OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-taxii message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-taxii] Questioning the wisdom of using DNS SRV records for TAXII 2.0 Discovery


2015-10-31 11:37 GMT+03:00 Trey Darley <trey@soltra.com>:
> On 30.10.2015 21:28:38, Jordan, Bret wrote:
>>
> It would be worth threat modeling the TAXII 2.0 architecture (once the
> spec's closer to completion) with an eye towards generating a TAXII
> 2.0 security best practices guide for implementers as an OASIS work
> product.
>

Open Microsoft Threat Modeler 2016
Define a new template (new function of version 2016)
Put CAPEC in it
Draw the Threat Model

Exam duration: 1 hour ;-)

PS: no comment on the air-gap myth in the SCADA world


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]