SlideShare una empresa de Scribd logo
1 de 18
Descargar para leer sin conexión
Open Document Exchange Formats:
      Security, Protection
         & Experiences
                 Christian Zier



      Federal Office for Information Security


        Berlin6 Open Access Conference
             12.11.2008, Düsseldorf
Agenda




➢   My place of work
➢   Standards and Open Standards
➢   Open Document Exchange Formats
➢   Security and Protection
➢   ODF and OOXML
➢   Migration at the BSI
My place of work: BSI


 Federal Office for Information
  Security (Bonn, Germany)
 Federal public agency within the
  area of responsibility of the
  Federal Ministry for the Interior
 Founded in 1991
  unique as a public agency in
  comparison to other European establishments
 Staff: around 460 employees
 Budget: 52 million €




Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 3
Focus of activities


 Internet security
 Secure e-government
 IT baseline protection
 Cryptographic innovation
 Biometrics
 Security from eavesdropping
 Certification and approval
 Protection of critical infrastructure
 Awareness campaign on IT security
 National / international security co-operation


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 4
Standards


   British Standards Institute:
        publicly available technical document
        developed in cooperation with interested
         parties
        based on scientific results and technical experiences
        intention is to improve the public welfare
 Subsystems can communicate via standardized interfaces
 Basis for interoperable products
 Promote competition between implementations
 Multiple competing standards for the same purpose
  question the meaning of standards

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 6
Open Standards


 Independent of implementations and manufacturers
 Competition between implementations, not standards
 Increases interoperability, avoids vendor lock-ins
 Facilitates developement of independent + FOSS
 Ensures future-proof access to archived data
 Makes sure that authors can acess their own documents
 There exist various definitions
 Standard has to be a common denominator
      → extensible to additional features



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 7
Open Document Exchange Formats


Open document exchange formats are
        independent
        developed in an open process
        sufficiently documented

Advantages of open document exchange formats:
        enhance competition and software diversity
        increase interoperability and automation
        enhance adaptability
        ensure archive security & guarantee future proof
        extensible to additional features




Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 8
Open Document Exchange Formats
                              contd.

 Authors retain access to and
  control over their documents
 E-Government needs ODEF for
  internal / external workflows, ...
  and secure documents
 Process to Open Document
  Exchange Formats:

    Not a question of if,
    it´s a question of how!



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 9
Security and Protection


 Attacks on IT-Systems increasingly via manipulated binary
  office documents
 Attacks are performed by well organized groups with good
  technical knowledge.
 For protection, we need to inspect documents
  to detect potentially malicious software (binary code)
 In case of critical vulnerability
  protection might imply blocking all
  documents of proprietary standard




Christian Zier, BSI, Germany    Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 10
Security and Protection
                                        contd.

   ODEF are well structured and meet the requirements:
        Structure allows for complete, transparent analyses
        Detection of malicious code strongly improved
        Possibilities to hide malicious code strongly reduced
        Efficient isolation of potentially dangerous code (e.g.
         macros, pictures, videos ...)
        Suspicious content can be filtered out without necessarily
         losing the information of the entire document




Christian Zier, BSI, Germany    Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 11
ODF (ISO 26300)


 Developed by Sun Microsystems and OASIS
 Many idependent implementations (OO, Koffice, AbiWord)
 Meets security requirements of eGovernment:
  structured format, can be scrutinised
 Has been examined and tested
 Possibility to directly access and
  edit the XML-files
 Macros uniquely identified with tags
 No definition for a mathematical formula
  language reduces interoperability.


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 12
OOXML (ISO 29500)


 Developed by Microsoft and Ecma International
 ISO 29500 has not yet been officially published
 There exists no implementation of this standard
 Security scans probably more elaborate + costly due to
        different tags in different document types for same
         properties (text color and alignment)
        6x more voluminous spec., indicates more complexity
        No tags for handling macros, also reduces interoperability
 More complex standard might reduce number of
  independent implementations and interoperability
 Only few independent implementations to be expected

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 13
Migration in the BSI


   In the past few years, BSI has
        migrated from Windows to Linux (around 50%)
        migrated from Microsoft Exchange to KOLAB Groupware
         (http://www.kolab.org) with Kontact and Outlook clients
        migrated from MS Office to StarOffice (~100%)
 About 500 installations of StarOffice
 Some installations of MS Office left
  (stand-alone and TS)
 Focus on text-documents as a start
 Exchange documents: ODF (and PDF)



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 14
Migration in the BSI
                                   Experiences

 The more recent the software, the less trouble
 Positive:
        Packaging and rollout easier with Linux
        Bugs can be found easier and fixed faster
        Better encryption functionality
   Negative (Debian Woody):
        Detection of printers
        Printing PDF-files
 Conversion of most templates after analysing for parts
  problematic to convert
 Migration was supported by training for StarOffice

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 15
Migration: Lessons learned


 „Where can I find this feature, where has that button
  gone?“
 „I want to return to Windows!“
 „This document looked fine on the other machine!?“


 People only accept a few drawbacks
 The every-day-scenarios have to work at least 90%
 Very important in administration: document templates
 Similarity of StarOffice to MS-Office was helpful




Christian Zier, BSI, Germany      Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 16
Migration: Lessons learned
                                      contd.

 Success strongly depends on willingness to engage into
  new software
 Many people care more about (good) applications than
  document standards → need good implementations of
  typical workflows for open documents.
 Only few severe problems → need more interoperability.


Might have read this before:

       It's not a question of IF, it's a question of HOW!



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 17
Contact


                                          Federal Office for
                                          Information Security (BSI)

                                          Christian Zier
                                          Godesberger Allee 185-189
                                          53175 Bonn

                                          Tel: +49 (0)228-9582-5946
                                          Fax: +49 (0)228-9582-5400

                                          christian.zier@bsi.bund.de
                                          www.bsi.bund.de
                                          www.bsi-fuer-buerger.de


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 18

Más contenido relacionado

Similar a Berlin 6 Open Access Conference: Christian Zier

Hardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyHardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyNoCodeHardening
 
Glasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesGlasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesDinis Cruz
 
G data 10 nov 2010
G data   10 nov 2010G data   10 nov 2010
G data 10 nov 2010Agora Group
 
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...Paris Open Source Summit
 
Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience OPITZ CONSULTING Deutschland
 
WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016Elsa Prieto
 
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxchristiandean12115
 
Setup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentSetup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentOlaf Hein
 
High-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationHigh-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationDirk Ortloff
 
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe inside-BigData.com
 
Berlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberBerlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberCornelius Puschmann
 
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...South Tyrol Free Software Conference
 
Do you know, where your sensitive data is?
Do you know, where your sensitive data is?Do you know, where your sensitive data is?
Do you know, where your sensitive data is?SPC Adriatics
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Javier Tallón
 
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel BeelenBrussels Legal Hackers
 
Multi cloud data integration with data virtualization
Multi cloud data integration with data virtualizationMulti cloud data integration with data virtualization
Multi cloud data integration with data virtualizationDenodo
 
IoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILIoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILTill Riedel
 
Nordic IT Security 2014 agenda
Nordic IT Security 2014 agendaNordic IT Security 2014 agenda
Nordic IT Security 2014 agendaCopperberg
 
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk
 

Similar a Berlin 6 Open Access Conference: Christian Zier (20)

Hardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyHardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security Strategy
 
Glasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesGlasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted Files
 
G data 10 nov 2010
G data   10 nov 2010G data   10 nov 2010
G data 10 nov 2010
 
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
 
Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience
 
WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016
 
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
 
Setup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentSetup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated Environment
 
High-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationHigh-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for information
 
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
 
Berlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberBerlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan Weisgerber
 
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
 
Do you know, where your sensitive data is?
Do you know, where your sensitive data is?Do you know, where your sensitive data is?
Do you know, where your sensitive data is?
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?
 
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
 
Multi cloud data integration with data virtualization
Multi cloud data integration with data virtualizationMulti cloud data integration with data virtualization
Multi cloud data integration with data virtualization
 
IoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILIoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDIL
 
Nordic IT Security 2014 agenda
Nordic IT Security 2014 agendaNordic IT Security 2014 agenda
Nordic IT Security 2014 agenda
 
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
 
Open Standard
Open StandardOpen Standard
Open Standard
 

Más de Cornelius Puschmann

Berlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanBerlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanCornelius Puschmann
 
Berlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongBerlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongCornelius Puschmann
 
Berlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenBerlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenCornelius Puschmann
 
Berlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouBerlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouCornelius Puschmann
 
Berlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseBerlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseCornelius Puschmann
 
Berlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleBerlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleCornelius Puschmann
 
Berlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanBerlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanCornelius Puschmann
 
Berlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelBerlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelCornelius Puschmann
 
Berlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicBerlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicCornelius Puschmann
 
Berlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelBerlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelCornelius Puschmann
 
Berlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonBerlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonCornelius Puschmann
 
Berlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendBerlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendCornelius Puschmann
 
Berlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillBerlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillCornelius Puschmann
 
Berlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleBerlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleCornelius Puschmann
 
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Cornelius Puschmann
 
Berlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuBerlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuCornelius Puschmann
 
Berlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamBerlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamCornelius Puschmann
 
Berlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosBerlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosCornelius Puschmann
 
Berlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerBerlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerCornelius Puschmann
 
Berlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaBerlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaCornelius Puschmann
 

Más de Cornelius Puschmann (20)

Berlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanBerlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne Nyhan
 
Berlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongBerlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre Furlong
 
Berlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenBerlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter Imboden
 
Berlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouBerlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore Papazoglou
 
Berlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseBerlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. Sprouse
 
Berlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleBerlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick Vandewalle
 
Berlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanBerlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark Liberman
 
Berlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelBerlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey Fomel
 
Berlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicBerlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena Kovacevic
 
Berlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelBerlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von Fintel
 
Berlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonBerlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John Houghton
 
Berlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendBerlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick Friend
 
Berlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillBerlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew Cockerill
 
Berlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleBerlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore Mele
 
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
 
Berlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuBerlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK Sahu
 
Berlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamBerlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun Arunachalam
 
Berlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosBerlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos Santos
 
Berlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerBerlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert Heller
 
Berlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaBerlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia Efimova
 

Último

HVAC System | Audit of HVAC System | Audit and regulatory Comploance.pptx
HVAC System | Audit of HVAC System | Audit and regulatory Comploance.pptxHVAC System | Audit of HVAC System | Audit and regulatory Comploance.pptx
HVAC System | Audit of HVAC System | Audit and regulatory Comploance.pptxKunal10679
 
Graduate Outcomes Presentation Slides - English (v3).pptx
Graduate Outcomes Presentation Slides - English (v3).pptxGraduate Outcomes Presentation Slides - English (v3).pptx
Graduate Outcomes Presentation Slides - English (v3).pptxneillewis46
 
An overview of the various scriptures in Hinduism
An overview of the various scriptures in HinduismAn overview of the various scriptures in Hinduism
An overview of the various scriptures in HinduismDabee Kamal
 
Software testing for project report .pdf
Software testing for project report .pdfSoftware testing for project report .pdf
Software testing for project report .pdfKamal Acharya
 
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...Nguyen Thanh Tu Collection
 
ANTI PARKISON DRUGS.pptx
ANTI         PARKISON          DRUGS.pptxANTI         PARKISON          DRUGS.pptx
ANTI PARKISON DRUGS.pptxPoojaSen20
 
size separation d pharm 1st year pharmaceutics
size separation d pharm 1st year pharmaceuticssize separation d pharm 1st year pharmaceutics
size separation d pharm 1st year pharmaceuticspragatimahajan3
 
UChicago CMSC 23320 - The Best Commit Messages of 2024
UChicago CMSC 23320 - The Best Commit Messages of 2024UChicago CMSC 23320 - The Best Commit Messages of 2024
UChicago CMSC 23320 - The Best Commit Messages of 2024Borja Sotomayor
 
Spring gala 2024 photo slideshow - Celebrating School-Community Partnerships
Spring gala 2024 photo slideshow - Celebrating School-Community PartnershipsSpring gala 2024 photo slideshow - Celebrating School-Community Partnerships
Spring gala 2024 photo slideshow - Celebrating School-Community Partnershipsexpandedwebsite
 
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17Celine George
 
Envelope of Discrepancy in Orthodontics: Enhancing Precision in Treatment
 Envelope of Discrepancy in Orthodontics: Enhancing Precision in Treatment Envelope of Discrepancy in Orthodontics: Enhancing Precision in Treatment
Envelope of Discrepancy in Orthodontics: Enhancing Precision in Treatmentsaipooja36
 
Basic Civil Engineering notes on Transportation Engineering, Modes of Transpo...
Basic Civil Engineering notes on Transportation Engineering, Modes of Transpo...Basic Civil Engineering notes on Transportation Engineering, Modes of Transpo...
Basic Civil Engineering notes on Transportation Engineering, Modes of Transpo...Denish Jangid
 
BỘ LUYỆN NGHE TIẾNG ANH 8 GLOBAL SUCCESS CẢ NĂM (GỒM 12 UNITS, MỖI UNIT GỒM 3...
BỘ LUYỆN NGHE TIẾNG ANH 8 GLOBAL SUCCESS CẢ NĂM (GỒM 12 UNITS, MỖI UNIT GỒM 3...BỘ LUYỆN NGHE TIẾNG ANH 8 GLOBAL SUCCESS CẢ NĂM (GỒM 12 UNITS, MỖI UNIT GỒM 3...
BỘ LUYỆN NGHE TIẾNG ANH 8 GLOBAL SUCCESS CẢ NĂM (GỒM 12 UNITS, MỖI UNIT GỒM 3...Nguyen Thanh Tu Collection
 
Capitol Tech Univ Doctoral Presentation -May 2024
Capitol Tech Univ Doctoral Presentation -May 2024Capitol Tech Univ Doctoral Presentation -May 2024
Capitol Tech Univ Doctoral Presentation -May 2024CapitolTechU
 
How to Manage Closest Location in Odoo 17 Inventory
How to Manage Closest Location in Odoo 17 InventoryHow to Manage Closest Location in Odoo 17 Inventory
How to Manage Closest Location in Odoo 17 InventoryCeline George
 
demyelinated disorder: multiple sclerosis.pptx
demyelinated disorder: multiple sclerosis.pptxdemyelinated disorder: multiple sclerosis.pptx
demyelinated disorder: multiple sclerosis.pptxMohamed Rizk Khodair
 
The basics of sentences session 4pptx.pptx
The basics of sentences session 4pptx.pptxThe basics of sentences session 4pptx.pptx
The basics of sentences session 4pptx.pptxheathfieldcps1
 

Último (20)

Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
Mattingly "AI and Prompt Design: LLMs with Text Classification and Open Source"
 
HVAC System | Audit of HVAC System | Audit and regulatory Comploance.pptx
HVAC System | Audit of HVAC System | Audit and regulatory Comploance.pptxHVAC System | Audit of HVAC System | Audit and regulatory Comploance.pptx
HVAC System | Audit of HVAC System | Audit and regulatory Comploance.pptx
 
Graduate Outcomes Presentation Slides - English (v3).pptx
Graduate Outcomes Presentation Slides - English (v3).pptxGraduate Outcomes Presentation Slides - English (v3).pptx
Graduate Outcomes Presentation Slides - English (v3).pptx
 
An overview of the various scriptures in Hinduism
An overview of the various scriptures in HinduismAn overview of the various scriptures in Hinduism
An overview of the various scriptures in Hinduism
 
Software testing for project report .pdf
Software testing for project report .pdfSoftware testing for project report .pdf
Software testing for project report .pdf
 
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
24 ĐỀ THAM KHẢO KÌ THI TUYỂN SINH VÀO LỚP 10 MÔN TIẾNG ANH SỞ GIÁO DỤC HẢI DƯ...
 
ANTI PARKISON DRUGS.pptx
ANTI         PARKISON          DRUGS.pptxANTI         PARKISON          DRUGS.pptx
ANTI PARKISON DRUGS.pptx
 
size separation d pharm 1st year pharmaceutics
size separation d pharm 1st year pharmaceuticssize separation d pharm 1st year pharmaceutics
size separation d pharm 1st year pharmaceutics
 
UChicago CMSC 23320 - The Best Commit Messages of 2024
UChicago CMSC 23320 - The Best Commit Messages of 2024UChicago CMSC 23320 - The Best Commit Messages of 2024
UChicago CMSC 23320 - The Best Commit Messages of 2024
 
Spring gala 2024 photo slideshow - Celebrating School-Community Partnerships
Spring gala 2024 photo slideshow - Celebrating School-Community PartnershipsSpring gala 2024 photo slideshow - Celebrating School-Community Partnerships
Spring gala 2024 photo slideshow - Celebrating School-Community Partnerships
 
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17
Removal Strategy _ FEFO _ Working with Perishable Products in Odoo 17
 
Envelope of Discrepancy in Orthodontics: Enhancing Precision in Treatment
 Envelope of Discrepancy in Orthodontics: Enhancing Precision in Treatment Envelope of Discrepancy in Orthodontics: Enhancing Precision in Treatment
Envelope of Discrepancy in Orthodontics: Enhancing Precision in Treatment
 
Basic Civil Engineering notes on Transportation Engineering, Modes of Transpo...
Basic Civil Engineering notes on Transportation Engineering, Modes of Transpo...Basic Civil Engineering notes on Transportation Engineering, Modes of Transpo...
Basic Civil Engineering notes on Transportation Engineering, Modes of Transpo...
 
BỘ LUYỆN NGHE TIẾNG ANH 8 GLOBAL SUCCESS CẢ NĂM (GỒM 12 UNITS, MỖI UNIT GỒM 3...
BỘ LUYỆN NGHE TIẾNG ANH 8 GLOBAL SUCCESS CẢ NĂM (GỒM 12 UNITS, MỖI UNIT GỒM 3...BỘ LUYỆN NGHE TIẾNG ANH 8 GLOBAL SUCCESS CẢ NĂM (GỒM 12 UNITS, MỖI UNIT GỒM 3...
BỘ LUYỆN NGHE TIẾNG ANH 8 GLOBAL SUCCESS CẢ NĂM (GỒM 12 UNITS, MỖI UNIT GỒM 3...
 
Capitol Tech Univ Doctoral Presentation -May 2024
Capitol Tech Univ Doctoral Presentation -May 2024Capitol Tech Univ Doctoral Presentation -May 2024
Capitol Tech Univ Doctoral Presentation -May 2024
 
How to Manage Closest Location in Odoo 17 Inventory
How to Manage Closest Location in Odoo 17 InventoryHow to Manage Closest Location in Odoo 17 Inventory
How to Manage Closest Location in Odoo 17 Inventory
 
demyelinated disorder: multiple sclerosis.pptx
demyelinated disorder: multiple sclerosis.pptxdemyelinated disorder: multiple sclerosis.pptx
demyelinated disorder: multiple sclerosis.pptx
 
Operations Management - Book1.p - Dr. Abdulfatah A. Salem
Operations Management - Book1.p  - Dr. Abdulfatah A. SalemOperations Management - Book1.p  - Dr. Abdulfatah A. Salem
Operations Management - Book1.p - Dr. Abdulfatah A. Salem
 
IPL Online Quiz by Pragya; Question Set.
IPL Online Quiz by Pragya; Question Set.IPL Online Quiz by Pragya; Question Set.
IPL Online Quiz by Pragya; Question Set.
 
The basics of sentences session 4pptx.pptx
The basics of sentences session 4pptx.pptxThe basics of sentences session 4pptx.pptx
The basics of sentences session 4pptx.pptx
 

Berlin 6 Open Access Conference: Christian Zier

  • 1. Open Document Exchange Formats: Security, Protection & Experiences Christian Zier Federal Office for Information Security Berlin6 Open Access Conference 12.11.2008, Düsseldorf
  • 2. Agenda ➢ My place of work ➢ Standards and Open Standards ➢ Open Document Exchange Formats ➢ Security and Protection ➢ ODF and OOXML ➢ Migration at the BSI
  • 3. My place of work: BSI  Federal Office for Information Security (Bonn, Germany)  Federal public agency within the area of responsibility of the Federal Ministry for the Interior  Founded in 1991 unique as a public agency in comparison to other European establishments  Staff: around 460 employees  Budget: 52 million € Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 3
  • 4. Focus of activities  Internet security  Secure e-government  IT baseline protection  Cryptographic innovation  Biometrics  Security from eavesdropping  Certification and approval  Protection of critical infrastructure  Awareness campaign on IT security  National / international security co-operation Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 4
  • 5.
  • 6. Standards  British Standards Institute:  publicly available technical document  developed in cooperation with interested parties  based on scientific results and technical experiences  intention is to improve the public welfare  Subsystems can communicate via standardized interfaces  Basis for interoperable products  Promote competition between implementations  Multiple competing standards for the same purpose question the meaning of standards Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 6
  • 7. Open Standards  Independent of implementations and manufacturers  Competition between implementations, not standards  Increases interoperability, avoids vendor lock-ins  Facilitates developement of independent + FOSS  Ensures future-proof access to archived data  Makes sure that authors can acess their own documents  There exist various definitions  Standard has to be a common denominator → extensible to additional features Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 7
  • 8. Open Document Exchange Formats Open document exchange formats are  independent  developed in an open process  sufficiently documented Advantages of open document exchange formats:  enhance competition and software diversity  increase interoperability and automation  enhance adaptability  ensure archive security & guarantee future proof  extensible to additional features Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 8
  • 9. Open Document Exchange Formats contd.  Authors retain access to and control over their documents  E-Government needs ODEF for internal / external workflows, ... and secure documents  Process to Open Document Exchange Formats: Not a question of if, it´s a question of how! Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 9
  • 10. Security and Protection  Attacks on IT-Systems increasingly via manipulated binary office documents  Attacks are performed by well organized groups with good technical knowledge.  For protection, we need to inspect documents to detect potentially malicious software (binary code)  In case of critical vulnerability protection might imply blocking all documents of proprietary standard Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 10
  • 11. Security and Protection contd.  ODEF are well structured and meet the requirements:  Structure allows for complete, transparent analyses  Detection of malicious code strongly improved  Possibilities to hide malicious code strongly reduced  Efficient isolation of potentially dangerous code (e.g. macros, pictures, videos ...)  Suspicious content can be filtered out without necessarily losing the information of the entire document Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 11
  • 12. ODF (ISO 26300)  Developed by Sun Microsystems and OASIS  Many idependent implementations (OO, Koffice, AbiWord)  Meets security requirements of eGovernment: structured format, can be scrutinised  Has been examined and tested  Possibility to directly access and edit the XML-files  Macros uniquely identified with tags  No definition for a mathematical formula language reduces interoperability. Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 12
  • 13. OOXML (ISO 29500)  Developed by Microsoft and Ecma International  ISO 29500 has not yet been officially published  There exists no implementation of this standard  Security scans probably more elaborate + costly due to  different tags in different document types for same properties (text color and alignment)  6x more voluminous spec., indicates more complexity  No tags for handling macros, also reduces interoperability  More complex standard might reduce number of independent implementations and interoperability  Only few independent implementations to be expected Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 13
  • 14. Migration in the BSI  In the past few years, BSI has  migrated from Windows to Linux (around 50%)  migrated from Microsoft Exchange to KOLAB Groupware (http://www.kolab.org) with Kontact and Outlook clients  migrated from MS Office to StarOffice (~100%)  About 500 installations of StarOffice  Some installations of MS Office left (stand-alone and TS)  Focus on text-documents as a start  Exchange documents: ODF (and PDF) Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 14
  • 15. Migration in the BSI Experiences  The more recent the software, the less trouble  Positive:  Packaging and rollout easier with Linux  Bugs can be found easier and fixed faster  Better encryption functionality  Negative (Debian Woody):  Detection of printers  Printing PDF-files  Conversion of most templates after analysing for parts problematic to convert  Migration was supported by training for StarOffice Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 15
  • 16. Migration: Lessons learned  „Where can I find this feature, where has that button gone?“  „I want to return to Windows!“  „This document looked fine on the other machine!?“  People only accept a few drawbacks  The every-day-scenarios have to work at least 90%  Very important in administration: document templates  Similarity of StarOffice to MS-Office was helpful Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 16
  • 17. Migration: Lessons learned contd.  Success strongly depends on willingness to engage into new software  Many people care more about (good) applications than document standards → need good implementations of typical workflows for open documents.  Only few severe problems → need more interoperability. Might have read this before: It's not a question of IF, it's a question of HOW! Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 17
  • 18. Contact Federal Office for Information Security (BSI) Christian Zier Godesberger Allee 185-189 53175 Bonn Tel: +49 (0)228-9582-5946 Fax: +49 (0)228-9582-5400 christian.zier@bsi.bund.de www.bsi.bund.de www.bsi-fuer-buerger.de Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 18