[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [cti] Agenda for Today's Working Call - 3/6/2018
Here are the notes from today’s call. The call began by articulating and re-affirming goals for STIX 2.1: STIX 2.1 will be a strong technical specification that contributes to improving the defensive posture of organizations and institutions that support our societies by:
1.
Promoting interoperability along key features, such as internationalization, malware, CoA, etc.
2.
Permitting rapid feature iteration, for instance by creating an extension process, so that we can adapt to the evolving threat landscape
3.
Including necessary backward breaking changes
4.
Enabling broad marketplace adoption
5.
Minimizing backward breaking changes for new work, through meeting the TC-approved “definition of done” We also identified, for the purposes of the call, some terms to use when describing the status of issues:
1.
TODO – The TC generally believes the feature is valuable, but has not started work
2.
In Progress – The TC is under active deliberation to define a feature
3.
Text Complete – The TC agrees on the text for a feature, and is ready to begin validating it through software implementations
4.
In Test – The TC is in the process of validating that the feature works in software
5.
Done – The feature is complete After some deliberation, the perspective on the call identified that the critical question facing the TC is: How do we enable rapid implementation of features that are already text complete without committing ourselves to untested text? This is the question that, if left unanswered, will stall development of the STIX/TAXII 2.1 specifications indefinitely. Call participants were able to brainstorm some proposals, along with the common objections
that have been raised. Most notably, I believe we need to find an answer to the critical question and move forward with specification development, even if the answer has known flaws. As a group, we must find a way to move forward. The answers brainstormed on the call (and shortly after in slack), along with their known objections, are:
The CTI TC’s must deliberate and select an answer to the critical question, and must proceed in unison once an answer is selected. Please debate the value of the various solutions, and continue to propose
new ones. Thank you. -Mark From: <cti@lists.oasis-open.org> on behalf of Mark Davidson <Mark.Davidson@nc4.com> All, The past week has generated a lot of discussion and varying perspectives on how best to proceed with development of STIX/TAXII 2.1. While there is general agreement on the goals for STIX/TAXII 2.1, the implementation
of these goals has uncovered some vigorously debated tradeoffs that warrant further discussion. On today’s working call we will: 1.
Articulate and re-affirm the goals for STIX/TAXII 2.1 2.
Clearly identify the tradeoffs identified through goal implementation and discuss them constructively 3.
Consider a proposed solution for moving forward 4.
Arrive at a concrete proposal that we can use for the duration of STIX/TAXII 2.1 development Thank you.
NC4 Soltra Disclaimer: This message is intended only for the use of the individual or entity to which it is addressed and may contain information which is privileged, confidential, proprietary, or exempt
from disclosure under applicable law. If you are not the intended recipient or the person responsible for delivering the message to the intended recipient, you are strictly prohibited from disclosing, distributing, copying, or in any way using this message.
If you have received this communication in error, please notify the sender and destroy and delete any copies you may have received.
|
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]