SlideShare a Scribd company logo
1 of 18
Download to read offline
Open Document Exchange Formats:
      Security, Protection
         & Experiences
                 Christian Zier



      Federal Office for Information Security


        Berlin6 Open Access Conference
             12.11.2008, Düsseldorf
Agenda




➢   My place of work
➢   Standards and Open Standards
➢   Open Document Exchange Formats
➢   Security and Protection
➢   ODF and OOXML
➢   Migration at the BSI
My place of work: BSI


 Federal Office for Information
  Security (Bonn, Germany)
 Federal public agency within the
  area of responsibility of the
  Federal Ministry for the Interior
 Founded in 1991
  unique as a public agency in
  comparison to other European establishments
 Staff: around 460 employees
 Budget: 52 million €




Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 3
Focus of activities


 Internet security
 Secure e-government
 IT baseline protection
 Cryptographic innovation
 Biometrics
 Security from eavesdropping
 Certification and approval
 Protection of critical infrastructure
 Awareness campaign on IT security
 National / international security co-operation


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 4
Standards


   British Standards Institute:
        publicly available technical document
        developed in cooperation with interested
         parties
        based on scientific results and technical experiences
        intention is to improve the public welfare
 Subsystems can communicate via standardized interfaces
 Basis for interoperable products
 Promote competition between implementations
 Multiple competing standards for the same purpose
  question the meaning of standards

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 6
Open Standards


 Independent of implementations and manufacturers
 Competition between implementations, not standards
 Increases interoperability, avoids vendor lock-ins
 Facilitates developement of independent + FOSS
 Ensures future-proof access to archived data
 Makes sure that authors can acess their own documents
 There exist various definitions
 Standard has to be a common denominator
      → extensible to additional features



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 7
Open Document Exchange Formats


Open document exchange formats are
        independent
        developed in an open process
        sufficiently documented

Advantages of open document exchange formats:
        enhance competition and software diversity
        increase interoperability and automation
        enhance adaptability
        ensure archive security & guarantee future proof
        extensible to additional features




Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 8
Open Document Exchange Formats
                              contd.

 Authors retain access to and
  control over their documents
 E-Government needs ODEF for
  internal / external workflows, ...
  and secure documents
 Process to Open Document
  Exchange Formats:

    Not a question of if,
    it´s a question of how!



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 9
Security and Protection


 Attacks on IT-Systems increasingly via manipulated binary
  office documents
 Attacks are performed by well organized groups with good
  technical knowledge.
 For protection, we need to inspect documents
  to detect potentially malicious software (binary code)
 In case of critical vulnerability
  protection might imply blocking all
  documents of proprietary standard




Christian Zier, BSI, Germany    Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 10
Security and Protection
                                        contd.

   ODEF are well structured and meet the requirements:
        Structure allows for complete, transparent analyses
        Detection of malicious code strongly improved
        Possibilities to hide malicious code strongly reduced
        Efficient isolation of potentially dangerous code (e.g.
         macros, pictures, videos ...)
        Suspicious content can be filtered out without necessarily
         losing the information of the entire document




Christian Zier, BSI, Germany    Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 11
ODF (ISO 26300)


 Developed by Sun Microsystems and OASIS
 Many idependent implementations (OO, Koffice, AbiWord)
 Meets security requirements of eGovernment:
  structured format, can be scrutinised
 Has been examined and tested
 Possibility to directly access and
  edit the XML-files
 Macros uniquely identified with tags
 No definition for a mathematical formula
  language reduces interoperability.


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 12
OOXML (ISO 29500)


 Developed by Microsoft and Ecma International
 ISO 29500 has not yet been officially published
 There exists no implementation of this standard
 Security scans probably more elaborate + costly due to
        different tags in different document types for same
         properties (text color and alignment)
        6x more voluminous spec., indicates more complexity
        No tags for handling macros, also reduces interoperability
 More complex standard might reduce number of
  independent implementations and interoperability
 Only few independent implementations to be expected

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 13
Migration in the BSI


   In the past few years, BSI has
        migrated from Windows to Linux (around 50%)
        migrated from Microsoft Exchange to KOLAB Groupware
         (http://www.kolab.org) with Kontact and Outlook clients
        migrated from MS Office to StarOffice (~100%)
 About 500 installations of StarOffice
 Some installations of MS Office left
  (stand-alone and TS)
 Focus on text-documents as a start
 Exchange documents: ODF (and PDF)



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 14
Migration in the BSI
                                   Experiences

 The more recent the software, the less trouble
 Positive:
        Packaging and rollout easier with Linux
        Bugs can be found easier and fixed faster
        Better encryption functionality
   Negative (Debian Woody):
        Detection of printers
        Printing PDF-files
 Conversion of most templates after analysing for parts
  problematic to convert
 Migration was supported by training for StarOffice

Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 15
Migration: Lessons learned


 „Where can I find this feature, where has that button
  gone?“
 „I want to return to Windows!“
 „This document looked fine on the other machine!?“


 People only accept a few drawbacks
 The every-day-scenarios have to work at least 90%
 Very important in administration: document templates
 Similarity of StarOffice to MS-Office was helpful




Christian Zier, BSI, Germany      Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 16
Migration: Lessons learned
                                      contd.

 Success strongly depends on willingness to engage into
  new software
 Many people care more about (good) applications than
  document standards → need good implementations of
  typical workflows for open documents.
 Only few severe problems → need more interoperability.


Might have read this before:

       It's not a question of IF, it's a question of HOW!



Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 17
Contact


                                          Federal Office for
                                          Information Security (BSI)

                                          Christian Zier
                                          Godesberger Allee 185-189
                                          53175 Bonn

                                          Tel: +49 (0)228-9582-5946
                                          Fax: +49 (0)228-9582-5400

                                          christian.zier@bsi.bund.de
                                          www.bsi.bund.de
                                          www.bsi-fuer-buerger.de


Christian Zier, BSI, Germany   Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf   Folie 18

More Related Content

Similar to Berlin 6 Open Access Conference: Christian Zier

Hardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyHardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyNoCodeHardening
 
Glasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesGlasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesDinis Cruz
 
G data 10 nov 2010
G data   10 nov 2010G data   10 nov 2010
G data 10 nov 2010Agora Group
 
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...Paris Open Source Summit
 
Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience OPITZ CONSULTING Deutschland
 
WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016Elsa Prieto
 
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxchristiandean12115
 
Setup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentSetup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentOlaf Hein
 
High-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationHigh-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationDirk Ortloff
 
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe inside-BigData.com
 
Berlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberBerlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberCornelius Puschmann
 
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...South Tyrol Free Software Conference
 
Do you know, where your sensitive data is?
Do you know, where your sensitive data is?Do you know, where your sensitive data is?
Do you know, where your sensitive data is?SPC Adriatics
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Javier Tallón
 
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel BeelenBrussels Legal Hackers
 
Multi cloud data integration with data virtualization
Multi cloud data integration with data virtualizationMulti cloud data integration with data virtualization
Multi cloud data integration with data virtualizationDenodo
 
IoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILIoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILTill Riedel
 
Nordic IT Security 2014 agenda
Nordic IT Security 2014 agendaNordic IT Security 2014 agenda
Nordic IT Security 2014 agendaCopperberg
 
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk
 

Similar to Berlin 6 Open Access Conference: Christian Zier (20)

Hardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security StrategyHardening as Part of a holistic Security Strategy
Hardening as Part of a holistic Security Strategy
 
Glasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted FilesGlasswall - Safety and Integrity Through Trusted Files
Glasswall - Safety and Integrity Through Trusted Files
 
G data 10 nov 2010
G data   10 nov 2010G data   10 nov 2010
G data 10 nov 2010
 
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
OWF14 - Legal and licensing aspects of Open Source - Procurement of open sour...
 
Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience Oracle IoT Cloud Service - First practical experience
Oracle IoT Cloud Service - First practical experience
 
WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016WITDOM presentation at Net Futures 2016
WITDOM presentation at Net Futures 2016
 
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docxITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
ITC568 Cloud Privacy and SecurityThe Cloud Security Ecosyste.docx
 
Setup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated EnvironmentSetup a Data Science Pipeline in a Highly Regulated Environment
Setup a Data Science Pipeline in a Highly Regulated Environment
 
High-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for informationHigh-Tech R&D -- Drowning in data but starving for information
High-Tech R&D -- Drowning in data but starving for information
 
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
New Horizons for a Data-Driven Economy – A Roadmap for Big Data in Europe
 
Berlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan WeisgerberBerlin 6 Open Access Conference: Stefan Weisgerber
Berlin 6 Open Access Conference: Stefan Weisgerber
 
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
SFScon17 - Frank Karlitschek: "The next steps for secure enterprise file sync...
 
Do you know, where your sensitive data is?
Do you know, where your sensitive data is?Do you know, where your sensitive data is?
Do you know, where your sensitive data is?
 
Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?Is Automation Necessary for the CC Survival?
Is Automation Necessary for the CC Survival?
 
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
20190316 - CLBFest - GDPR & Blockchain - Axel Beelen
 
Multi cloud data integration with data virtualization
Multi cloud data integration with data virtualizationMulti cloud data integration with data virtualization
Multi cloud data integration with data virtualization
 
IoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDILIoT 2014 Value Creation Workshop: SDIL
IoT 2014 Value Creation Workshop: SDIL
 
Nordic IT Security 2014 agenda
Nordic IT Security 2014 agendaNordic IT Security 2014 agenda
Nordic IT Security 2014 agenda
 
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
Marek Pietrzyk - CISO Summit Zurich - Next generation Information Rights Mana...
 
Open Standard
Open StandardOpen Standard
Open Standard
 

More from Cornelius Puschmann

Berlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanBerlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanCornelius Puschmann
 
Berlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongBerlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongCornelius Puschmann
 
Berlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenBerlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenCornelius Puschmann
 
Berlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouBerlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouCornelius Puschmann
 
Berlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseBerlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseCornelius Puschmann
 
Berlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleBerlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleCornelius Puschmann
 
Berlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanBerlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanCornelius Puschmann
 
Berlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelBerlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelCornelius Puschmann
 
Berlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicBerlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicCornelius Puschmann
 
Berlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelBerlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelCornelius Puschmann
 
Berlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonBerlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonCornelius Puschmann
 
Berlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendBerlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendCornelius Puschmann
 
Berlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillBerlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillCornelius Puschmann
 
Berlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleBerlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleCornelius Puschmann
 
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Cornelius Puschmann
 
Berlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuBerlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuCornelius Puschmann
 
Berlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamBerlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamCornelius Puschmann
 
Berlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosBerlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosCornelius Puschmann
 
Berlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerBerlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerCornelius Puschmann
 
Berlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaBerlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaCornelius Puschmann
 

More from Cornelius Puschmann (20)

Berlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne NyhanBerlin 6 Open Access Conference: Julianne Nyhan
Berlin 6 Open Access Conference: Julianne Nyhan
 
Berlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre FurlongBerlin 6 Open Access Conference: Deirdre Furlong
Berlin 6 Open Access Conference: Deirdre Furlong
 
Berlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter ImbodenBerlin 6 Open Access Conference: Dieter Imboden
Berlin 6 Open Access Conference: Dieter Imboden
 
Berlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore PapazoglouBerlin 6 Open Access Conference: Theodore Papazoglou
Berlin 6 Open Access Conference: Theodore Papazoglou
 
Berlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. SprouseBerlin 6 Open Access Conference: Gene D. Sprouse
Berlin 6 Open Access Conference: Gene D. Sprouse
 
Berlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick VandewalleBerlin 6 Open Access Conference: Patrick Vandewalle
Berlin 6 Open Access Conference: Patrick Vandewalle
 
Berlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark LibermanBerlin 6 Open Access Conference: Mark Liberman
Berlin 6 Open Access Conference: Mark Liberman
 
Berlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey FomelBerlin 6 Open Access Conference: Sergey Fomel
Berlin 6 Open Access Conference: Sergey Fomel
 
Berlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena KovacevicBerlin 6 Open Access Conference: Jelena Kovacevic
Berlin 6 Open Access Conference: Jelena Kovacevic
 
Berlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von FintelBerlin 6 Open Access Conference: Kai von Fintel
Berlin 6 Open Access Conference: Kai von Fintel
 
Berlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John HoughtonBerlin 6 Open Access Conference: John Houghton
Berlin 6 Open Access Conference: John Houghton
 
Berlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick FriendBerlin 6 Open Access Conference: Frederick Friend
Berlin 6 Open Access Conference: Frederick Friend
 
Berlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew CockerillBerlin 6 Open Access Conference: Matthew Cockerill
Berlin 6 Open Access Conference: Matthew Cockerill
 
Berlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore MeleBerlin 6 Open Access Conference: Salvatore Mele
Berlin 6 Open Access Conference: Salvatore Mele
 
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
Berlin 6 Open Access Conference: Susan Murray (for Eve Gray Murray)
 
Berlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK SahuBerlin 6 Open Access Conference: DK Sahu
Berlin 6 Open Access Conference: DK Sahu
 
Berlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun ArunachalamBerlin 6 Open Access Conference: Arun Arunachalam
Berlin 6 Open Access Conference: Arun Arunachalam
 
Berlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos SantosBerlin 6 Open Access Conference: Solange dos Santos
Berlin 6 Open Access Conference: Solange dos Santos
 
Berlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert HellerBerlin 6 Open Access Conference: Lambert Heller
Berlin 6 Open Access Conference: Lambert Heller
 
Berlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia EfimovaBerlin 6 Open Access Conference: Lilia Efimova
Berlin 6 Open Access Conference: Lilia Efimova
 

Recently uploaded

This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.christianmathematics
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfciinovamais
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and ModificationsMJDuyan
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docxPoojaSen20
 
ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.MaryamAhmad92
 
Dyslexia AI Workshop for Slideshare.pptx
Dyslexia AI Workshop for Slideshare.pptxDyslexia AI Workshop for Slideshare.pptx
Dyslexia AI Workshop for Slideshare.pptxcallscotland1987
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhikauryashika82
 
Unit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxUnit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxVishalSingh1417
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfagholdier
 
psychiatric nursing HISTORY COLLECTION .docx
psychiatric  nursing HISTORY  COLLECTION  .docxpsychiatric  nursing HISTORY  COLLECTION  .docx
psychiatric nursing HISTORY COLLECTION .docxPoojaSen20
 
Micro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfMicro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfPoh-Sun Goh
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfAdmir Softic
 
Food safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfFood safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfSherif Taha
 
Third Battle of Panipat detailed notes.pptx
Third Battle of Panipat detailed notes.pptxThird Battle of Panipat detailed notes.pptx
Third Battle of Panipat detailed notes.pptxAmita Gupta
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptxMaritesTamaniVerdade
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSCeline George
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...Poonam Aher Patil
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsTechSoup
 

Recently uploaded (20)

This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.This PowerPoint helps students to consider the concept of infinity.
This PowerPoint helps students to consider the concept of infinity.
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
 
Understanding Accommodations and Modifications
Understanding  Accommodations and ModificationsUnderstanding  Accommodations and Modifications
Understanding Accommodations and Modifications
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docx
 
ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.ICT role in 21st century education and it's challenges.
ICT role in 21st century education and it's challenges.
 
Dyslexia AI Workshop for Slideshare.pptx
Dyslexia AI Workshop for Slideshare.pptxDyslexia AI Workshop for Slideshare.pptx
Dyslexia AI Workshop for Slideshare.pptx
 
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in DelhiRussian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
Russian Escort Service in Delhi 11k Hotel Foreigner Russian Call Girls in Delhi
 
Unit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxUnit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptx
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
psychiatric nursing HISTORY COLLECTION .docx
psychiatric  nursing HISTORY  COLLECTION  .docxpsychiatric  nursing HISTORY  COLLECTION  .docx
psychiatric nursing HISTORY COLLECTION .docx
 
Micro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdfMicro-Scholarship, What it is, How can it help me.pdf
Micro-Scholarship, What it is, How can it help me.pdf
 
Spatium Project Simulation student brief
Spatium Project Simulation student briefSpatium Project Simulation student brief
Spatium Project Simulation student brief
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Food safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdfFood safety_Challenges food safety laboratories_.pdf
Food safety_Challenges food safety laboratories_.pdf
 
Third Battle of Panipat detailed notes.pptx
Third Battle of Panipat detailed notes.pptxThird Battle of Panipat detailed notes.pptx
Third Battle of Panipat detailed notes.pptx
 
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
2024-NATIONAL-LEARNING-CAMP-AND-OTHER.pptx
 
How to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POSHow to Manage Global Discount in Odoo 17 POS
How to Manage Global Discount in Odoo 17 POS
 
General Principles of Intellectual Property: Concepts of Intellectual Proper...
General Principles of Intellectual Property: Concepts of Intellectual  Proper...General Principles of Intellectual Property: Concepts of Intellectual  Proper...
General Principles of Intellectual Property: Concepts of Intellectual Proper...
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The Basics
 

Berlin 6 Open Access Conference: Christian Zier

  • 1. Open Document Exchange Formats: Security, Protection & Experiences Christian Zier Federal Office for Information Security Berlin6 Open Access Conference 12.11.2008, Düsseldorf
  • 2. Agenda ➢ My place of work ➢ Standards and Open Standards ➢ Open Document Exchange Formats ➢ Security and Protection ➢ ODF and OOXML ➢ Migration at the BSI
  • 3. My place of work: BSI  Federal Office for Information Security (Bonn, Germany)  Federal public agency within the area of responsibility of the Federal Ministry for the Interior  Founded in 1991 unique as a public agency in comparison to other European establishments  Staff: around 460 employees  Budget: 52 million € Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 3
  • 4. Focus of activities  Internet security  Secure e-government  IT baseline protection  Cryptographic innovation  Biometrics  Security from eavesdropping  Certification and approval  Protection of critical infrastructure  Awareness campaign on IT security  National / international security co-operation Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 4
  • 5.
  • 6. Standards  British Standards Institute:  publicly available technical document  developed in cooperation with interested parties  based on scientific results and technical experiences  intention is to improve the public welfare  Subsystems can communicate via standardized interfaces  Basis for interoperable products  Promote competition between implementations  Multiple competing standards for the same purpose question the meaning of standards Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 6
  • 7. Open Standards  Independent of implementations and manufacturers  Competition between implementations, not standards  Increases interoperability, avoids vendor lock-ins  Facilitates developement of independent + FOSS  Ensures future-proof access to archived data  Makes sure that authors can acess their own documents  There exist various definitions  Standard has to be a common denominator → extensible to additional features Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 7
  • 8. Open Document Exchange Formats Open document exchange formats are  independent  developed in an open process  sufficiently documented Advantages of open document exchange formats:  enhance competition and software diversity  increase interoperability and automation  enhance adaptability  ensure archive security & guarantee future proof  extensible to additional features Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 8
  • 9. Open Document Exchange Formats contd.  Authors retain access to and control over their documents  E-Government needs ODEF for internal / external workflows, ... and secure documents  Process to Open Document Exchange Formats: Not a question of if, it´s a question of how! Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 9
  • 10. Security and Protection  Attacks on IT-Systems increasingly via manipulated binary office documents  Attacks are performed by well organized groups with good technical knowledge.  For protection, we need to inspect documents to detect potentially malicious software (binary code)  In case of critical vulnerability protection might imply blocking all documents of proprietary standard Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 10
  • 11. Security and Protection contd.  ODEF are well structured and meet the requirements:  Structure allows for complete, transparent analyses  Detection of malicious code strongly improved  Possibilities to hide malicious code strongly reduced  Efficient isolation of potentially dangerous code (e.g. macros, pictures, videos ...)  Suspicious content can be filtered out without necessarily losing the information of the entire document Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 11
  • 12. ODF (ISO 26300)  Developed by Sun Microsystems and OASIS  Many idependent implementations (OO, Koffice, AbiWord)  Meets security requirements of eGovernment: structured format, can be scrutinised  Has been examined and tested  Possibility to directly access and edit the XML-files  Macros uniquely identified with tags  No definition for a mathematical formula language reduces interoperability. Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 12
  • 13. OOXML (ISO 29500)  Developed by Microsoft and Ecma International  ISO 29500 has not yet been officially published  There exists no implementation of this standard  Security scans probably more elaborate + costly due to  different tags in different document types for same properties (text color and alignment)  6x more voluminous spec., indicates more complexity  No tags for handling macros, also reduces interoperability  More complex standard might reduce number of independent implementations and interoperability  Only few independent implementations to be expected Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 13
  • 14. Migration in the BSI  In the past few years, BSI has  migrated from Windows to Linux (around 50%)  migrated from Microsoft Exchange to KOLAB Groupware (http://www.kolab.org) with Kontact and Outlook clients  migrated from MS Office to StarOffice (~100%)  About 500 installations of StarOffice  Some installations of MS Office left (stand-alone and TS)  Focus on text-documents as a start  Exchange documents: ODF (and PDF) Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 14
  • 15. Migration in the BSI Experiences  The more recent the software, the less trouble  Positive:  Packaging and rollout easier with Linux  Bugs can be found easier and fixed faster  Better encryption functionality  Negative (Debian Woody):  Detection of printers  Printing PDF-files  Conversion of most templates after analysing for parts problematic to convert  Migration was supported by training for StarOffice Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 15
  • 16. Migration: Lessons learned  „Where can I find this feature, where has that button gone?“  „I want to return to Windows!“  „This document looked fine on the other machine!?“  People only accept a few drawbacks  The every-day-scenarios have to work at least 90%  Very important in administration: document templates  Similarity of StarOffice to MS-Office was helpful Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 16
  • 17. Migration: Lessons learned contd.  Success strongly depends on willingness to engage into new software  Many people care more about (good) applications than document standards → need good implementations of typical workflows for open documents.  Only few severe problems → need more interoperability. Might have read this before: It's not a question of IF, it's a question of HOW! Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 17
  • 18. Contact Federal Office for Information Security (BSI) Christian Zier Godesberger Allee 185-189 53175 Bonn Tel: +49 (0)228-9582-5946 Fax: +49 (0)228-9582-5400 christian.zier@bsi.bund.de www.bsi.bund.de www.bsi-fuer-buerger.de Christian Zier, BSI, Germany Berlin 6 Open Access Conference, 12.11.2008, Düsseldorf Folie 18