MITRE
 
About Us Our Work Employment News & Events
MITRE Remote Access for MITRE Employees Site Map
Home > Our Work > Technical Papers >

Transformational Vulnerability Management Through Standards

March 2005

Robert A. Martin, The MITRE Corporation

ABSTRACT

The Department of Defense's new enterprise licenses for vulnerability assessment and remediation tools [1,2] call for use of capabilities that conform to both the Common Vulnerabilities and Exposures (CVE) [3] and Open Vulnerability and Assessment Language (OVAL) [4] standards efforts, as does a new Air Force enterprise-wide software agreement with Microsoft [5]. These contracting activities are part of a larger transformation of the Department of Defense's (DoD's) management and measurement of the information assurance posture of their network-enabled systems with respect to vulnerabilities, configuration settings, and policy compliance. In combination with procedural changes, the adoption of these [6] and other standards, such as the National Security Agency's (NSA's) Extensible Markup Language (XML) Configuration Checklist Data Format (XCCDF) [7], are making it possible to radically improve the accuracy and timeliness of the DoD's remediation and measurement activities which are critical to ensuring the network and systems integrity of their network-centric warfare capabilities.

» Download Paper [PDF, 627KB]

Additional Search Keywords

N/A

 

Page last updated: April 13, 2005   |   Top of page

Homeland Security Center Center for Enterprise Modernization Command, Control, Communications and Intelligence Center Center for Advanced Aviation System Development

 
 
 

Serving as Architects of Information Advantage.™
Copyright © 1997-2008, The MITRE Corporation. All rights reserved.
MITRE is a registered trademark of The MITRE Corporation.
Material on this site may be copied and distributed with permission only.

 

Privacy Policy | Contact Us

Boston Business Journal Best Places to Work 2007 Computerworld Best Places to Work in IT 2005-2008 Fortune 100 Best Places to Work 2002-2008