OASIS Cyber Threat Intelligence (CTI) TC

 View Only
  • 1.  Slides, legislation and BoF (was) Re: [cti] F2F Update & Call for agenda

    Posted 01-04-2016 23:50
      |   view attached
    Rich et al., For those who want to consider the rather significant larger context in which this work is being done and focus on the associated data models, architectures, and interfaces: 1.  The canonical reference for those uploaded slides, for outside, non-TC access, at the moment is:  https://lists.oasis-open.org/archives/ cti /201601/msg00000/_ cybersecurity _act_reference-model_1.1. pptx 2.  For those who do not use a compatible powerpoint application , a PDF version is attached. 3. For clarity's sake, members of the TC are welcome to re-post my slide deck, if you wish, but it's provided to the TC for information, not as a technical contribution.  It represents a considerable amount of work not otherwise available and is intended to be helpful to those implementing the Act in the very short time frames required. 4. Other OASIS technical specifications may be useful beyond those in TC CTI. cheers, --tony Attachment: _cybersecurity_act_reference-model_1.1.pdf Description: Adobe PDF document

    Attachment(s)



  • 2.  Re: [cti] Slides, legislation and BoF (was) Re: [cti] F2F Update & Call for agenda

    Posted 01-09-2016 04:53
    In case some are interested by (US) strategy regarding standardization Ref NIST IR8074 http://www.fiercegovernmentit.com/story/white-house-aims-engage-private-sector-international-organizations-global-c/2016-01-04 Regards On Tuesday, 5 January 2016, Tony Rutkowski < tony@yaanatech.com > wrote: Rich et al., For those who want to consider the rather significant larger context in which this work is being done and focus on the associated data models, architectures, and interfaces: 1.  The canonical reference for those uploaded slides, for outside, non-TC access, at the moment is:  https://lists.oasis-open.org/archives/ cti /201601/msg00000/_ cybersecurity _act_reference-model_1.1. pptx 2.  For those who do not use a compatible powerpoint application , a PDF version is attached. 3. For clarity's sake, members of the TC are welcome to re-post my slide deck, if you wish, but it's provided to the TC for information, not as a technical contribution.  It represents a considerable amount of work not otherwise available and is intended to be helpful to those implementing the Act in the very short time frames required. 4. Other OASIS technical specifications may be useful beyond those in TC CTI. cheers, --tony


  • 3.  Re: [cti] Slides, legislation and BoF (was) Re: [cti] F2F Update & Call for agenda

    Posted 01-09-2016 12:50
      |   view attached
    There were two significant problems with that NISTIR. 1) it was highly NIST centric dealing within what amounts to Washington agency politics, and is simply one agency's publication.  It was eclipsed if not replaced by the new Act which is U.S. organic law, and 2) it omitted vast swaths of the cyber security universe.  For a far more extensive, balanced, and useful guide to the cyber security standards universe, see Global Cyber Security Ecosystem. --tony On 2016-01-08 11:53 PM, Jerome Athias wrote: In case some are interested by (US) strategy regarding standardization Ref NIST IR8074 http://www.fiercegovernmentit.com/story/white-house-aims-engage-private-sector-international-organizations-global-c/2016-01-04 Regards On Tuesday, 5 January 2016, Tony Rutkowski < tony@yaanatech.com > wrote: Rich et al., For those who want to consider the rather significant larger context in which this work is being done and focus on the associated data models, architectures, and interfaces: 1.  The canonical reference for those uploaded slides, for outside, non-TC access, at the moment is:  https://lists.oasis-open.org/archives/ cti /201601/msg00000/_ cybersecurity _act_reference-model_1.1. pptx 2.  For those who do not use a compatible powerpoint application , a PDF version is attached. 3. For clarity's sake, members of the TC are welcome to re-post my slide deck, if you wish, but it's provided to the TC for information, not as a technical contribution.  It represents a considerable amount of work not otherwise available and is intended to be helpful to those implementing the Act in the very short time frames required. 4. Other OASIS technical specifications may be useful beyond those in TC CTI. cheers, --tony -- ________________________________ Anthony Michael Rutkowski EVP, Industry Standards & Regulatory Affairs tony@yaanatech.com +1 703 999 8270 ________________________________ Yaana Technologies LLC 542 Gibraltar Drive Milpitas CA 95035 USA Attachment: tr_103306v010101p.pdf Description: Adobe PDF document

    Attachment(s)

    pdf
    tr_103306v010101p.pdf   553 KB 1 version


  • 4.  F2F#01_BOF_cybersecurity-act+EUnis presentation

    Posted 01-15-2016 13:41
      |   view attached
    slides from this morning's BOF. Feedback is appreciated. --tony Attachment: _CTI_F2F#01_cybersecurity_act_presentation.pptx Description: application/vnd.openxmlformats-officedocument.presentationml.presentation

    Attachment(s)



  • 5.  [cti] Slides, legislation and BoF (was) Re: [cti] F2F Update & Call for agenda

    Posted 01-09-2016 16:23
    Dear all, The objective of the Friday morning BOF slot is to make is as interactive and useful to CTI work as possible within the 30 minute timeframe.  In BOF tradition, it will also be informal and off the record. Towards that end, the following blog article may be helpful to provide an understanding of the larger context and why TC CTI work has a newly enhanced importance.  See https://www.yaanatech.com/implementing-the-cybersecurity-act-of-2015-a-public-private-specifications-approach/ Note also that the entity diagram at the end of the blog that is derived from another analysis denominated the entity ontology deconstruction of the Act. The BOF focus will necessarily be on the slide 8 challenge questions (or more as appropriate).   The idea is really to frame the questions.  The answers are complex and not going to be found in a few minute discussion. 1. Is the deconstructed architecture accurate, useful? 2. What information exchange requirements exist at the three identified NCCIC interfaces? 3. What assumptions should be made about the capabilities and architectures within these three domains (federal, non-federal, international)? 4. What other other information exchange interfaces among the enumerated entities? Are there sector-specific interface sub-types and what are they? 5. What are the required information sharing expressions and other capabilities at these interfaces, and to what extent can existing and planned TC CTI specifications be mapped to these requirements? 6. What entities transform threat intelligence into defensive measures, e.g., to the Twenty Controls?  How does the SACM work mate with the CTI work? 7. What are the algorithms for the “personal information of a specific individual or information that identifies a specific individual” filter function, and how/where is this work going to occur? 8. Is it feasible to create an ad-hoc TC CTI or OASIS group to assist in the Act’s implementation similar to other compliance obligations? --tony ps. I'm also on the hook as the rapporteur for ETSI TC CYBER's CTI work item to recommend at its formal meeting in four weeks, how to sync with CTI.  Appreciate any ideas for globalisation of this work.