DocumentCode
384946
Title
Managing vulnerabilities in your commercial-off-the-shelf (COTS) systems using an industry standards effort
Author
Martin, Robert A.
Author_Institution
Mitre Corp., Bedford, MA, USA
Volume
1
fYear
2002
fDate
27-31 Oct. 2002
Abstract
Organizations around the world, in every type of industry and market, are moving towards networks that are based on the Internet protocols. In addition, third-party commercial and open source software has become a critical element to these organizations and the infrastructure of networks, utilities, and services they rely upon to function. That means the software problems in these commercial-off-the-shelf (COTS) software products can quickly cause significant difficulties for any organization. When such software problems have security implications, they are referred to as "vulnerabilities." This paper discusses the ways of finding out about the vulnerabilities that exist in the COTS and open source software products used by an organization, or by the infrastructures that the organization is dependent upon. CVE, the common vulnerabilities and exposures initiative [cve.mitre.org], is a new international, community-based effort from industry, government, and academia that is working to create an organizing mechanism to make finding and fixing these COTS and open source software product vulnerabilities more rapid and efficient.
Keywords
Internet; data privacy; risk management; security of data; software packages; software reliability; software standards; COTS software product problems; CVE; Internet protocol networks; commercial-off-the-shelf software product vulnerability management; common vulnerabilities/exposures initiative; industry standards; industry/government/academia organizing mechanisms; networks/utilities/services infrastructure; open source software; risk management; software security problems; third-party commercial software; vulnerability finding/fixing; Business; Computer errors; Data security; Government; Internet; Military computing; Open source software; Power system security; Risk management; Standards organizations;
fLanguage
English
Publisher
ieee
Conference_Titel
Digital Avionics Systems Conference, 2002. Proceedings. The 21st
Print_ISBN
0-7803-7367-7
Type
conf
DOI
10.1109/DASC.2002.1067959
Filename
1067959
Link To Document