The OASIS international consortium has announced an industry initiative to bring interoperability and data sharing across cybersecurity products. With initial open source content and code contributed by IBM Security and McAfee, and formed under the auspices of OASIS, the Open Cybersecurity Alliance (OCA) brings together organisations and individuals from around the world to develop open source security technologies which can freely exchange information, insights, analytics, and orchestrated responses.
Connecting these tools and data requires complex integrations, taking away from time that could be spent hunting and responding to threats. To accelerate and optimise security for enterprise users, the OCA will develop protocols and standards which enable tools to work together and share information across vendors. The aim is to simplify the integration of security technologies across the threat lifecycle – from threat hunting and detection, to analytics, operations and response – so that products can work together out of the box.
The purpose of the OCA is to develop and promote sets of open source common content, code, tooling, patterns, and practices for interoperability and sharing data among cybersecurity tools. For enterprise users, this means improving security visibility and ability to discover new insights and findings that might otherwise have been missed. They can also extract more value from existing products and reducing vendor lock-in. Also, they can connect data and share insights across products.
Founders of the Alliance, IBM Security and McAfee, are joined in the initiative by Advanced Cyber Security Corp, Corsa, CrowdStrike, CyberArk, Cybereason, DFLabs, EclecticIQ, Electric Power Research Institute, Fortinet, Indegy, New Context, ReversingLabs, SafeBreach, Syncurity, ThreatQuotient, and Tufin. The OCA welcomes participation from additional organisations and individual contributors.
“Today, organisations struggle without a standard language when sharing data between products and tools,” said Carol Geyer, Chief Development Officer of OASIS. “We have seen efforts emerge to foster data exchange, but what has been missing is the ability for each tool to transmit and receive these messages in a standardised format, resulting in more expensive and time-consuming integration costs. The aim of the OCA is to accelerate the open sharing concept making it easier for enterprises to manage and operate.”
“Attackers maximise damage by sharing data with one another. Our best defense strategy is to share data too,” said D.J. Long, Vice President Business Development, McAfee. “The OCA creed is ‘Integrate once, reuse everywhere’ which builds upon McAfee’s open philosophy that led to the OpenDXL project in 2016. Organisations will be able to seamlessly exchange data between products and tools from any provider that adopts the OCA project deliverables. We’re looking at the potential for unprecedented real-time security intelligence.”
Discussion about this post