Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
NIST, DHS add national vulnerability database to mix
Robert Lemos, SecurityFocus 2005-08-12

The National Institute of Standards and Technology and the Department of Homeland Security took the wraps off the National Vulnerability Database this week, but questions still remain whether the federal initiative improves upon existing databases or just adds another choice to the current collections of flaws.

Comments Mode:
What a total waste of federal funds!!! 2005-08-12
Age (1 replies)
Re: What a total waste of federal funds!!! 2005-08-16
Certified Security Professional (1 replies)
Re: Re: What a total waste of federal funds!!! 2005-08-19
Age
The point of my statement is quite simple. We already have mature vulnerability databases in the form of the OSVDB & ISS X-Force Database. Both databases are peer reviewed, and are open for comment. Both are superior to the NVD.

The OSVDB is ran by several security professionals from the elite within the security community. ISS X-Force likewise has a stellar reputation for accuracy. These organizations do have their own rigorous standards, as seen by the quality of their work.

Your assumption that the OSVDB & ISS will manipulate data within their databases is just as likely as the NVD personnel altering the NVD, in order to prove to obtain more funding for the NVD project.

This is a prime example of something the private industry is doing better, faster, cheaper than the federal government.

Common Criteria evaluations & FIPS compliancies have been sourced now to commercial laboratories, because they are faster and more economical than government. They have more incentive to perform their work better.

If Commercial interests can be trusted to perform CC & FIPS work, then vulnerability databases also belong in the private sector.

As for your arguement about the size of an organization being relevant, ISS X-Force & OSVDB are much larger than the NVD team. Although the size of the organization has little consequence on the quality of the output, again your own points defeat you.

In general, I find your response to be characterized by a logical fallacy "Government is to be trusted more so than private, open source, or commercial entities". Is that why the Clipper chip is so popular?

Cheers!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11278/32331#32331
Poker Rating 2006-01-28
Alex







 

Privacy Statement
Copyright 2008, SecurityFocus