1 month, 10 days ago

The Open Group and the Executive Order on Improving the Nation’s Cybersecurity

On May 12, 2021, President Joe Biden issued the Executive Order on Improving the Nation’s Cybersecurity. This EO enumerates that “…the prevention, detection, assessment, and remediation of cyber incidents is a top priority and essential to national and economic security.” The EO contains a significant level of detail regarding areas of improvement for federal IT systems, as well as policy responses to be implemented by the government in support of greater security for private and public IT systems. The EO mentions in some detail the shift to zero trust security as a part of what is needed to combat cyber threats, as well as increased reliance on enhanced supply chain security.

2 months, 28 days ago

Enterprise Architecture, Open Standards, and Aircraft Certification

Aircraft safely is of interest to everyone around the world. To address aircraft safety there are certification processes in place where two organizations with the greatest involvement are the FAA (Federal Aviation Agency) in the US, and the EASA (European Union Aviation Safety Agency) in Europe.

Certification is how the FAA manages risk through safety assurance. It provides the FAA confidence that a proposed product or operation will meet FAA safety expectations to protect the public. Certification affirms that FAA requirements have been met.

5 months, 14 days ago

A Shared Language for Supply Chain Security

In the world of technology, there are paradigms of language that arise organically and artificially over time. Necessity requires a shared mode of communication for ideas and as a result, descriptors, nouns, and technical designators are created and shared. The problem arises when certain words acquire a surfeit of meaning, so much so that they paradoxically become less meaningful. There are many examples of this but for our purposes, we’re going to look at “Supply Chain Security”.

6 months, 5 days ago

Solorigate: A case study for why supply chain security is critical for governments and businesses

By Jim Hietala (VP, BD and Security), Andras Szakal (VP and CTO), John Linford Security and OTTF Forum Director) – The Open Group

In potentially the most damaging cyber-supply chain attack ever, a leading IT systems management vendor became the latest hi-tech company to suffer a major cybersecurity breach with wide-reaching consequences. The malware that caused the attack has been dubbed SUNBURST by Microsoft and code-named Solorigate by FireEye, the security consulting firm that uncovered the breach after falling victim to it late last year.

After successfully infiltrating the development environment, attackers were able to observe and learn how to subvert the vendor’s development and operations pipeline. Hackers were then able to maliciously taint the vendor’s product by planting a sophisticated trojan. Once the software, which required broad systems access, was installed in customers’ environments, the attackers were able to leverage the tainted software to exfiltrate sensitive information from within an organization’s network.

6 months, 13 days ago

Reflections on 2020 and Looking Ahead to 2021

By Steve Nunn, President and CEO, The Open Group

Happy New Year everyone!

Firstly, I hope that you, your family, and friends, have been able to stay safe during these trying times. So many around the world have lost so much in this COVID-19 pandemic which clearly will be with us for some time yet. We must, however, be heartened by the unprecedented speed with which vaccines have been developed. The delivery and administration of these vaccines has only just begun, of course, but we have good reason to be optimistic about the coming months.

7 months, 16 days ago

Updates to the Open FAIR™ Body of Knowledge, Part 3

The Open Group Security Forum is thrilled to announce the publication of an update to the Open FAIR™ Body of Knowledge (BoK). The Open FAIR BoK is comprised of The Open Group Risk Taxonomy (O-RT) Standard and The Open Group Risk Analysis (O-RA) Standard. The Open Group initiated a standards effort regarding FAIR ~10 years ago, and these standards define the official, open, vendor-neutral and consensus-developed definition of FAIR.

This blog post is the third of three in a series to describe updates to the Open FAIR™ Body of Knowledge. It will describe specific updates to O-RT to bring it to Version 3.0. The first post described revisions made to both O-RA and O-RT for consistency between the documents; the second post described specific updates to O-RA to bring it to Version 2.0.

7 months, 23 days ago

Updates to the Open FAIR™ Body of Knowledge, Part 2

The Open Group Security Forum is thrilled to announce the publication of an update to the Open FAIR™ Body of Knowledge (BoK). The Open FAIR BoK is comprised of The Open Group Risk Taxonomy (O-RT) Standard and The Open Group Risk Analysis (O-RA) Standard. The Open Group initiated a standards effort regarding FAIR ~10 years ago, and these standards define the official, open, vendor-neutral and consensus-developed definition of FAIR.

8 months, 1 day ago

Updates to the Open FAIR™ Body of Knowledge, Part 1

The Open Group Security Forum is thrilled to announce the publication of an update to the Open FAIR™ Body of Knowledge (BoK). The Open FAIR BoK is comprised of The Open Group Risk Taxonomy (O-RT) Standard and The Open Group Risk Analysis (O-RA) Standard. The Open Group initiated a standards effort regarding FAIR ~10 years ago, and these standards define the official, open, vendor-neutral and consensus-developed definition of FAIR.

8 months, 22 days ago

The Open Group ‘Digital-First’ Virtual Event October 26 – 29, 2020 – Highlights Blog

In the ongoing transition to Digital-First, an increasing number of technology executives, managers, and practitioners are looking for new approaches that will help them to make sense of the evolving business landscape and deliver digital products and services.

As an organization that is known for solving business issues through global industry collaboration, The Open Group hosted its third virtual event October 26-29, 2020, which provided over 3,300 registrants with the opportunity to discover the critical digital standards that enable a smooth transition to a Digital-First enterprise.

8 months, 23 days ago

Schneider Electric and Aramco to Collaborate on O-PAS™ Automation Test Bed

Schneider Electric, the leader in digital transformation of energy management and automation, and Aramco, the world’s pre-eminent integrated energy and chemicals company that drives global commerce and enhances the daily lives of people around the globe, today announced they have signed a memorandum of understanding to collaborate on assessing emerging technologies based on The Open Group Open Process Automation™ Standard (O-PAS). Testing will take place at a new built-for-purpose test bed in the Saudi Schneider Electric Innovation and Research Center in Dhahran Techno Valley, Saudi Arabia.

8 months, 27 days ago

The Open Group at “Experience IT NM”

On November 4 and 5, 2020, the New Mexico Technology Council is hosting its virtual event entitled Experience IT NM. The New Mexico Technology Council a member-driven association of businesses, organizations, and tech professionals working together to promote the growth and success of New Mexico’s technology business sectors. Its members include a diverse mix of New Mexico companies, cities, and universities and colleges.