Industry agrees on security vulnerability reporting format


"End users will be able to find, process and act upon relevant information more quickly and easily, with a higher level of confidence that the information is accurate and comprehensive. Consumers will ultimately benefit with safer systems and applications," she said.

ICASI's members include Microsoft, Cisco, Juniper Networks, Nokia, Amazon, IBM and Intel, but it would be a mistake to see this as another high-level standard designed to make life easier for big vendors.

One unspoken and longer-term hope is that CVRF will make it easier for independent researchers to submit vulnerability data to companies higher up the chain, a process that has been fraught with complexity until now. Being able to submit data using a machine-readable XML system should allow security information to circulate more rapidly than has happened in the past, without excluding individuals.

ICASI has published an that describes its inner workings in detail.