SlideShare una empresa de Scribd logo
1 de 18
Descargar para leer sin conexión
Open Document Exchange Formats:
      Security, Protection
         & Experiences
                 Christian Zier



      Federal Office for Information Security


        Berlin6 Open Access Conference
             12.11.2008, Düsseldorf
Agenda




➢   My place of work
➢   Standards and Open Standards
➢   Open Document Exchange Formats
➢   Security and Protection
➢   ODF and OOXML
➢   Migration at the BSI
My place of work: BSI


 Federal Office for Information
  Security (Bonn, Germany)
 Federal public agency within the
  area of responsibility of the
  Federal Ministry for the Interior
 Founded in 1991
  unique as a public agency in
  comparison to other European establishments
 Staff: around 460 employees
 Budget: 52 million €




Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 3
Focus of activities


 Internet security
 Secure e-government
 IT baseline protection
 Cryptographic innovation
 Biometrics
 Security from eavesdropping
 Certification and approval
 Protection of critical infrastructure
 Awareness campaign on IT security
 National / international security co-operation


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 4
Standards


   British Standards Institute:
        publicly available technical document
        developed in cooperation with interested
         parties
        based on scientific results and technical experiences
        intention is to improve the public welfare
 Subsystems can communicate via standardized interfaces
 Basis for interoperable products
 Promote competition between implementations
 Multiple competing standards for the same purpose
  question the meaning of standards

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 6
Open Standards


 Independent of implementations and manufacturers
 Competition between implementations, not standards
 Increases interoperability, avoids vendor lock-ins
 Facilitates developement of independent + FOSS
 Ensures future-proof access to archived data
 Makes sure that authors can acess their own documents
 There exist various definitions
 Standard has to be a common denominator
      → extensible to additional features



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 7
Open Document Exchange Formats


Open document exchange formats are
        independent
        developed in an open process
        sufficiently documented

Advantages of open document exchange formats:
        enhance competition and software diversity
        increase interoperability and automation
        enhance adaptability
        ensure archive security & guarantee future proof
        extensible to additional features




Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 8
Open Document Exchange Formats
                              contd.

 Authors retain access to and
  control over their documents
 E-Government needs ODEF for
  internal / external workflows, ...
  and secure documents
 Process to Open Document
  Exchange Formats:

    Not a question of if,
    it´s a question of how!



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 9
Security and Protection


 Attacks on IT-Systems increasingly via manipulated binary
  office documents
 Attacks are performed by well organized groups with good
  technical knowledge.
 For protection, we need to inspect documents
  to detect potentially malicious software (binary code)
 In case of critical vulnerability
  protection might imply blocking all
  documents of proprietary standard




Christian Zier, BSI, Germany    Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 10
Security and Protection
                                        contd.

   ODEF are well structured and meet the requirements:
        Structure allows for complete, transparent analyses
        Detection of malicious code strongly improved
        Possibilities to hide malicious code strongly reduced
        Efficient isolation of potentially dangerous code (e.g.
         macros, pictures, videos ...)
        Suspicious content can be filtered out without necessarily
         losing the information of the entire document




Christian Zier, BSI, Germany    Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 11
ODF (ISO 26300)


 Developed by Sun Microsystems and OASIS
 Many idependent implementations (OO, Koffice, AbiWord)
 Meets security requirements of eGovernment:
  structured format, can be scrutinised
 Has been examined and tested
 Possibility to directly access and
  edit the XML-files
 Macros uniquely identified with tags
 No definition for a mathematical formula
  language reduces interoperability.


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 12
OOXML (ISO 29500)


 Developed by Microsoft and Ecma International
 ISO 29500 has not yet been officially published
 There exists no implementation of this standard
 Security scans probably more elaborate + costly due to
        different tags in different document types for same
         properties (text color and alignment)
        6x more voluminous spec., indicates more complexity
        No tags for handling macros, also reduces interoperability
 More complex standard might reduce number of
  independent implementations and interoperability
 Only few independent implementations to be expected

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 13
Migration in the BSI


   In the past few years, BSI has
        migrated from Windows to Linux (around 50%)
        migrated from Microsoft Exchange to KOLAB Groupware
         (http://www.kolab.org) with Kontact and Outlook clients
        migrated from MS Office to StarOffice (~100%)
 About 500 installations of StarOffice
 Some installations of MS Office left
  (stand-alone and TS)
 Focus on text-documents as a start
 Exchange documents: ODF (and PDF)



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 14
Migration in the BSI
                                   Experiences

 The more recent the software, the less trouble
 Positive:
        Packaging and rollout easier with Linux
        Bugs can be found easier and fixed faster
        Better encryption functionality
   Negative (Debian Woody):
        Detection of printers
        Printing PDF-files
 Conversion of most templates after analysing for parts
  problematic to convert
 Migration was supported by training for StarOffice

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 15
Migration: Lessons learned


 „Where can I find this feature, where has that button
  gone?“
 „I want to return to Windows!“
 „This document looked fine on the other machine!?“


 People only accept a few drawbacks
 The every-day-scenarios have to work at least 90%
 Very important in administration: document templates
 Similarity of StarOffice to MS-Office was helpful




Christian Zier, BSI, Germany      Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 16
Migration: Lessons learned
                                      contd.

 Success strongly depends on willingness to engage into
  new software
 Many people care more about (good) applications than
  document standards → need good implementations of
  typical workflows for open documents.
 Only few severe problems → need more interoperability.


Might have read this before:

       It's not a question of IF, it's a question of HOW!



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 17
Contact


                                          Federal Office for
                                          Information Security (BSI)

                                          Christian Zier
                                          Godesberger Allee 185-189
                                          53175 Bonn

                                          Tel: +49 (0)228-9582-5946
                                          Fax: +49 (0)228-9582-5400

                                          christian.zier@bsi.bund.de
                                          www.bsi.bund.de
                                          www.bsi-fuer-buerger.de


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 18

Más contenido relacionado

Similar a Berlin 6 Open Access Conference: Christian Zier

Hardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyHardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyNoCodeHardening
 
Glasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesGlasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesDinis Cruz
 
G data 10 nov 2010
G data   10 nov 2010G data   10 nov 2010
G data 10 nov 2010Agora Group
 
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...Paris Open Source Summit
 
Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience OPITZ CONSULTING Deutschland
 
WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016Elsa Prieto
 
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxchristiandean12115
 
Setup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentSetup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentOlaf Hein
 
High-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationHigh-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationDirk Ortloff
 
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe inside-BigData.com
 
Berlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberBerlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberCornelius Puschmann
 
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...South Tyrol Free Software Conference
 
Do you know, where your sensitive data is?
Do you know, where your sensitive data is?Do you know, where your sensitive data is?
Do you know, where your sensitive data is?SPC Adriatics
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Javier Tallón
 
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel BeelenBrussels Legal Hackers
 
Multi cloud data integration with data virtualization
Multi cloud data integration with data virtualizationMulti cloud data integration with data virtualization
Multi cloud data integration with data virtualizationDenodo
 
IoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILIoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILTill Riedel
 
Nordic IT Security 2014 agenda
Nordic IT Security 2014 agendaNordic IT Security 2014 agenda
Nordic IT Security 2014 agendaCopperberg
 
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk
 

Similar a Berlin 6 Open Access Conference: Christian Zier (20)

Hardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyHardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security Strategy
 
Glasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesGlasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted Files
 
G data 10 nov 2010
G data   10 nov 2010G data   10 nov 2010
G data 10 nov 2010
 
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
 
Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience
 
WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016
 
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
 
Setup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentSetup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated Environment
 
High-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationHigh-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for information
 
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
 
Berlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberBerlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan Weisgerber
 
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
 
Do you know, where your sensitive data is?
Do you know, where your sensitive data is?Do you know, where your sensitive data is?
Do you know, where your sensitive data is?
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?
 
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
 
Multi cloud data integration with data virtualization
Multi cloud data integration with data virtualizationMulti cloud data integration with data virtualization
Multi cloud data integration with data virtualization
 
IoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILIoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDIL
 
Nordic IT Security 2014 agenda
Nordic IT Security 2014 agendaNordic IT Security 2014 agenda
Nordic IT Security 2014 agenda
 
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
 
Open Standard
Open StandardOpen Standard
Open Standard
 

Más de Cornelius Puschmann

Berlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanBerlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanCornelius Puschmann
 
Berlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongBerlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongCornelius Puschmann
 
Berlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenBerlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenCornelius Puschmann
 
Berlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouBerlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouCornelius Puschmann
 
Berlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseBerlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseCornelius Puschmann
 
Berlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleBerlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleCornelius Puschmann
 
Berlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanBerlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanCornelius Puschmann
 
Berlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelBerlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelCornelius Puschmann
 
Berlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicBerlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicCornelius Puschmann
 
Berlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelBerlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelCornelius Puschmann
 
Berlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonBerlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonCornelius Puschmann
 
Berlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendBerlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendCornelius Puschmann
 
Berlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillBerlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillCornelius Puschmann
 
Berlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleBerlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleCornelius Puschmann
 
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Cornelius Puschmann
 
Berlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuBerlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuCornelius Puschmann
 
Berlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamBerlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamCornelius Puschmann
 
Berlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosBerlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosCornelius Puschmann
 
Berlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerBerlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerCornelius Puschmann
 
Berlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaBerlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaCornelius Puschmann
 

Más de Cornelius Puschmann (20)

Berlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanBerlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne Nyhan
 
Berlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongBerlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre Furlong
 
Berlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenBerlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter Imboden
 
Berlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouBerlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore Papazoglou
 
Berlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseBerlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. Sprouse
 
Berlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleBerlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick Vandewalle
 
Berlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanBerlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark Liberman
 
Berlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelBerlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey Fomel
 
Berlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicBerlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena Kovacevic
 
Berlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelBerlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von Fintel
 
Berlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonBerlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John Houghton
 
Berlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendBerlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick Friend
 
Berlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillBerlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew Cockerill
 
Berlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleBerlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore Mele
 
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
 
Berlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuBerlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK Sahu
 
Berlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamBerlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun Arunachalam
 
Berlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosBerlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos Santos
 
Berlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerBerlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert Heller
 
Berlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaBerlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia Efimova
 

Último

Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxDenish Jangid
 
Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsKarakKing
 
Dyslexia AI Workshop for Slideshare.pptx
Dyslexia AI Workshop for Slideshare.pptxDyslexia AI Workshop for Slideshare.pptx
Dyslexia AI Workshop for Slideshare.pptxcallscotland1987
 
Single or Multiple melodic lines structure
Single or Multiple melodic lines structureSingle or Multiple melodic lines structure
Single or Multiple melodic lines structuredhanjurrannsibayan2
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - Englishneillewis46
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSCeline George
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and ModificationsMJDuyan
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfagholdier
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...christianmathematics
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptxMaritesTamaniVerdade
 
ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701bronxfugly43
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxheathfieldcps1
 
Python Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxPython Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxRamakrishna Reddy Bijjam
 
SOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning PresentationSOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning Presentationcamerronhm
 
Spellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseSpellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseAnaAcapella
 
Vishram Singh - Textbook of Anatomy Upper Limb and Thorax.. Volume 1 (1).pdf
Vishram Singh - Textbook of Anatomy  Upper Limb and Thorax.. Volume 1 (1).pdfVishram Singh - Textbook of Anatomy  Upper Limb and Thorax.. Volume 1 (1).pdf
Vishram Singh - Textbook of Anatomy Upper Limb and Thorax.. Volume 1 (1).pdfssuserdda66b
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin ClassesCeline George
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdfQucHHunhnh
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfciinovamais
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxJisc
 

Último (20)

Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptxBasic Civil Engineering first year Notes- Chapter 4 Building.pptx
Basic Civil Engineering first year Notes- Chapter 4 Building.pptx
 
Salient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functionsSalient Features of India constitution especially power and functions
Salient Features of India constitution especially power and functions
 
Dyslexia AI Workshop for Slideshare.pptx
Dyslexia AI Workshop for Slideshare.pptxDyslexia AI Workshop for Slideshare.pptx
Dyslexia AI Workshop for Slideshare.pptx
 
Single or Multiple melodic lines structure
Single or Multiple melodic lines structureSingle or Multiple melodic lines structure
Single or Multiple melodic lines structure
 
Graduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - EnglishGraduate Outcomes Presentation Slides - English
Graduate Outcomes Presentation Slides - English
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and Modifications
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
Explore beautiful and ugly buildings. Mathematics helps us create beautiful d...
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
 
ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701ComPTIA Overview | Comptia Security+ Book SY0-701
ComPTIA Overview | Comptia Security+ Book SY0-701
 
The basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptxThe basics of sentences session 3pptx.pptx
The basics of sentences session 3pptx.pptx
 
Python Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docxPython Notes for mca i year students osmania university.docx
Python Notes for mca i year students osmania university.docx
 
SOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning PresentationSOC 101 Demonstration of Learning Presentation
SOC 101 Demonstration of Learning Presentation
 
Spellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please PractiseSpellings Wk 3 English CAPS CARES Please Practise
Spellings Wk 3 English CAPS CARES Please Practise
 
Vishram Singh - Textbook of Anatomy Upper Limb and Thorax.. Volume 1 (1).pdf
Vishram Singh - Textbook of Anatomy  Upper Limb and Thorax.. Volume 1 (1).pdfVishram Singh - Textbook of Anatomy  Upper Limb and Thorax.. Volume 1 (1).pdf
Vishram Singh - Textbook of Anatomy Upper Limb and Thorax.. Volume 1 (1).pdf
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 

Berlin 6 Open Access Conference: Christian Zier

  • 1. Open Document Exchange Formats: Security, Protection & Experiences Christian Zier Federal Office for Information Security Berlin6 Open Access Conference 12.11.2008, Düsseldorf
  • 2. Agenda ➢ My place of work ➢ Standards and Open Standards ➢ Open Document Exchange Formats ➢ Security and Protection ➢ ODF and OOXML ➢ Migration at the BSI
  • 3. My place of work: BSI  Federal Office for Information Security (Bonn, Germany)  Federal public agency within the area of responsibility of the Federal Ministry for the Interior  Founded in 1991 unique as a public agency in comparison to other European establishments  Staff: around 460 employees  Budget: 52 million € Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 3
  • 4. Focus of activities  Internet security  Secure e-government  IT baseline protection  Cryptographic innovation  Biometrics  Security from eavesdropping  Certification and approval  Protection of critical infrastructure  Awareness campaign on IT security  National / international security co-operation Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 4
  • 5.
  • 6. Standards  British Standards Institute:  publicly available technical document  developed in cooperation with interested parties  based on scientific results and technical experiences  intention is to improve the public welfare  Subsystems can communicate via standardized interfaces  Basis for interoperable products  Promote competition between implementations  Multiple competing standards for the same purpose question the meaning of standards Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 6
  • 7. Open Standards  Independent of implementations and manufacturers  Competition between implementations, not standards  Increases interoperability, avoids vendor lock-ins  Facilitates developement of independent + FOSS  Ensures future-proof access to archived data  Makes sure that authors can acess their own documents  There exist various definitions  Standard has to be a common denominator → extensible to additional features Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 7
  • 8. Open Document Exchange Formats Open document exchange formats are  independent  developed in an open process  sufficiently documented Advantages of open document exchange formats:  enhance competition and software diversity  increase interoperability and automation  enhance adaptability  ensure archive security & guarantee future proof  extensible to additional features Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 8
  • 9. Open Document Exchange Formats contd.  Authors retain access to and control over their documents  E-Government needs ODEF for internal / external workflows, ... and secure documents  Process to Open Document Exchange Formats: Not a question of if, it´s a question of how! Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 9
  • 10. Security and Protection  Attacks on IT-Systems increasingly via manipulated binary office documents  Attacks are performed by well organized groups with good technical knowledge.  For protection, we need to inspect documents to detect potentially malicious software (binary code)  In case of critical vulnerability protection might imply blocking all documents of proprietary standard Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 10
  • 11. Security and Protection contd.  ODEF are well structured and meet the requirements:  Structure allows for complete, transparent analyses  Detection of malicious code strongly improved  Possibilities to hide malicious code strongly reduced  Efficient isolation of potentially dangerous code (e.g. macros, pictures, videos ...)  Suspicious content can be filtered out without necessarily losing the information of the entire document Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 11
  • 12. ODF (ISO 26300)  Developed by Sun Microsystems and OASIS  Many idependent implementations (OO, Koffice, AbiWord)  Meets security requirements of eGovernment: structured format, can be scrutinised  Has been examined and tested  Possibility to directly access and edit the XML-files  Macros uniquely identified with tags  No definition for a mathematical formula language reduces interoperability. Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 12
  • 13. OOXML (ISO 29500)  Developed by Microsoft and Ecma International  ISO 29500 has not yet been officially published  There exists no implementation of this standard  Security scans probably more elaborate + costly due to  different tags in different document types for same properties (text color and alignment)  6x more voluminous spec., indicates more complexity  No tags for handling macros, also reduces interoperability  More complex standard might reduce number of independent implementations and interoperability  Only few independent implementations to be expected Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 13
  • 14. Migration in the BSI  In the past few years, BSI has  migrated from Windows to Linux (around 50%)  migrated from Microsoft Exchange to KOLAB Groupware (http://www.kolab.org) with Kontact and Outlook clients  migrated from MS Office to StarOffice (~100%)  About 500 installations of StarOffice  Some installations of MS Office left (stand-alone and TS)  Focus on text-documents as a start  Exchange documents: ODF (and PDF) Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 14
  • 15. Migration in the BSI Experiences  The more recent the software, the less trouble  Positive:  Packaging and rollout easier with Linux  Bugs can be found easier and fixed faster  Better encryption functionality  Negative (Debian Woody):  Detection of printers  Printing PDF-files  Conversion of most templates after analysing for parts problematic to convert  Migration was supported by training for StarOffice Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 15
  • 16. Migration: Lessons learned  „Where can I find this feature, where has that button gone?“  „I want to return to Windows!“  „This document looked fine on the other machine!?“  People only accept a few drawbacks  The every-day-scenarios have to work at least 90%  Very important in administration: document templates  Similarity of StarOffice to MS-Office was helpful Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 16
  • 17. Migration: Lessons learned contd.  Success strongly depends on willingness to engage into new software  Many people care more about (good) applications than document standards → need good implementations of typical workflows for open documents.  Only few severe problems → need more interoperability. Might have read this before: It's not a question of IF, it's a question of HOW! Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 17
  • 18. Contact Federal Office for Information Security (BSI) Christian Zier Godesberger Allee 185-189 53175 Bonn Tel: +49 (0)228-9582-5946 Fax: +49 (0)228-9582-5400 christian.zier@bsi.bund.de www.bsi.bund.de www.bsi-fuer-buerger.de Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 18