OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cacao message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cacao] Playbook Types


I support this proposal too. I think the majority will honestly be templates. So somethingÂlike is_executable is probably correct and a default of false is probably good.Â

Bret


On Wed, Nov 2, 2022 at 2:29 PM Mateusz Zych <mateusdz@ifi.uio.no> wrote:
Hi All,Â

I agree and support this proposal.Â

Best,Â
Mateusz Zych

On 2 Nov 2022, at 16:52, aa tt <atcyber1000@gmail.com> wrote:

Rich et al - Iâm supportive of this change provided the proposed text to explain the template concept vs executable is updated to describe the use of this new property.

I assume this property would be required (?) and therefore we should decide what the default value (false) would indicate. I suggest that the default value should be the likely majority playbook class/category.Â

So if most playbooks will be templates then is_executable would be a good name and default to false.

If most playbooks would be executable then is_template might be better to name the property and that way the default value of false would work nicely.

Allan


On Nov 2, 2022, at 6:47 AM, Rich Piazza <rpiazza@mitre.org> wrote:

Hi All,
Â
On the working call yesterday there was a discussion about section 1.3 of the CACAO working document. Some of the important points:
Â
  • The difference between an executable playbook and a playbook template is mostly subjective. There are suggestions to the text to help clarify this.
  • There is no difference between an executable playbook and a playbook template in terms of their properties
  • The term paybook class is confusing, since it is specified using the type property of a playbook.
Â
A suggested proposal is to remove the concept of playbook classes, and replace it by a new Boolean property, maybe called âis_executableâ, to differentiate between executable playbooks and playbook templates.
Â
ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Rich
Â
Â
--
Rich Piazza
Lead Cyber Security Engineer
The MITRE Corporation
781-271-3760
ââââââââââââââââââââââââââââââââââââ
MITRE - Solving Problems for a Safer Worldâ




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]