Work item:
|
X.1526
|
Subject/title:
|
Language for the open definition of vulnerabilities and for the assessment of a system state
|
Status:
|
Approved on 2014-01-24
|
Approval process:
|
TAP
|
Type of work item:
|
Recommendation
|
Version:
|
Rev.
|
Equivalent number:
|
-
|
Timing:
|
-
|
Liaison:
|
-
|
Supporting members:
|
-
|
Summary:
|
Recommendation ITU-T X.1526 on the language for the open definition of vulnerabilities and for the assessment of a system state (also known as, Open Vulnerability and Assessment Language, OVAL) includes the three main steps of the assessment process: representing configuration information of endpoints for testing; analysing the endpoint for the presence of the specified machine state (vulnerability, configuration, patch state, etc.) and reporting the results of this assessment. The purpose of OVAL is to provide an international, information security, community standard to promote open and publicly available security content and to standardize the transfer of this information across the entire spectrum of security tools and services. OVAL is a language used to encode endpoint details, and an assortment of content repositories held throughout the community.
|
Comment:
|
Report COM 17 R 15 was revised in the January meeting in the French and English versions.
|
Reference(s):
|
|
|
Historic references:
|
Contact(s):
|
|
ITU-T A.5 justification(s): |
|
|
|
First registration in the WP:
2013-09-10 15:51:27
|
Last update:
2014-03-10 17:01:50
|