“…The Incident Object Description Exchange Format (IODEF) defines a data model for reporting incident information and provides an XML schema, while the Extensible Configuration Checklist Description Format defines an XML schema on security configuration checklist. There are many other information structures, including the Asset Reporting Format, Common Attack Pattern Enumeration and Classification, Common Configuration Enumeration (CCE), Common Configuration Scoring System, Common Event Expression, Common Platform Enumeration (CPE), Common Vulnerability Reporting Framework (CVRF), Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration, Common Weakness Scoring System, Cyber Observable Expression, Malware Attribute Enumeration and Characterization, Malware Metadata Exchange Format, Open Checklist Interactive Language, Open Vulnerability and Assessment Language (OVAL), Structured Threat Information Exchange, Software Identification, Web Services Agreement Specification, and Extensible Access Control Markup Language . These are useful for accumulating cybersecurity‐related information and building repositories.…”