Why is the AVDL standard necessary?
Enterprise customers are asking their suppliers to provide products that interoperate. A consistent definition of application security vulnerabilities is a significant step towards that goal. Today, organizations are actively engaged in a project whereby XML-based vulnerability assessment output will be used to improve the effectiveness of attack prevention, event correlation, and remediation technologies. XML establishes a common framework, but XML alone does not ensure vendor interoperability. In fact, the first implementation of these XML-based information exchanges will be proprietary, as no suitable standard exists. Members of the OASIS AVDL Technical Committee believe that customers should ultimately be given the benefit of interoperability between all vendors in each category of the application security lifecycle, allowing them to select those products that offer the most useful functionality for their unique and individual requirements. As a vendor-neutral open forum, OASIS is