Secure Coding mailing list archives

The Next Frontier


From: ljknews at mac.com (ljknews)
Date: Wed, 27 Jun 2007 17:08:19 -0400

At 4:38 PM -0400 6/27/07, Paco Hope wrote:
On 6/26/07 5:00 PM, "McGovern, James F (HTSC, IT)" <James.McGovern at thehartford.com> wrote:

Would there be value in terms of defining an XML schema that all tools could emit audit information to?

You might want to take a look at what the Fortify guys already do. Their "FVDL" (Fortify Vulnerability Description 
Language) is XML written to a specific schema

In the US, the federal government has a lot of that going on:

http://nvd.nist.gov/scap.cfm

but they only support certain platforms, like Windows.
-- 
Larry Kilgallen


Current thread: