Amazon Web Services (AWS), Splunk, and Broadcom joined an open source coalition along with fifteen additional cybersecurity vendors on a mission to break down data siloes that universally hinder security teams.

Joining those initiating vendors in the Open Cybersecurity Schema Framework (OCSF) project are Cloudflare, CrowdStrike, DTEX, IBM Security, IronNet, JupiterOne, Okta, Palo Alto Networks, Rapid7, Salesforce, Securonix, Sumo Logic, Tanium, Trend Micro, and Zscaler, though OCSF is encouraging the entire cybersecurity community to take advantage of and contribute to the project. The project is led by a steering committee with members from AWS and Splunk and is collectively managed by maintainers and contributors.

Sumo Logic Security Business Unit VP and GM Dave Frampton identified "the collaboration of multiple security vendors for the benefit of customers and the industry as a whole" as a major short-term target of forming a coalition like OCSF. On a longer term, the OCSF will benefit the community by improving its content overall, he told SDxCentral.

And while the nature of competitive business might seem to discourage industry-wide open source collaboration, Frampton noted the positive impacts on the community that stem from this scale of collaboration are more than worth it. Vendor differentiation can still exist, he added, just further up the stack in terms of features and user experience.

As an early founder, Sumo Logic provides technical input regarding the development of the schema that sits at the heart of this open source effort. This supports OCSF's goal to provide a vendor-agnostic taxonomy that lets security teams quickly ingest and analyze data by removing the need for up front normalization tasks that consume time and resources.

OCSF says its open standard can be adopted for any environment, application, or solution provider and sufficiently meets current security standards and best practices. Participating security vendors can incorporate industry-wide OCSF standards into their offerings, which will simplify security data normalization on a broader scale so security professionals can spend more time preventing threats and less time organizing the data the gets them there.

"Every business deserves a simple, straightforward way to analyze and understand the security landscape–and that starts with their data," Cloudflare CTO John Graham-Cumming said in a statement. "By participating in the OCSF, we hope to help the entire security industry focus on doing the work that matters instead of wasting countless hours and resources on formatting data."

"Security vendor participation in open projects always benefits the community. We are encouraged to see it and take a lead in supporting this kind of collaboration," Frampton added.