Editor’s Note: For a discussion on the regulatory use of market driven consortia standards versus voluntary consensus standards, see here.
From: OASIS Advancing open standards for the information society
Boeing, Check Point, Cisco, Dell, EMC, eSentire, Fortinet, Fujitsu, IBM, iboss, iSIGHT Partners, NEC, New Context, Palo Alto Networks, Resilient, Securonix, Soltra, TELUS, ThreatQuotient, ThreatStream, TruSTAR, US DHS Office of Cybersecurity and Communications, US NIST, ViaSat, and Others Collaborate on International Standards to Prevent and Defend Against Cyber Attack
Three foundational cyber security specifications, STIX, TAXII, and CybOX, are now being advanced through the international open standards process at OASIS. In a transition headed by the U.S. Department of Homeland Security, a record number of organizations from around the world have come together in the new OASIS Cyber Threat Intelligence (CTI) Technical Committee to develop and promote adoption of standards that enable cyber threat intelligence to be analyzed and shared among trusted partners and communities. The work will support automated information analysis and sharing for cyber security situational awareness, real-time network defense, and sophisticated threat characterization and response.
***
“STIX, TAXII, and CybOX have reached a level of maturity where they will benefit from a more formal collaboration guided by a globally recognized standards development process that ensures transparency, international participation, stability, reciprocity, and perpetual ease of access,” said Richard Struse of the U.S. Department of Homeland Security Office of Cybersecurity and Communications, who chairs the OASIS CTI Technical Committee. “OASIS provides all of this, and is an ANSI-accredited developer of American National Standards as well as an authorized PAS Submitter to ISO. Having these certifications available to STIX, TAXII, and CybOX means they will be implementable by the broadest possible stakeholder community.”
Leave a Reply