OASIS Cyber Threat Intelligence (CTI) TC

 View Only

STIX Extensions Policy Discussion in Next STIX WG Meeting

  • 1.  STIX Extensions Policy Discussion in Next STIX WG Meeting

    Posted 11-11-2022 15:00
    Hi,   As Rich mentioned last week,  updates to the STIX Extensions Policy are needed.  Rich Piazza will lead the next session of the STIX WG on Tuesday, November 15, 2022 which will be devoted to discussing potential updates. I would like to invite you to join in this special session if you are working on extensions or have an interest in STIX extensions. The meeting invitation for the session is on Kavi here .   The working draft based on the current policy is   here .   Quoting Rich:  The following are some of the issues to be discussed:   What requirements should be adhered to for any validator implementation? How are approved extension definitions expressed in a future STIX specification? Should extensions based on external specifications and/or frameworks always remain extensions and not be an “official” part of the STIX specification (e.g., ATT&CK)? Are there some requirements or best practices for creating a JSON schema for an extension definition – perhaps related to the requirements of a validator?   Please come share your thoughts and ideas!   Emily