OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-stix] Can we just make a little bit of progress?


Bret, do you think TAXII would be as far along as it is if you hadn’t brought a long a a straw man for TAXII 2.0? I am trying to implement your winning plan.

As for the discussions currently under way, I would be happy to second a motion to vote on a direction.


Aharon


From: "Jordan, Bret" <bret.jordan@bluecoat.com>
Date: Tuesday, December 1, 2015 at 3:36 PM
To: Aharon <achernin@soltra.com>
Cc: "Jonathan Bush (DTCC)" <jbush@dtcc.com>, Mark Davidson <mdavidson@soltra.com>, "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>
Subject: Re: [cti-stix] Can we just make a little bit of progress?

That is great... However, there is a bigger systemic issue in the STIX SC..  Some of us have tried to bring relatively small proposals to the table, and we can not get consensus and things just die on the vine.  Given that, how do we expect the get consensus on a big sweeping proposal?  What is going to change in the SC or its leadership that will make that happen with your big sweeping proposal?  


Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." 

On Dec 1, 2015, at 07:05, Aharon Chernin <achernin@soltra.com> wrote:

As I mentioned in prior emails to the group, we are creating a STIX 2.0 proposal that includes a sightings and relationship object. We hope to have this proposal in time for the face 2 face meeting. Any number of options can occur based on this proposal. The group could decide to vote it in, decide to use it as a base and make changes, or decide to out right reject it. This is a very similar approach to what the TAXII SC did for their TAXII 2.0 proposal. It allows the SC to work together and modify a straw man that is close to what they need versus working together to create something that does not yet exist. 

I welcome the group to come up with their own straw mans as well, for example the Sightings object or the Relationships object. It would save us time on our proposal if we leverage someone else’s work effort.

Aharon

From: <cti-stix@lists.oasis-open.org> on behalf of "Bush, Jonathan" <jbush@dtcc.com>
Date: Tuesday, December 1, 2015 at 1:36 PM
To: Mark Davidson <mdavidson@soltra.com>, "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>
Subject: [cti-stix] RE: Can we just make a little bit of progress?

Thank you Mark.  I think more than a few of the members are feeling what you are feeling – exhaustion from the endless debate.  I believe that some have already tuned out, we need to take steps now to prevent losing others.
 
I would suggest – Co-chairs:  Borrowing from Agile here - Can we:
1.     pick a topic, one topic, (maybe that is JSON right now, great, we can slow down all other debate and all take a breath)
2.     drive it to conclusion with a quick vote (like a week perhaps),
3.     implement the resolution
4.     then move on to the next topic? 
 
Can we perhaps do this in some small intervals, like maybe 1 month (instead of a big bang approach)?  Can we publish our roadmap of topics that we plan on tackling in the next N months (6?), knowing that it will most likely change as we go?
 
I think at some point we also need to address group participation, as it impacts voting quite a bit.  Do we maybe have too many people in this group?  Makes driving to a consensus or a majority very difficult.
 
Also, I would suggest that we are trying to solve far too much over email.  Am I the only one that doesn’t have time to sit and read some of these huge email chains every day?  I have to admit, I find myself looking at these emails, with topics that are by no means “light”, and saying “wow, doesn’t anyone have a day job!?”.  Huge kudos to Aharon for organizing the face-to-face meeting coming up soon, but I would suggest that it needs to happen more than once a year.  2 at a minimum.  I feel that if we don’t change to an agile, small release format as noted above, the more frequent face-to-face meetings are critical.  Each one should end in a release of the format.
 
From: cti-stix@lists.oasis-open.org [mailto:cti-stix@lists.oasis-open.org] On Behalf Of Mark Davidson
Sent: Tuesday, December 01, 2015 8:12 AM
To: cti-stix@lists.oasis-open.org
Subject: [cti-stix] Can we just make a little bit of progress?
 
I'd like to offer a perspective, and this is in response to nobody in particular.
 
STIX 2.0 was kicked off on October 21, which is about ~5 weeks of work time (subtracting the US Thanksgiving holiday week). Since then, topics under discussion have included from sightings, the indicator type vocabulary, an MTI discussion (which is currently under a TC-wide vote), relationships, and timestamps. From what I can see, the ONLY topic we seem to be anywhere near reaching a conclusion on is the MTI discussion because it's resolution was motioned.
 
I hope I surprise nobody when I say that the outsider perspective of our TC, and this SC in particular, is that we debate topics endlessly and never reach a conclusion on them. I challenge everyone to change this perception. Can we please drive resolution on some of the topics we've discussed? Can some design artifacts be updated with the current state of the discussion? 
 
By now we should have an updated STIX 2.0 architecture with Relationships and possibly Sightings broken out into their own top level objects. Other bits and pieces should also be documented by now. We seem to have a rough consensus on how timestamps should work (as Bret called out yesterday) - where can that be documented?
 
We should have a model that is malleable and gets updated on a regular basis as we discuss topics, decide things, and change previous decisions (yes, we are allowed to do that!). How can we do that?
 
I find the endless debate tiring, and it discourages me from participating. I want my contributions to help push us toward resolution of issues, not add to the cacophony of opinions. If we go back to before the STIX 2.0 kickoff, this SC has been at it for 5+ months - what topics have we resolved?
 
Can we just make a little bit of progress?
 
Thank you.
-Mark

DTCC DISCLAIMER: This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error, please notify us immediately and delete the email and any attachments from your system. The recipient should check this email and any attachments for the presence of viruses.  The company accepts no liability for any damage caused by any virus transmitted by this email.



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]