Seems like a Schema to me

Reading any representation of standards will at some point propose a common schema for application and digital communication.  Tom O’Reilly’s published “What is Web 2.0, in which he summarizes these points as Core Competencies for companies claiming their software or service meets the standard to be described as Web 2.0.  If a framework for all standards has any hope for success, it will at the very least be Web 2.0 compliant.  His summary suggests that success comes from:

  • Services, not packaged software, with cost-effective scalability
  • Control over unique, hard-to-recreate data sources that get richer as more people use them
  • Trusting users as co-developers
  • Harnessing collective intelligence
  • Leveraging the long tail through customer self-service
  • Software above the level of a single device
  • Lightweight user interfaces, development models, AND business models

With an interesting side bar titled “The Architecture of Participation”, O’Reilly pitches the development of data, not in a predetermined design pattern, but it a pattern based in common use[120]. The side bar notes Dan Bricklin’s work.  The Cornucopia of the Commons, which three ways to build a large database.

“The first, demonstrated by Yahoo!, is to pay people to do it. The second, inspired by lessons from the open source community, is to get volunteers to perform the same task. The Open Directory Project, an open source Yahoo competitor, is the result. But Napster demonstrated a third way. Because Napster set its defaults to automatically serve any music that was downloaded, every user automatically helped to build the value of the shared database. This same approach has been followed by all other P2P file sharing services.  […]  One of the key lessons of the Web 2.0 era is this: Users add value. But only a small percentage of users will go to the trouble of adding value to your application via explicit means. Therefore, Web 2.0 companies set inclusive defaults for aggregating user data and building value as a side-effect of ordinary use of the application. As noted above, they build systems that get better the more people use them[121]."

Seems like our society runs in two directions at the same time.  Blogs, Wiki and RSS have us overtaking outmoded rules for everything from spelling to acceptable business attire.  Moving rapidly in parallel, laws restricting digital expression, increasing the girth of copyright and extending legal jurisdiction to every form and channel of communication, is the subject of both world and local news.  We have never struggled harder to be compliant with greater numbers of independent variations of conformity, to such granular levels of performance and standard.

Is this why I feel dizzy?

The Common Criteria project is among the Open Source initiatives heavily supported by U.S. Government, (see open source memo).  In fact, the U.S federal government uses open source software in response to the E-Government Act of 2002.  Various news releases describe the E-Government Act as a regulation that: “promotes the sharing of best practices and innovative approaches in acquiring, using, and managing information resources for the government.”  An outstanding example is found at the Government Open Code Collaborative Repository, which provides, among other things, an open source Content Management System.  The repository contains code available for use in meeting state and local governments requirements CMS. The Commonwealth of Massachusetts Information Technology Division; the Rhode Island Office of the Secretary of State; the Pennsylvania Office of Information Technology; the Utah Governor’s Office, CIO Section; the Kansas Secretary of State Office; the Kansas Treasurer’s Office; the Missouri Secretary of State Office; the West Virginia Auditor’s Office; the City of Gloucester, MA; the City of Worcester, MA; and the City of Newport News, VA, launched the formation of the Government Open Code Collaborative (GOCC) in June of 2004, as a means for collaboration and sharing of computer code developed for and by government entities.  Additional links found at this site point to: WorkforceConnections, Advanced Distributed Learning, W3C Web Content Accessibility Guidelines and www.core.gov.

All conferences and articles concerned with open source and code reuse mention OASIS and in particular, the SAML standard.  The approach used for evaluation of product security offered some similarity to the approach used for the creation of SAML 2.0, the OASIS Security Assertion Markup Language[122].   The most significant difference in the Common Criteria and SAML projects however, is that one evaluates and the other creates assurance from the very start.  CC is focused to the evaluation of meeting standards, the committees of OASIS and the SAML TC strive to constrain information by schema, creating preventive controls and uniform communication of data such that compliance is embedded in both form and function.  Reading the introduction and end references of SAML 2.0 reveals that this TC applied common security evaluation constructs, leveraging many of the same elements found in the 15408 ISO/IEC series, reworked to normalize use case requirements, enforcing industry security terms in its glossary, and listing various IETF RFC and government standard considerations, such as NIST SP 800 26.  For example, SAML is used to demonstrate conformity to web security standards, such as Federal Information Processing Standard, FIPS 140.

Constraint and normalization of information is a cornerstone in meeting regulatory compliance requirements.  Concepts around the representation of information have existed for many decades, but the most compelling manner of representing information is probably “DocBook.”  The concept of the DocBook[123] may have been the initial draw for many persons among the Information Technology Audit community, and as it offered the basis of what would become Financial Assertion markup language and the representation of bank regulation compliant financial reporting.  I know it attracted and inspired me to join and participate with several configuration and network data center OASIS TCs.  This volunteer organization is at the forefront of compliance and automation.  Remarkably, both teams and standards evolve through raw collaboration, commitment, and talent.  In spite of tremendous success, leaders like the creator of DocBook XSL: The Complete Guide, Bob Stayton, and DocBook: The Definitive Guide, author Norman Walsh, provide daily support to OASIS XML use groups[124].

The concept of stylesheets as a means to validate any standard is long and well implemented by the web application and electronic industry user communities.  BPEL, (Business Process Execution Language) offers process documentation and controls modeling a lot of hope.  It is already an adopted standard by the FFIEC.  A profound product is the recently released “Enterprise Technical Reference Model (ETRM) v3.5.  ERTM incorporates a new Discipline for Data Formats within the Information Domain.  This Discipline addresses the acceptable formats in which data can be presented and captured for viewing and download at www.mass.gov. ERTM, announced by several news feeds for its bold and eloquent use of Open Standards, is said to jump ahead of the compliance curve.  Quoting a small portion of what I find to truly be a Must Read™ shows the importance of OASIS to security and IT.

“[…] Domain: Security - Discipline: Identity Management

Description: Identity Management is a broad administrative area that deals with identifying individuals in a system and controlling their access to resources within that system by associating user rights and restrictions with the established identity. The driver licensing system is a simple example of identity management: drivers are identified by their license numbers and user specifications (such as "can not drive after dark") are linked to the identifying number.

In a wider context, industry standards groups such as the World Wide Web Consortium and OASIS are developing standards that would enable global identity management, in which each individual would be uniquely identified, and all applicable data would be linked to that identity.

Relevant Standards Organizations.

OASIS – The organization for advancement of structured information standards (OASIS) is currently working two sets of Service Registry standards, i.e. UDDI and ebXML. More information about OASIS can be found at www.oasis-open.org.

W3C - The World Wide Web Consortium was created in October 1994 to lead the World Wide Web to its full potential by developing common protocols that promote its evolution and ensure its interoperability. W3C has around 400 Member organizations from all over the world and has earned international recognition for its contributions to the growth of the Web. More information about W3C can be found at www.w3.org.

WS-Interoperability – The Web Services Interoperability Organization is an open industry effort chartered to promote Web Services interoperability across platforms, applications, and programming languages. More information about WS-I can be found at www.ws-i.org.

IETF- the Internet Engineering Task Force (IETF) is a large open international community of network designers, operators, vendors, and researchers concerned with the evolution of the Internet architecture and the smooth operation of the Internet.  It is open to any interested individual. The actual technical work of the IETF is done in its working groups, which are organized by topic into several areas (e.g., routing, transport, security, etc.).  More information on the IETF can be found at www.ietf.org/home.html.

Main Menu