Home > SOA Tips > XML Developer > National standards, security bodies release security checklists spec
SOA Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

XML DEVELOPER

National standards, security bodies release security checklists spec


Ed Tittel
02.09.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In January 2005, a joint task force of security and standards professionals from NIST (National Institute of Standards and Technology) and the NSA (the National Security Agency) released a specification for the Extensible Configuration Checklist Description Format, aka XCCDF (Adobe Acrobat required.) This specification permits checking using any of a number of configuration check tools, and was based on MITRE's Open Vulnerability Assessment Language (OVAL). Document and reference metadata is based on the Dublin Core Metadata element set.

This standard is of particular interest to industry and government security experts, analysts, auditors, and those who develop security management products. The sponsoring organizations—namely, NIST and the NSA—encourage public feedback to improve this specification. XCCDF is built using XML markup according to a formal XML Schema, which means that documents that conform to XCCDF syntax and structure can be validated using an XML parser that can check conformance to XML Schema requirements (for example, XMLSpy).

The XCCDF specification aims to address numerous concerns in the area of information security, including the following:

  • Information interchange
  • Document generation
  • Automated compliance testing
  • Compliance scoring
  • Creation of a data model and formats for storing benchmark compliance testing

  • In a nutshell, XCCDF aims to create a common foundation for defining security checklists and benchmarks, along with configuration guidance, so as to enable more consistent and widespread use of best security practices and procedures.

    As such, XCCDF documents seek to define a well-organized collection of security configuration rules for a specific set of target systems. That said, XCCDF is designed to be both portable and platform-neutral to facilitate easy sharing and use of its checklists, benchmarks, and security guidance information. The driving notion behind a security configuration checklist is a set of rules or instructions for configuring some IT product or system to conform to a security baselines or some specific security benchmark level. By creating a formal notation that works with configuration checkers, it becomes much easier to check products and systems for compliance, while maintaining platform neutrality so that checklists need not target only specific systems or platforms to check, or specific configuration checkers within which to work.

    Ed Tittel is a full-time writer and trainer whose interests include XML and development topics, along with IT Certification and information security topics. E-mail Ed at etittel@techtarget.com with comments, questions, or suggested topics or tools for review.

    Rate this Tip
    To rate tips, you must be a member of SearchSOA.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    XML Developer
    Use the soapUI software tool to tame WSDL
    WSDL 2.0, new messaging for Web services
    Using RELAX NG For data integration
    Efficient XML Interchange tackles data verbosity
    XML to DDL imports, synchronizes database schemata
    The basics of MathML 3.0
    Migrating to XSLT 2.0
    What's up with XML 2.0?
    Say hello to XPath 2.0
    Podcasting software covers many bases

    XML and XML schema
    What's the future of XML?
    SOA pattern of the week (#7): policy centralization
    Try XML-based Extensible Business Reporting Language (XBRL) for accounting reports
    What's new at the W3C
    Ganymede: Modeling tools target SOA, UML
    Data services mashups emerge for SOA
    Making sense of data services mashups
    XML turns 10
    SOA helps save 100-year-old business
    Oracle maps heterogeneous data services strategy for SOA

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    class diagram  (SearchSOA.com)
    Fast Infoset (FI)  (SearchSOA.com)
    GeoRSS  (SearchSOA.com)
    Keyhole Markup Language  (SearchSOA.com)
    RELAX NG  (SearchSOA.com)
    state diagram  (SearchSOA.com)
    Universal Business Language  (SearchSOA.com)
    Vector Markup Language  (SearchSOA.com)
    XML infoset  (SearchSOA.com)
    XML pipeline  (SearchSOA.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    SOA Trends and Strategy - SOA Education, SOA Development, SOA Implementations
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2001 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts