OASIS Common Security Advisory Framework (CSAF) TC
Standardizing automated disclosure of cybersecurity vulnerability issues
Omar Santos, osantos@cisco.com, Chair
Table of Contents
- Announcements
- Overview
- Officers
- Subcommittees
- TC Liaisons
- TC Tools and Approved Publications
- Technical Work Produced by the Committee
- OASIS TC Open Repositories Sponsored by the Committee
- Expository Work Produced by the Committee
- External Resources
- Mailing Lists and Comments
- Press Coverage and Commentary
- Additional Information
CSAF Common Vulnerability Reporting Framework (CVRF) V1.2 is approved as an OASIS Committee Specification. For details, see the announcement.
See press release: OASIS Awards 2017 Open Standards Cup to TOSCA for Cloud Portability and to CSAF for Cybersecurity Disclosure
Participation in the OASIS CSAF TC is open to all interested parties. Contact join@oasis-open.org for more information.
The OASIS CSAF Technical Committee is chartered to make a major revision to the Common Vulnerability Reporting Framework (CVRF) under a new name for the framework that reflects the primary purpose: a Common Security Advisory Framework (CSAF). TC deliverables are designed standardize existing practice in structured machine-readable vulnerability-related advisories and further refine those standards over time.
For more information on the CSAF TC, see the TC Charter.
- Chair: Omar Santos ( Cisco)
No subcommittees have been formed for this TC.
No TC Liaisons have been announced for this TC.
TC Tools and Approved Publications
Technical Work Produced by the Committee
“CSAF Common Vulnerability Reporting Framework (CVRF) Version 1.2” Committee Specification 01. 13 September 2017, Formats: HTML, PDF (Authoritative).
OASIS TC Open Repositories Sponsored by the Committee
- csaf-documentation: GitHub repository for management of non-normative information about the work of the CSAF Technical Committee, including documentation
- csaf-parser: CSAF Parser tool for parsing and checking the syntax of the Common Vulnerability Reporting Framework (CVRF) content
Expository Work Produced by the Committee
There are no approved expository work products for this TC yet.
Although not produced by the OASIS CSAF TC, the following information offers useful insights into its work.
External resources have not yet been identified.
csaf: the discussion list used by TC members to conduct Committee work. TC membership is required to post, and TC members are automatically subscribed. The public may view the OASIS list archives, also mirrored by MarkLogic at MarkMail.org.
csaf-comment: a public mailing list for providing feedback on the technical work of the OASIS CSAF TC. Send a comment or view the OASIS comment list archives, also mirrored by MarkLogic at MarkMail.org.
- OASIS Awards 2017 Open Standards Cup to TOSCA for Cloud Portability and to CSAF for Cybersecurity Disclosure; 14 Aug 2017
- OASIS Advances Standard for Automated Disclosure of Cybersecurity Vulnerability Issues; Cisco, EclecticIQ, FireEye, Hitachi, IBM, Intel, LookingGlass, NIST, NC4, Oracle, Red Hat, SafeNet, TELUS, VeriSign, Center for Internet Security, CERT/CC, US DHS, and Others Define Common Security Advisory Framework (CSAF); 17 Jan 2017
- ICASI Transfers Development of Security Open Standard to OASIS; 16 Nov 2016
Providing Feedback: OASIS welcomes feedback on its technical activities from potential users, developers, and others to better assure the interoperability and quality of OASIS work.
TC Participants
Representing these OASIS Foundationals and Sponsors:
- Accenture
- Cisco Systems
- Cryptsoft Pty Ltd.
- EclecticIQ
- FireEye, Inc.
- Hitachi, Ltd.
- McAfee
- Microsoft
- NC4
- NIST
- Oracle
- Red Hat
- TELUS
View full TC roster from 'Membership' link above.