OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti] Documents


+1

Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." 

On Mar 7, 2016, at 16:18, Allan Thomson <athomson@lgscout.com> wrote:

Hi Sean - 

Appreciate your response. I understand that each of the 3 documents are not the same content. I also understand the relationship between them.

What I meant by “version” was that when an implementer wants to implement STIX version X they also need to implement CTI Common 1.0 and CyBOx 3.0. And they have to know what versions of each of the 3 documents they are building a product on. 

I can see arguments for and against having them be separate documents. 

But I still lean towards having a single document that contains 3 separate sections with ONE version for the combined content.

Subsequent updates to CyBox content would just update the content of that section in the document and a new version of the combined STIX could be generated.

So instead of a testing matrix hell that would have 3 trains (CTI Common, STIX and CyBox), I think one train is better. STIX 2.0, STIX 2.1, STIX 2.2….etc.

Allan





On Mar 7, 2016, at 11:11 AM, Barnum, Sean D. <sbarnum@MITRE.ORG> wrote:

Allan, I would like to point out a concern I have with the way you characterize things below.

We are not talking about “versions” of a single body of content.
We are talking about completely different bodies of content. 
Are their interrelationships between them? Yes.
Are they all the same thing? No.
Are there clear reasons why they should be different things? Yes.
Are there other bodies of content that will want to relate with one or two but not all three of these bodies of content? Yes.

Characterizing this issue as a versioning issue is, I believe, inaccurate and misleading.
I do not think that was your intent but I believe that it could be the result from some reading your post.

sean

From: <cti@lists.oasis-open.org> on behalf of Allan Thomson <athomson@lgscout.com>
Date: Monday, March 7, 2016 at 1:45 PM
To: "Jordan, Bret" <bret.jordan@BLUECOAT.COM>
Cc: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
Subject: Re: [cti] Documents

Having a single version of the content is preferred from my perspective.

You can still have normative text that describes each module separately.

But having ONE version to track for the related content is preferred.

allan

On Mar 7, 2016, at 9:14 AM, Jordan, Bret <bret.jordan@BLUECOAT.COM> wrote:

Right now, we have three documents for STIX & CybOX, aka CTI.  We have:

CTI Common 1.0
STIX 2.0
CybOX 3.0

I would like to challenge this design.  It seems like we are opening ourselves to document versioning and compliance / interoperability nightmares. 

1) Does it really make sense, other than for historical reasons, to keep these documents separate?  

2) If they were merged, then could not things like MAEC and other standards (that are NOT part of OASIS) just reference the sections that were of interest to them?



Thanks,

Bret



Bret Jordan CISSP
Director of Security Architecture and Standards | Office of the CTO
Blue Coat Systems
PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050
"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg." 




Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]