OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

openc2-actuator message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [openc2-actuator] Re: description for SBoM AP template request


Thanks, Duncan. Do you think we should change the shorthand correspondingly, to "ap-sbomR"? Right now I can't envision other SBoM-related APs, but if any should arise they should have distinctive shorthands.

The abstract is an exercise in plagiarism and kitbashing from our existing specs and the first of those NTIA documents.ÂÂ

Dave

David Lemire, CISSP
Systems Engineer

HII Mission Driven Innovative Solutions (HII-MDIS) â formerly G2, Inc.

Technical Solutions Division

302 Sentinel Drive | Annapolis Junction, MD 20701

Email: dave.lemire@g2-inc.com

Work: 301-575-5190 | Mobile: 240-938-9350



On Wed, Dec 11, 2019 at 12:10 PM duncan sfractal.com <duncan@sfractal.com> wrote:
  • âShould this be ".... Software Bill of Materials Handling"? "Retrieval"?â
    • Excellent point. SLPF describes the functionality. In this case the functionality is the ability to retrieve the SBoM so âSoftware Bill of Materials Retrievalâ is probably best

The abstract is great. Thank you

Â

Duncan Sparrell

sFractal Consulting LLC

iPhone, iTypo, iApologize

I welcome VSRE emails. Learn more atÂhttp://vsre.info/

Â

Â

From: Dave Lemire <dave.lemire@g2-inc.com>
Date: Wednesday, December 11, 2019 at 9:53 AM
To: "duncan@sfractal.com" <duncan@sfractal.com>, Alex Everett <alex.everett@unc.edu>, David Kemp <Dkemp@mobility-challenge.com>
Cc: OpenC2CoChairs <openc2-committee-chairs@lists.oasis-open.org>, "oasis.oc2.apsc" <openc2-actuator@lists.oasis-open.org>
Subject: description for SBoM AP template request

Â

Related to my previous email:Â At yesterday's AP-SC meeting Duncan Sparrell agreed to edit a proposed Software Bill of Materials (SBoM) Actuator Profile. To request the template, I need certain data, so this email is to coordinate the details. Also, in keeping with our current specification development processes, I assume I'm requesting this template be in Markdown format.

Â

Work product title and version number:ÂÂOpen Command and Control (OpenC2) Profile for Software Bill of Materials, Version 1.0

Â

Should this be ".... Software Bill of Materials Handling"? "Retrieval"?Â

Â

Work product abbreviation: ap-sbom

Track:ÂStandards Track Work Product

Abstract:ÂÂOpen Command and Control (OpenC2) is a concise and extensible language to enable the command and control of cyber defense components, subsystems and/or systems in a manner that is agnostic of the underlying products, technologies, transport mechanisms or other aspects of the implementation. Software Bill of Materials (SBoM) is an emerging set of standards for identifying and listing software components, information about those
components, and supply chain relationships between them. This profile defines the Actions, Targets, Specifiers and Options that are consistent with the version 1.0 of the OpenC2 Language Specification ([OpenC2-Lang-v1.0]) in the context of Software Bill of Materials handling.

Â

Editor(s):Â Duncan Sparrell

Â

NOTE: I'm not sure how to handle the reference to the L-Spec version, since we kind of envision this to be a post-1.0 thing, but I don't think I can refer to a document that doesn't exist or is even in development yet.

Â

Dave

Â

David Lemire, CISSP

Systems Engineer

HII Mission Driven Innovative Solutions (HII-MDIS) â formerly G2, Inc.

Technical Solutions Division

302 Sentinel Drive | Annapolis Junction, MD 20701

Email: dave.lemire@g2-inc.com

Work: 301-575-5190 | Mobile: 240-938-9350



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]