Red Hat is developing a new software vulnerability database with the National Institute of Standards and Technology (NIST). The database will give vendors of both open source and proprietary software a place to post official statements and security related information pertaining to their own projects and products. . At Red Hat's recommendation to NIST, the new security information service will be implemented within the agency's National Vulnerability Database (NVD) and will be based on the Common Vulnerabilities and Exposures naming standard for "an open, transparent forum to contribute information about vulnerabilities," according to Red Hat. The link for this article located at Linux Insider is no longer available. . Red Hat and NIST collaborate to create a new software security database for enhancing vulnerability reporting.. developing, software, vulnerability, database, national, institute, standards. . LinuxSecurity.com Team
The Internetworked Security Information Service (ISIS) brings together four independent projects--the Open Source Vulnerability Database, the Alldas.de defacement-tracking service, the PacketStorm software database and the vulnerability watchdog VulnWatch--into a loosely organized collaboration. "There are a lot of commercial organizations that . . . . The Internetworked Security Information Service (ISIS) brings together four independent projects--the Open Source Vulnerability Database, the Alldas.de defacement-tracking service, the PacketStorm software database and the vulnerability watchdog VulnWatch--into a loosely organized collaboration. "There are a lot of commercial organizations that put out this type of information for free, but will it always be that way?" said Chris Wysopal, director of research and development for security company @Stake. "We are calling the project 'open source' because the information in it will be open and free." The link for this article located at ZDNet is no longer available. . The Internetworked Security Information Service (ISIS) brings together four independent projects--th. internetworked, security, information, service, (isis), brings, together, independent, projects--th. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.