OASIS Cyber Threat Intelligence (CTI) TC

 View Only

STIX Core Incident Extension - Can We Bring it to Vote?

  • 1.  STIX Core Incident Extension - Can We Bring it to Vote?

    Posted 06-09-2022 22:13
    I was curious if we could hold a vote on accepting the Core Incident Extension https://github.com/oasis-open/cti-stix-common-objects/tree/main/extension-definition-specifications/incident-core as a specification candidate extension for STIX 2.1. As of now a number of TC members have worked on this and I believe we have treated it as such, but the end state of this workflow is somewhat undefined. Without further action from the TC it is simply an extension to be considered to be added to the next version of STIX. In order to better solidify this flow I would ask if we could bring this up to a vote and if this passes begin adding these extensions to STIX 2.1's errata to allow vendors to be easily access these documents from an official source and be confident that they will be writing their code against a stable foundation. This will also allow future interoperability documentation for STIX 2.1 to reference these new extensions when we talk about creating new profiles and expanded interoperability levels. //SIGNED// Jeffrey Mates, Civ DC3/TSD Computer Scientist Technical Solutions Development jeffrey.mates@us.af.mil 410-694-4335 Attachment: smime.p7s Description: S/MIME cryptographic signature