>-----Original Message-----
>From: Sanford Whitehouse [mailto:
swhitehouse@...]
>Sent: Monday, 22 October, 2007 03:35
>To: cee-discussion-list CEE-Related Discussion
>Subject: [CEE-DISCUSSION-LIST] A whitepaper response
>
<snip>
>
>If there is an aspect of any standard that should be stated, it is the
>reason vendors should adopt it. What benefit do they receive by
giving
>up ownership of their logs? What will hurt them if they chose to go
>another direction? With so many companies moving to multi-function
>products and enterprise scale manageability, why should
>interoperaterability with competitors at any level benefit them?
>
Sanford brings up a point that I have been intentionally avoiding:
what is the motivation for vendor adoption?
There has been a lot of interest in CEE from both vendors and
researchers,
and there is an understandable, realistic interest from IT customers as
CEE would be able to help with regulatory compliance and network
monitoring. However, what is the motivation for vendors?
For log management and SIM vendors, there is an obvious cost reduction
with a decrease in the effort for mapping log data and supporting new
products. For your more generic software vendors, besides the "playing
nice with others" and possibly improving internal log support, what
would you argue as being the major reasons why a vendor should
participate?
Or, if you are a vendor representative, what is your interest in CEE?
William Heinbockel
Infosec Engineer, Sr.
The MITRE Corporation
202 Burlington Rd. MS S145
Bedford, MA 01730
heinbockel@...
781-271-2615