OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [cti-stix] Re: Reviewing External-Reference


All,

As we discussed on the call and in the thread with this subject line (it was split a bunch and I didn’t know which to reply to so I just deleted it all), we need to figure out whether the external_references field should be on all TLOs or just most TLOs.

External references are used for a couple things:

1. To provide an ID reference to the TLO’s ID in a non-STIX system. For example, the CVE for a Vulnerability TLO, the CAPEC ID for an Attack Pattern TLO, or a Remedy/other ID for an Incident.
2. To provide a URL reference to the TLO’s representation in some other format, like the PDF version of a Report, or other supporting material (why the object was created)

The definition for external references is here: https://docs.google.com/document/d/1HJqhvzO35h62gQGPvghVRIAtQrZn3_J__0UcDAj-NXY/edit#heading=h.cez46v5quobo 

At this point we think the definition itself is in good shape and I’m hoping to make a motion on it as soon as I can put together the e-mail. But the definition doesn’t answer the question of where it should be used: should we have an external_references field as part of TLO Common Object Properties and therefore be available on all TLOs (including future ones) or should we only add it to the TLOs where we know it makes good sense? After some discussion it seems like it makes sense essentially everywhere except for maybe Relationship, Marking Definition, Sighting, and Observation…use cases have been brought up for some or all of those, they’re just not as strong as on things like Attack Pattern.

Based on the mailing list discussion and discussion on the call it looks like we’re leaning towards including it on all TLOs at this point, but I wanted to give people another chance to give some feedback, in particular if you haven’t weighed in yet.

Thanks!
John



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]