OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Object Level Markings


Hi folks,

I'm a newcomer to this TC (and indeed OASIS), so you'll have to forgive me if I'm missing something, or retracing your steps, or going about things to wrong way.

The current section 6.5 appears to discuss aspects of object level markings, and suggests these might cover both legal permissioning (such as Copyright), and MAC systems (such as security labelling). Mixing the two is interesting - I hadn't considered this but it makes sense.

Also, the system operates by reference. This is going to be very difficult to manage, and is traditionally avoided in most cases. This is especially true if the referenced label data for the marking is not present within the same transmission, since automated tooling for MAC will become extremely complex (and complexity begets unhappy accreditors).

Has the group considered prior art in this space? I'm thinking particularly of XMPP's XEP-0258, but others may also apply. I'm particularly keen to ensure that multipolicy systems will work effectively, since I see that as being very likely in the CTI world shortly.

As for multiple orthogonal rules - I don't understand where precedence comes into this. Taking Copyright as an example, if one derives a work from an existing work, the copyright changes, and the license may also change - I don't see the benefit in including a list of previous copyright notices, and then having the systems decide which one applies.

I would expect that every marking present would need to be adhered to (some might not be practical to adhere to programmatically, of course). But you can't share something, say, UK SECRET, no matter what the copyright notice says - and vice-versa, an unclassified document cannot be shared if the copyright license is not available.

Happy to discuss this further, or or out of any particuar call.

Dave.



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]