Home - OCA (original) (raw)

OCA Sponsors

What We Do

Open Cybersecurity Alliance (OCA) develops standardized data interfaces to support an open ecosystem where cybersecurity tools interoperate without the need for custom integrations.

OCA is a nonprofit, global collaboration of software providers, end users, government agencies, research institutes , and individuals committed to enabling the free exchange of information, insights, analytics, and response across cybersecurity tools.

An open source project, OCA operates under the OASIS Open governance process, which ensures transparency, inclusiveness, and safety, with a path to standardization and reference in international policy and procurement.

OCA Principles


Security Tool Integration

OCA Goals

Interoperability

Develop and promote sets of open source content, code, tooling, patterns, and practices to maximize interoperability and the sharing of data among cybersecurity tools

Open Ecosystem

Build an open ecosystem where cybersecurity products interoperate without the need for customized integrations.

Value Increase

Extract more value from existing products and reduce costs by reducing the complexity of architecting and deploying ever-increasing cyber solutions.

Improved Visibility

Improve security visibility and ability to discover new insights that might otherwise have been missed.

Why OCA?

OCA is committed to solving the costly problem of siloed cyber tools and products. Our mission is to connect the fragmented cybersecurity landscape with common, open source code and practices that allow companies to “integrate once, reuse everywhere.”

For enterprise users, this means improving security visibility and the ability to discover new insights that might otherwise go unseen; extracting more value from existing products and reducing vendor lock-in; and connecting data and sharing insights across products.

OCA Sub-Projects

OCA is an incubator for a growing number of Open Source projects.

Home

Kestrel

Threat Hunting Language

Provides an abstraction for threat hunters to focus on what to hunt instead of how to hunt. Learn more.

Home

STIX Shifter

Patterning Library

Allows data to be normalized across domains for comprehensive security analysis. Learn more.

Home

PACE

Posture Attribute Collection and Evaluation

A comprehensive automated strategy for understanding security posture and what to do about it. Learn more.

IOB Artwork 1

Indicators of Behavior (IOB)

Augmentation to Machine Readable CTI

A structured representation of reusable adversary behaviors, detections of those behaviors, and correlation workflows to aid network defenders. Learn more.

Home

CASP

Cybersecurity Automation Sub-Project

Prototyping, testing, and specifying interoperability among cybersecurity automation technologies. Learn more

OXA-logo-3

OXA

Open XDR Architecture

Defining interactions between security products, using open standards and APIs, in order to enable a composable security architecture. Learn more

CACAO-Roaster-logo_rounded

CACAO Roaster

Editor for CACAO Playbooks

Allows defenders in a no-code graphical manner to design and generate CACAO playbooks to orchestrate and automate their cybersecurity operations.
Learn more.

CASP_Village-campfire 1

Interoperability Village

Interoperability Testing for OCA

A dynamic distributed architecture that enables interoperability testing between between a diverse set of stakeholders.

Learn more.

OCA Working Groups

Zero Trust Architecture

Working to create and further refine OCA technologies to enable a Zero Trust architecture.

Join our mailing list.

OCA Ontology

Creating a unified ontology for cybersecurity information in order to have standard ways of encoding information on data fabrics, APIs, etc.

Join our mailing list.

How You Benefit

The OCA approach will define an architecture that is distributed, modular and adaptive. OCA will provide easily extensible, common-code components and open specifications that will normalize information between disparate systems. Our framework will reduce the complexity of architecting and deploying ever-increasing cyber solutions.

Unlike vendor partner alliances, OCA is a collaborative community with open governance. OCA is working on projects that span key conversations happening in the security industry, i.e., Zero Trust, Extended Detection and Response (XDR), Posture Assessment and more. Unlike industry-specific platforms for sharing threat data, OCA is uniquely focused on product interoperability, with benefits for the entire cybersecurity community.


Security Vendors



Security Practitioners



Managed Security Service Providers



Public Sector