2011
DOI: 10.6028/nist.ir.7694
|View full text |Cite
|
Sign up to set email alerts
|

Specification for the asset reporting format 1.1

Abstract: The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the U.S. economy and public welfare by providing technical leadership for the nation"s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology. ITL"s responsibilities include the development of technical, physical, administrative, and m… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3

Citation Types

0
1
0

Year Published

2014
2014
2022
2022

Publication Types

Select...
3

Relationship

0
3

Authors

Journals

citations
Cited by 3 publications
(3 citation statements)
references
References 0 publications
0
1
0
Order By: Relevance
“…In [22], a model of data exchange format expression for aggregated assets is introduced. Asset summary reporting may be used as a part of an asset reporting format document [23]. In [23], a data model of data exchange format expression for assets and relationships between them and reports is introduced.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…In [22], a model of data exchange format expression for aggregated assets is introduced. Asset summary reporting may be used as a part of an asset reporting format document [23]. In [23], a data model of data exchange format expression for assets and relationships between them and reports is introduced.…”
Section: Related Workmentioning
confidence: 99%
“…Asset summary reporting may be used as a part of an asset reporting format document [23]. In [23], a data model of data exchange format expression for assets and relationships between them and reports is introduced. However, there is still an open question as to how to detect assets before their identification and reporting on them.…”
Section: Related Workmentioning
confidence: 99%
“…The Incident Object Description Exchange Format (IODEF) defines a data model for reporting incident information and provides an XML schema, while the Extensible Configuration Checklist Description Format defines an XML schema on security configuration checklist. There are many other information structures, including the Asset Reporting Format, Common Attack Pattern Enumeration and Classification, Common Configuration Enumeration (CCE), Common Configuration Scoring System, Common Event Expression, Common Platform Enumeration (CPE), Common Vulnerability Reporting Framework (CVRF), Common Vulnerability Scoring System (CVSS), Common Weakness Enumeration, Common Weakness Scoring System, Cyber Observable Expression, Malware Attribute Enumeration and Characterization, Malware Metadata Exchange Format, Open Checklist Interactive Language, Open Vulnerability and Assessment Language (OVAL), Structured Threat Information Exchange, Software Identification, Web Services Agreement Specification, and Extensible Access Control Markup Language . These are useful for accumulating cybersecurity‐related information and building repositories.…”
Section: Related Workmentioning
confidence: 99%