The Open Cybersecurity Schema Framework (OCSF) project spearheaded by Broadcom and Amazon Web Services (AWS) might just be a lot of hype that won't translate as seamlessly to reality as the group claims.

"As we stand today, OCSF is very much in its infancy," Steve Benton, who spent 18 years running cybersecurity for BT Group and is now VP of threat research at Anomali, told SDxCentral in an email. "It is surrounded by an air of expectation and anticipation for actual compliant products and interfaces being released to begin the journey to ‘out of the box’, ‘normalized-ready’, security events data benefitting the SOC."

The OCSF, announced earlier this month, promises to break down data siloes that hinder security teams through industry-wide vendor collaboration. AWS, Splunk, and Broadcom are founding members of the open source coalition, which also includes security giants like Palo Alto Networks, Sumo Logic, and Trend Micro as part of the initial group.

OCSF says its open standard can be adopted for any environment, application, or solution provider and sufficiently meets current security standards and best practices. Participating security vendors can incorporate industry-wide OCSF standards into their offerings, which will simplify security data normalization on a broader scale so security professionals can spend more time preventing threats and less time organizing the data the gets them there, according to the group.

Sumo Logic Security Business Unit VP and GM Dave Frampton identified “the collaboration of multiple security vendors for the benefit of customers and the industry as a whole” as a major short-term target of forming a coalition like OCSF. On a longer term, the OCSF will benefit the community by improving its content overall, he told SDxCentral at the time.

“Security vendor participation in open projects always benefits the community. We are encouraged to see it and take a lead in supporting this kind of collaboration,” Frampton added.

OCSF's Idealistic Aspirations

In light of the project's utopian aspirations, Benton is concerned with the technical difficulties of "hype transitioning to reality."

He expects security teams will be overwhelmed once the first OCSF products are released, deployed, and "start providing the promised wider and deeper sets of events at [an] increased pace."

Benton noted OSCF will provide wider threat detection data, but it will not come with correlated threat intelligence necessary to craft an effective response. "Think whack-a-mole on steroids, more heads popping up faster, complete with false positives and the SOC analysts inevitably being sucked down investigative rabbit holes," Benton argued.

Atop that data complexity, he says OSCF will create "two worlds" out of the time before and after the creation of the coalition. As the framework increasingly gains adoption, the ecosystem's security vendors will "have the unenviable task of figuring out and managing a migration journey whilst maintaining their security posture and responding effectively to events," according to Benton.

OCSF Ignores Industry Efforts

Benton also pointed out the framework is missing Mitre ATT&CK integration. ATT&CK is an open knowledge base used to develop threat methodologies and models and has long been an industry standard. "Honestly, this feels like a miss right now," he said.

ATT&CK boasts huge benefits for security teams' micro and macro understanding of threats and attacks, and it accelerates the velocity of decision making, Benton explained. OCSF's lack of integration with this standard means threat analysis is done manually by security analysts "among all the other things they have to do."

Extended detection and response (XDR) is also given the cold shoulder by OCSF as it exists today, according to Benton. The framework unifies security events, but it doesn't unify execution or coordination of security controls, he explained.

"‘One screen’ - the very idea we are looking to move to with XDR - will not exist for some time," he said. "Instead, in responding to the wider event alerts OCSF enables, organizations will still have to go full ‘swivel chair’ mode, screen to screen with different data and information."

The Importance of Collaboration

Security vendors will need to establish trust with one another for an endeavor like OCSF to live up to its aspirations, and this will "profoundly determine the success or failure" of the project, according to Benton. "Hard pressed SOC teams cannot carry the industry – that would be the complete opposite of the purpose of OCSF."

To that point, he warns a half-hearted implementation of the framework would be worse than an outright failure like a crash on take-off. "OCSF is a rallying call which cannot be ignored – everyone needs to be all in, right now, and committed to sustain for the long term," he said.