OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-stix message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-stix] Re: [cti-cybox] Re: [EXT] [cti-cybox] Agenda for August 8 Working Call


For reference the IEP-SIG is meeting today in 15 mins in an effort to have IEP 2.0 finalized in time for the STIX 2.1 likely lock down dates. 

IEP is well advanced in it's development. We've created draft STIX data marking objects, and I'll be creating an FAQ on how to use those over the next couple of weeks.

IEP will clarify a lot of the ambiguity that arises from just using TLP as we currently do, and we've had a VERY positive response from FIRST and OASIS members when we've down then the IEP 2.0 before. 

I personally believe it's critical to get IEP added to STIX 2.1 to speed up sharing and make it easier for producers to communicate to consumers what they are allowed to do with the data they receive. 

Cheers
Terry MacDonald
Cosive

On 8/08/2017 07:16, "Wunder, John A." <jwunder@mitre.org> wrote:

For reference, here’s the e-mail discussion from April on the topic: http://markmail.org/search/?q=IEP&q=list%3Aorg.oasis-open.lists.cti-stix#query:IEP%20list%3Aorg.oasis-open.lists.cti-stix+page:1+mid:f7apnrhbdclilfcu+state:results (I hope I did that link right…it’s the thread titled “STIX 2.1: Adding IEP Framework to STIX 2.1”.

 

John

 

From: "Struse, Richard J." <rjs@mitre.org>
Date: Monday, August 7, 2017 at 2:59 PM
To: "Bret Jordan (CS)" <Bret_Jordan@symantec.com>, John Wunder <jwunder@mitre.org>, "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>
Subject: Re: [cti-cybox] Re: [EXT] [cti-cybox] Agenda for August 8 Working Call

 

Since we began this work there has been a clear recognition that TLP, while useful, isn’t sufficient to represent the sorts of policy expressions that are required to truly enable CTI sharing ecosystems. The FIRST community is exactly the sort of hands-on community best suited to develop such policy frameworks and it doesn’t seem like there are any competing policy frameworks under consideration.  Given that, and the fact that we are requiring IEP nor are we “tying” STIX to IEP (or vice-versa), it seems worthwhile to do the work necessary to figure out how to best support those communities that wish to use IEP.

 

Is there anyone actively opposed to the TC figuring out how we might support IEP?

 

From: <cti-cybox@lists.oasis-open.org> on behalf of Bret Jordan <Bret_Jordan@symantec.com>
Date: Monday, August 7, 2017 at 2:45 PM
To: "Wunder, John A." <jwunder@mitre.org>, "cti-stix@lists.oasis-open.org" <cti-stix@lists.oasis-open.org>, "cti-cybox@lists.oasis-open.org" <cti-cybox@lists.oasis-open.org>
Subject: [cti-cybox] Re: [EXT] [cti-cybox] Agenda for August 8 Working Call

 

On the IEP front, we need to make sure the TC wants to do it before we figure out how we should do it.  I would love to see some discussion over email first, before we tackle it on a working call that only has a subset of the membership.  In other words, a working call is not a good place to decide "if" we should do something.  It is a great place to figure out "how" we should do it, once the TC has sufficiently debated and decided to do it.

 

 

Bret

 


From: cti-cybox@lists.oasis-open.org <cti-cybox@lists.oasis-open.org> on behalf of Wunder, John A. <jwunder@mitre.org>
Sent: Monday, August 7, 2017 9:11 AM
To: cti-stix@lists.oasis-open.org; cti-cybox@lists.oasis-open.org
Subject: [EXT] [cti-cybox] Agenda for August 8 Working Call

 

All,

 

We have three topics for the working call this week:

 

1.       Continue work on DNS Request/Response

2.       Continue work on Location, in particular discuss ISO 3166

3.       Discuss inclusion of IEP (how we should do it)

 

John



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]