Document - Producing a project plan detailing the required ...

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal