There were two significant problems with that NISTIR. 1) it was highly NIST centric dealing within what amounts to Washington agency politics, and is simply one agency's publication. It was eclipsed if not replaced by the new Act which is U.S. organic law, and 2) it omitted vast swaths of the cyber security universe. For a far more extensive, balanced, and useful guide to the cyber security standards universe, see Global Cyber Security Ecosystem. --tony On 2016-01-08 11:53 PM, Jerome Athias wrote: In case some are interested by (US) strategy regarding standardization Ref NIST IR8074
http://www.fiercegovernmentit.com/story/white-house-aims-engage-private-sector-international-organizations-global-c/2016-01-04 Regards On Tuesday, 5 January 2016, Tony Rutkowski <
tony@yaanatech.com > wrote: Rich et al., For those who want to consider the rather significant larger context in which this work is being done and focus on the associated data models, architectures, and interfaces: 1. The canonical reference for those uploaded slides, for outside, non-TC access, at the moment is:
https://lists.oasis-open.org/archives/ cti /201601/msg00000/_ cybersecurity _act_reference-model_1.1. pptx 2. For those who do not use a compatible powerpoint application , a PDF version is attached. 3. For clarity's sake, members of the TC are welcome to re-post my slide deck, if you wish, but it's provided to the TC for information, not as a technical contribution. It represents a considerable amount of work not otherwise available and is intended to be helpful to those implementing the Act in the very short time frames required. 4. Other OASIS technical specifications may be useful beyond those in TC CTI. cheers, --tony -- ________________________________ Anthony Michael Rutkowski EVP, Industry Standards & Regulatory Affairs
tony@yaanatech.com +1 703 999 8270 ________________________________ Yaana Technologies LLC 542 Gibraltar Drive Milpitas CA 95035 USA Attachment: tr_103306v010101p.pdf Description: Adobe PDF document