OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-users] Fwd: FIRST Information Exchange Policy Special Interest Group (IEP-SIG) - Call for Participation


Hi Patrick,

That's fine with me, as I was already involved in the creation of the draft framework. I really do hope that others join as well, as I think this could be a great way of increasing the fidelity of the permissions a producer can apply to their STIX content. But we need people to comment, critique and challenge in order to get this right.

Cheers

Terry MacDonald | Chief Product Officer







On Fri, Apr 8, 2016 at 8:40 PM, Patrick Maroney <Pmaroney@specere.org> wrote:
Terry,

Thank you for sharing and highlighting this activity.   I read through everything: They've made great progress and have produced an excellent body of work at many levels.  

Re:" I have very high hopes for the IEP, and I think it would be excellent to use this within STIX as the data marking mechanism. The examples that have been provided are all in JSON, so it would work perfectly."

I agree with your assessment that there is great potential here and that it is worth exploring.

i propose/move that we should:

(1) Identify and engage CTI TC members engaged in the IEP-SIG and organize a group of interested parties to:

(1.1) Explore the IEP-SIG work products in the context of how we could integrate/adopt.  

(1.2) Identify risks and opportunities.

(1.3) Report findings/recommendations back to the TC.
 

(2) I also nominate you to lead this effort. 👍



Patrick Maroney
President
Integrated Networking Technologies, Inc.
Desk: (856)983-0001
Cell: (609)841-5104
Email: pmaroney@specere.org

_____________________________
From: Terry MacDonald <terry.macdonald@cosive.com>
Sent: Thursday, April 7, 2016 6:16 PM
Subject: [cti-users] Fwd: FIRST Information Exchange Policy Special Interest Group (IEP-SIG) - Call for Participation
To: <cti@lists.oasis-open.org>, <cti-users@lists.oasis-open.org>


Hi All,

The FIRST Information Exchange Policy Special Interest Group (IEP-SIG)  have very recently announced the FIRST IEP-SIG Call for Participation. The Information Exchange Policy is designed to help information producers specify how recipients have to handle the producers data, who they can share it with and what they are allowed to do with the producers data. It is designed to extend TLP in a useful way.

I have very high hopes for the IEP, and I think it would be excellent to use this within STIX as the data marking mechanism. The examples that have been provided are all in JSON, so it would work perfectly.

As mentioned below, anyone can participate in the IEP-SIG, including organizations who are not members of FIRST. If you would like to join the IEP-SIG then please email the FIRST Secretariat first-sec@first.org
 
Cheers

Terry MacDonald | Chief Product Officer







---------- Forwarded message ----------
From: Paul McKitrick <pmckit@microsoft.com>
Date: Fri, Apr 1, 2016 at 3:40 PM
Subject: FIRST Information Exchange Policy Special Interest Group (IEP-SIG) - Call for Participation
To: "first-teams@first.org" <first-teams@first.org>, "iep-sig@first.org" <iep-sig@first.org>
Cc: Steve Mancini <smancini@cylance.com>, Terry MacDonald <terry.macdonald@cosive.com>, Merike Kaeo <merike@fsi.io>, "Paul McKitrick (NZITF)" <paul@nzitf.org.nz>


Hi FIRST teams,

 

The FIRST Information Exchange Policy Special Interest Group (IEP-SIG) Co-Chairs are pleased to announce the FIRST IEP-SIG Call for Participation.

 

Anyone can participate in the IEP-SIG, including organizations who are not members of FIRST, and we would like a global representation and cross section of participants including National CERTs, incident responders, security vendors, community stewards, policy writers, and lawyers. If you would like to join the IEP-SIG then please email the FIRST Secretariatfirst-sec@first.org.

 

Please find the following documents attached:

·        The FIRST IEP-SIG Call for Participation -FIRST IEP-ISG Call for Participation.pdf

·        The proposed draft of the FIRST IEP Framework v1.0 -FIRST IEP Framework 1.0 (draft).pdf

·        A recent presentation by the IEP-SIG Co-Chairs that provides some background context to this problem space (please note that some affiliations have changed since the time of this presentation) - MSRA 2015 - Automating Information Exchange.pdf

We look forward to your participation and contributions to initiative over the coming months.

 

Regards,

Paul.

 

Paul McKitrick

Senior Security Strategist

Microsoft Security Response Center

 

Office:   +1 425 704 0338

Mobile:  +1 425 749 0811

pmckit@microsoft.com

MSFT_logo_small

 

 







[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]