|
|||||||||||
|
RE: ADVL vs VulnXML
From: David Burton <dburton(at)netcontinuum.com>
Date: Wed Apr 02 2003 - 18:08:26 EST
We are proposing AVDL to address the broader business-oriented problem of how companies actually manage ongoing application security risk on a day-to-day basis. Managing application security risk in a highly dynamic environment can be an extraordinary challenge for security administrators. Fortunately, there are now a wide variety of best-of-breed products on the market to help companies with the task of discovering application vulnerabilities, blocking application-layer attacks, repairing vulnerable web sites, distributing patches and managing security events. Unfortunately, these products have no universal way to communicate with each other, making pragmatic management of this risk a highly manual, and often complex, process. The goal of AVDL is to help companies begin managing the full application security lifecycle by providing a more uniform way of communicating application security vulnerabilities, policies and events via XML. It is the full intent of the vendors proposing AVDL to repurpose any positive progress that has already been made by the security community to date.
Dave Burton
-----Original Message-----
I just noticed on OASIS the newly proposed Application Vulnerbility
Description
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=avdl How does this differ from OWASP VulnXML (http://www.owasp.org/vulnxml/) ? I don't see anyone from OWASP on the committee which is kinda interesting given they invented the concept over a year ago and have a database running coming along so I hear. I hope this won't be a case of a few vendors trying to take thought leadership for something the open source community has already done! Concerned about your privacy? Follow this link to get FREE encrypted email: https://www.hushmail.com/?l=2 Big $$$ to be made with the HushMail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427 Received on Wed Apr 2 19:05:19 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:50 EDT |
||||||||||
|
|||||||||||