| By Red Hat News Desk | Article Rating: |
|
| June 22, 2006 12:30 PM EDT | Reads: |
8,284 |
Red Hat, provider of open source
solutions to the enterprise, announced compatibility
certification with Open Vulnerability and Assessment Language (OVAL)
definitions for Red Hat Enterprise Linux 3 and 4 security advisories.
Red Hat will now produce and support OVAL patch definitions to provide
a structured and machine-readable version of advisories, allowing
OVAL-compatible tools to accurately test for the presence of
vulnerabilities.
With OVAL compatibility, Red Hat Enterprise Linux users can benefit from the utilization of third-party, OVAL-compatible patch auditing and compliance tools to audit their systems. By providing an alternative, machine-readable view of Red Hat security errata advisories, users can now integrate data about vulnerabilities from the Red Hat Security Response team into their existing vulnerability management processes. All users will continue to use Red Hat Network to manually or automatically obtain updates in addition to this new security view.
"As a founding member of the OVAL board, we've been working with the MITRE Corporation on OVAL for many years," said Mark J. Cox, Red Hat Security Response Team Lead, Red Hat. "Just as the MITRE CVE project has become common for dealing with vulnerability patches, we expect the same rapid adoption for the OVAL project. This initiative forms part of our commitment to make the deployment of security ubiquitous through the use of industry-wide standards."
"The translation of Red Hat errata into OVAL allows organizations looking to secure Red Hat operating systems to rely on open, standards-based tests that can be digested by assessment tools in order to perform instant and automated evaluations," said Matthew Wojcik, Senior Information Security Engineer and OVAL Moderator, the MITRE Corporation. "By pursuing OVAL compatibility, Red Hat has declared their commitment to open standards and is helping to raise the bar for patch management and vulnerability assessment in the marketplace."
The OVAL project, maintained by the MITRE Corporation, is an international information-security effort that promotes open and publicly available security content, and seeks to standardize the transfer of this information across the entire spectrum of security tools and services.
Published June 22, 2006 Reads 8,284
Copyright © 2006 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Red Hat News Desk
Red Hat News Desk trawls the world's news information sources and brings you timely updates on its flagship Red Hat Enterprise Linux as well as the company's other product lines including database, content, and collaboration management applications; server and embedded operating systems; and software - including its most recent virtualization offerings.
- Oracle To Keynote Cloud Computing Expo
- The Difference Between Web Hosting and Cloud Computing
- GovIT Expo Highlights Cloud Computing
- Ajax in RichFaces 3.3, JSF 2 and RichFaces 4
- The End of IT 1.0 As We Know It Has Begun
- Cloud Computing Best Practices
- Gang of Four Creates Cloud BI Stack
- Tactical Cloud Computing Panel at 1st Annual GovIT Expo
- Product Evaluation: JBoss TCO Calculator
- The JBoss SOA Assessment Tool: Spend Less, Do More
- Oracle To Keynote Cloud Computing Expo
- SOA & Cloud Bootcamp: Comparing Cloud Computing Providers
- The Difference Between Web Hosting and Cloud Computing
- Peeking Through the Keyhole on Sun’s Boardroom
- GovIT Expo Highlights Cloud Computing
- Finding New Life For SOA in the Cloud
- Ajax in RichFaces 3.3, JSF 2 and RichFaces 4
- Red Hat Announces Premier Cloud Provider Certification and Partner Program
- SingTel Throws in its Lot with the Cloud
- The End of IT 1.0 As We Know It Has Begun
- Virtualization Conference Keynote Webcast Live on SYS-CON.TV
- Red Hat Drops Consumer Linux, Sponsors Community Led Fedora Project
- Citrix & Dell Partner on Server Virtualization
- Red Hat CTO Keynoting Today on The Future of the Virtual Enterprise
- Red Hat Named "Platinum Sponsor" of Virtualization Conference & Expo
- Red Hat vs Sun Battle of Words Heats Up
- Forbes' "Red Hat = Linux" Spin Angers Sun Microsystems COO
- SOA, Virtualization and Web 2.0: BEA's Deputy CTO Connects the Dots
- Getting Started with Red Hat Linux
- Red Hat to Deploy "NX" vs Viruses
































