Skip to content

OASIS OHDF TC: supporting version control for Work Product artifacts developed by members of the OASIS Heimdall Data Format (OHDF) TC, including prose specification editing and secondary artifacts like meeting minutes, productivity code, etc. https://github.com/organizations/oasis-tcs/ohdf

License

oasis-tcs/ohdf

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

23 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

README

Members of the OASIS Heimdall Data Format (OHDF) TC create and manage technical content in this TC GitHub repository as part of the TC's chartered work (i.e., the program of work and deliverables described in its charter).

OASIS TC GitHub repositories, as described in GitHub Repositories for OASIS TC Members' Chartered Work, are governed by the OASIS TC Process, IPR Policy, and other policies. While they make use of public GitHub repositories, these TC GitHub repositories are distinct from OASIS Open Repositories, which are used for development of open source licensed content.

Description

The OHDF TC's goal is to develop a common format for exchanging normalized security data between cybersecurity tools. A standard vendor-agnostic data format will support cybersecurity product interoperability without having to create customized integrations.

Security tools typically generate data in unique formats that require multiple dashboards and utilities to review. This leads to a time-consuming process for completing security assessments, data in disparate locations and inconsistent semantics of data elements across formats.

In addition, few security tools provide context to relevant compliance standards for comparison across security tools.

OHDF provides a common data exchange format that:

  • Enables the consistent integration, aggregation, and analysis of security data from all available sources
  • Preserves data integrity with original source data
  • Maximizes interoperability and data sharing Facilitates the transformation and transport of data between security/management processes or technologies
  • Allows for the mapping and enrichment of security data to relevant compliance standards (GDPR, NIST SP 800-53, PCI-DSS, etc.)

The TC will update OHDF as industry needs evolve.

Numerous stakeholders and adopters can benefit from the work of the OHDF TC:

  • For Commercial and Vendor Cybersecurity Partners, OHDF defines a standardized, interoperable target format that vendor tools can consume across their customer base consistently and that is easily managed within the product lifecycle.

  • For the Open Source Community, OHDF enables easy integration with commercial solutions without the need for direct partnerships. For Government Agencies, OHDF can streamline business processes by having a standard, open source, machine-readable format for all security data.

  • For Academia, OHDF offers a structured way to communicate and enhance research findings throughout the security community.

  • For Corporate and Federal CISOs/CIOs, OHDF can increase visibility across the enterprise by taking advantage of normalized security data in a standard format that supports risk information interoperability from a broad range of inputs to support security risk decision-making.

  • For Security Engineers, OHDF can reduce resource requirements for multiple security data types by standardizing formatting across disparate security tools.

  • For Risk Managers, OHDF can improve decision making by using a standardized format to facilitate automation, standardize communication requirements, and inform risk-based analysis.

  • For DevSecOps/Software Engineers, OHDF can streamline CI/CD processes by leveraging a standardized format to collate/aggregate normalized security data to support automated and continuous security processes.

Contributions

As stated in this repository's CONTRIBUTING file, contributors to this repository are expected to be Members of the OASIS OHDF TC, for any substantive change requests. Anyone wishing to contribute to this GitHub project and participate in the TC's technical activity is invited to join as an OASIS TC Member. Public feedback is also accepted, subject to the terms of the OASIS Feedback License.

Licensing

Please see the LICENSE file for description of the license terms and OASIS policies applicable to the TC's work in this GitHub project. Content in this repository is intended to be part of the OHDF TC's permanent record of activity, visible and freely available for all to use, subject to applicable OASIS policies, as presented in the repository LICENSE file.

Contact

Please send questions or comments about OASIS TC GitHub repositories to OASIS Open Project administrator. For questions about content in this repository, please contact the TC Chair or Co-Chairs as listed on the the OHDF TC's home page.

About

OASIS OHDF TC: supporting version control for Work Product artifacts developed by members of the OASIS Heimdall Data Format (OHDF) TC, including prose specification editing and secondary artifacts like meeting minutes, productivity code, etc. https://github.com/organizations/oasis-tcs/ohdf

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published