TagVault.org is a non-profit organization formed under the structure of IEEE-ISTO. It is a registration and certification authority for software identification tags (SWID tags) based on the ISO/IEC 19770-2:2009 standard. TagVault is a member-driven organization that provides a forum for sharing information and resources about software tags among software publishers, tool providers and SAM practitioners. TagVault provides a shared library of technical knowledge and software tools including consistent cross-vendor, cross-platform APIs.
2012 Software Identification Summit
Save the date!
Date: May 2, 2012
Cost: $100 Facilities Fee
Location: Campbell, CA (close to the San Jose International Airport - SJC)
Breaking through the fog of misinformation!
This year’s summit focuses on software security and software publisher benefits of TagVault.org certified software identification (SWID) tags. Industry experts will give detailed presentations on the issues and risks related to software assurance, and how certified ISO SWID tags can be used to improve the ability for consumers to mitigate these issues and risks. We will also go into detail about how software publishers benefit by including TagVault.org certified SWID tags with their software products.
- Go to form
- Login or register to post comments
- Read more
Software Discovery Tool Analysis
Identifying which software products are installed on a computing device is similar to an archeological dig (i.e. trying to determine which software titles are installed based on various artifacts discovered on the device) and regularly results in incomplete and incorrect results. Unfortunately, compliance, logistics and security processes and procedures rely on this discovery data to manage an organization’s infrastructure.
Incorrect data from software discovery utilities can and does result in:
Automation of CPE Names Using Certified SWID Tags
This article and the referenced document is likely to be of primary interest to individuals working within the US Government or related organizations and have an interest in the overall Security Content Automation Protocol (SCAP) standards and processes.
You've got questions, we've got answers - let's see if they match...
TagVault.org will be participating in a Panel discussion on the 19770-2 standard at Flexera's SoftSummit conference in San Jose, CA from Oct 24 - 26. David Wright, CTO of Veritag, John Richardson, Director Licensing Technology for Symantec and Steve Klos, Executive Director of TagVault.org will be on the panel and we are ready for your questions - please send them to us!
Flexera recently announced that InstallShield 2012 creates and installs SWID tags by default as part of the software installation process on Windows devices. This removes even the slightest barrier for a huge number of ISV's who may otherwise gloss over the fact that their customers are spending significant money and resources trying to make their best guess about what software is installed on a device.
2011 IAITAM Conference Promotes ISO SAM Standards
As usual, the 2011 IAITAM conference was very well attended and the only complaint I heard was the problem of having too many interesting speakers presenting at the same time (6 different tracks over a period of 3 days provides a lot to choose from)!TagVault.org Industry Focused Activities
In addition hosting the the annual software identification summit (next summit - early May 2012), TagVault.org participates in many conferences and other industry related activities throughout the year. Since the program is a non-profit organization, we attempt to keep our costs down and travel only when necessary. If we are at a conference or meeting near you and you want to setup a meeting, please let us know via the contact form on this website and we would be happy to setup some time to meet face to face.Resounding Approval for the 2011 Software Identification Summit
On May 4th, in the Washington DC area, the first annual software identification summit was held to provide a forum for all software ecosystem members to discuss the future of software identification. The summit was attended by a number of governmental agencies, software publishers, tool providers as well as software procurement and management teams. The software supply chain and management process is a complete mess!
.png)






















.png)