Quick Facts

  • OCSF joined the Linux Foundation in November 2024, marking a major governance milestone
  • The project has grown to 900 contributors and 200 participating organizations since launching in 2022
  • Major security vendors including AWS, Splunk, CrowdStrike, and Palo Alto Networks have integrated OCSF support

The Open Cybersecurity Schema Framework moved under Linux Foundation governance in November 2024, two years after AWS, Cisco, IBM, and Splunk launched the project to standardize security data formats.

The framework has expanded rapidly from 17 founding companies to more than 200 participating organizations and 900 contributors. This growth reflects widespread industry adoption of OCSF’s standardized approach to security data management.

Enterprise Integration Accelerates

Major security platforms now support OCSF natively. AWS Security Lake converts AWS logs into OCSF format and stores them in Parquet. Splunk translates incoming data into OCSF through its edge processor. CrowdStrike positions Falcon data for OCSF translation while preparing its Next-Gen SIEM to ingest OCSF-formatted data.

Palo Alto Networks forwards Strata Logging Service data into Amazon Security Lake using OCSF format. This broad vendor support addresses the longtime challenge of incompatible security data formats across different tools.

Rapid Technical Evolution

OCSF has released multiple versions since version 1.0.0 in September 2023. The latest version 1.3.0, released in August 2024, adds event classes for software inventory and remediation activities. Future versions will include enhanced support for AI system monitoring and threat intelligence enrichment.

“We believe that joining the Linux Foundation will strengthen OCSF’s role as a leading open security data schema and accelerate its adoption across the industry,” said Gee Rittenhouse, AWS Vice President of Security Services.

Operational Benefits Drive Adoption

Security teams report significant efficiency gains from OCSF standardization. Owen Connolly, CISO at Liberty Group, said the framework eliminates time spent analyzing data across multiple systems. “Having a platform that provides OCSF-ready data connectors is a game changer and allows my team to focus on detection, triage, investigation, and response rather than data architecture.”

The standardization reduces vendor development costs by eliminating the need for custom parsers for each security tool. This translates to lower total operational costs for enterprises managing multiple security platforms.

Strategic Value for Leadership

CISOs gain measurable benefits from OCSF adoption. Standardized telemetry enables consistent key performance indicators including mean time to detect and mean time to respond. The framework also reduces vendor lock-in risk by allowing security teams to change analytics platforms without rewriting detection content.

Linux Foundation Executive Director Jim Zemlin emphasized the collaborative approach. “With cybersecurity incidents on the rise, the need for collaborative, open source solutions grows with each passing day.”

The Linux Foundation transition provides stronger governance and resources for continued development. This institutional backing positions OCSF to become the de facto standard for security data formatting as AI expands attack surfaces and security tool complexity.

Read more: OCSF explained: The shared data language security teams have been missing

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.