CTI STIX Subcommittee

 View Only
  • 1.  STIX 2.1 Proposal - IEP Data Marking Object

    Posted 01-13-2017 04:30
    Hi All, This proposal is for adding the ability to mark STIX objects using the FIRST Information Exchange Policy (IEP) Framework. This would be designed to support IEP 2.0 currently under development. The IEP Framework is a FIRST backed initiative to help Organizations better define how recipients can use their threat intelligence. In other words  "What am I allowed to do with this intel?". Think of it as TLP with extra features! IEP 1.0 was accepted for inclusion in STIX 2.0 but was eventually removed due to the lack of implementation detail. IEP 2.0 has rectified this with the inclusion of an additional separate detailed JSON Standard which provides the implementation detail needed.  Please note: The IEP 2.0 documentation is not yet in the public domain as it is still under development by the FIRST IEP-SIG. We expect the final version of IEP to be released in the next 2-3 months, which should easily fit into the STIX 2.1 development timeframe. Please add this to the list of items to be included in STIX 2.1. Cheers Terry MacDonald   Chief Product Officer M:   +64 211 918 814 E:   terry.macdonald@cosive.com W:   www.cosive.com Attachment: STIX2.1Proposal-InformationExchangePolicyMarkingObjectType2.pdf Description: Adobe PDF document


  • 2.  Re: [cti-stix] STIX 2.1 Proposal - IEP Data Marking Object

    Posted 01-13-2017 17:15
    Seconded.

    Patrick Maroney
    Principle Engineer - Data Science & Analytics
    Wapack Labs
    pmaroney@wapacklabs.com
    (609)841-5104


    On Jan 12, 2017, at 11:29 PM, Terry MacDonald <terry.macdonald@cosive.com> wrote:

    Hi All,

    This proposal is for adding the ability to mark STIX objects using the FIRST Information Exchange Policy (IEP) Framework. This would be designed to support IEP 2.0 currently under development.

    The IEP Framework is a FIRST backed initiative to help Organizations better define how recipients can use their threat intelligence. In other words "What am I allowed to do with this intel?". Think of it as TLP with extra features!

    IEP 1.0 was accepted for inclusion in STIX 2.0 but was eventually removed due to the lack of implementation detail. IEP 2.0 has rectified this with the inclusion of an additional separate detailed JSON Standard which provides the implementation detail needed.

    Please note: The IEP 2.0 documentation is not yet in the public domain as it is still under development by the FIRST IEP-SIG.

    We expect the final version of IEP to be released in the next 2-3 months, which should easily fit into the STIX 2.1 development timeframe.

    Please add this to the list of items to be included in STIX 2.1.

    Cheers

    Terry MacDonald | Chief Product Officer



    M: +64 211 918 814
    E: terry.macdonald@cosive.com
    W: www.cosive.com



    <stix2.1proposal-informationexchangepolicymarkingobjecttype2.pdf>

    ---------------------------------------------------------------------
    To unsubscribe from this mail list, you must leave the OASIS TC that
    generates this mail. Follow this link to all your TCs in OASIS at:
    https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
    </stix2.1proposal-informationexchangepolicymarkingobjecttype2.pdf></terry.macdonald@cosive.com>


  • 3.  Re: [cti-stix] STIX 2.1 Proposal - IEP Data Marking Object

    Posted 01-13-2017 17:15
      |   view attached
    Seconded. Patrick Maroney Principle Engineer - Data Science & Analytics Wapack Labs pmaroney@wapacklabs.com (609)841-5104 On Jan 12, 2017, at 11:29 PM, Terry MacDonald < terry.macdonald@cosive.com > wrote: Hi All, This proposal is for adding the ability to mark STIX objects using the FIRST Information Exchange Policy (IEP) Framework. This would be designed to support IEP 2.0 currently under development. The IEP Framework is a FIRST backed initiative to help Organizations better define how recipients can use their threat intelligence. In other words   What am I allowed to do with this intel? . Think of it as TLP with extra features! IEP 1.0 was accepted for inclusion in STIX 2.0 but was eventually removed due to the lack of implementation detail. IEP 2.0 has rectified this with the inclusion of an additional separate detailed JSON Standard which provides the implementation detail needed.  Please note: The IEP 2.0 documentation is not yet in the public domain as it is still under development by the FIRST IEP-SIG. We expect the final version of IEP to be released in the next 2-3 months, which should easily fit into the STIX 2.1 development timeframe. Please add this to the list of items to be included in STIX 2.1. Cheers Terry MacDonald   Chief Product Officer M:   +64 211 918 814 E:   terry.macdonald@cosive.com W:   www.cosive.com <STIX2.1Proposal-InformationExchangePolicyMarkingObjectType2.pdf> --------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC that generates this mail.  Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php


  • 4.  Re: [cti-stix] STIX 2.1 Proposal - IEP Data Marking Object

    Posted 01-14-2017 03:17
    I support this.


    Bret

    ________________________________
    From: cti-stix@lists.oasis-open.org <cti-stix@lists.oasis-open.org> on behalf of Terry MacDonald <terry.macdonald@cosive.com>
    Sent: Thursday, January 12, 2017 9:29:52 PM
    To: cti-stix@lists.oasis-open.org; cti-users@lists.oasis-open.org
    Cc: iep-sig@first.org
    Subject: [cti-stix] STIX 2.1 Proposal - IEP Data Marking Object

    Hi All,

    This proposal is for adding the ability to mark STIX objects using the FIRST Information Exchange Policy (IEP) Framework. This would be designed to support IEP 2.0 currently under development.

    The IEP Framework is a FIRST backed initiative to help Organizations better define how recipients can use their threat intelligence. In other words "What am I allowed to do with this intel?". Think of it as TLP with extra features!

    IEP 1.0 was accepted for inclusion in STIX 2.0 but was eventually removed due to the lack of implementation detail. IEP 2.0 has rectified this with the inclusion of an additional separate detailed JSON Standard which provides the implementation detail needed.

    Please note: The IEP 2.0 documentation is not yet in the public domain as it is still under development by the FIRST IEP-SIG.

    We expect the final version of IEP to be released in the next 2-3 months, which should easily fit into the STIX 2.1 development timeframe.

    Please add this to the list of items to be included in STIX 2.1.

    Cheers

    Terry MacDonald | Chief Product Officer

    [cid:ii_ieey6d6n0_14fb9f453311a1f9]

    M: +64 211 918 814<tel:+64+211+918+814>
    E: terry.macdonald@cosive.com<mailto:terry.macdonald@cosive.com>
    W: www.cosive.com<https: clicktime.symantec.com/a/1/1mcriwpew751ddepvuzxced9zemfux_vnqwccs90bf0="?d=byJasoF1RRMKAffvfTPOjBczgAq6WxAYXgPcvCVjHUF4_JulQX9ljX9Rvc7YBc1VgR54DVRX0Wf8q0phcHUB_tqO7Q3kVFKE9D3YpNkt8DfGnlCffqD_ta9VlrIcemRQMCKxsY7s6ZoIy6rHUYp4apj2G18FUHfinXyTp86uZ9vRGmYCwkMrcSdksI6WItLLmeZqLq2el10_-Xy9emyfXQ99M-zx1bGqQ9BBQMVJ1QpLjUexnTIhsGLHOfo5PJOVeRaWid5sza4_ERL-oXnqpSECmOVEfkT0EizSod8Ff9W3BOLFe4mUvvGDgd4lJ_6EjYqkMyHJrQFF4Hqv3qCo-YszjixCYJGz1ODKVmau9UEwT4hLeVpwcY5WnQCHtMxaSHgiz6AFcGbR74rgNe-dZ8dkys_YBgcsj4LlmT_DUdQ0iP6r6yQishrAcsdlq1_ORmGI8A2uaM3-RRI0PzfDhMl2tCTqA23GIxpD0TiPRw%3D%3D&u=https%3A%2F%2Fwww.cosive.com%2F">




    </https:></mailto:terry.macdonald@cosive.com></tel:+64+211+918+814></terry.macdonald@cosive.com></cti-stix@lists.oasis-open.org>


  • 5.  Re: [cti-stix] STIX 2.1 Proposal - IEP Data Marking Object

    Posted 01-14-2017 03:17
      |   view attached
    I support this. Bret From: cti-stix@lists.oasis-open.org <cti-stix@lists.oasis-open.org> on behalf of Terry MacDonald <terry.macdonald@cosive.com> Sent: Thursday, January 12, 2017 9:29:52 PM To: cti-stix@lists.oasis-open.org; cti-users@lists.oasis-open.org Cc: iep-sig@first.org Subject: [cti-stix] STIX 2.1 Proposal - IEP Data Marking Object   Hi All, This proposal is for adding the ability to mark STIX objects using the FIRST Information Exchange Policy (IEP) Framework. This would be designed to support IEP 2.0 currently under development. The IEP Framework is a FIRST backed initiative to help Organizations better define how recipients can use their threat intelligence. In other words  "What am I allowed to do with this intel?". Think of it as TLP with extra features! IEP 1.0 was accepted for inclusion in STIX 2.0 but was eventually removed due to the lack of implementation detail. IEP 2.0 has rectified this with the inclusion of an additional separate detailed JSON Standard which provides the implementation detail needed.  Please note: The IEP 2.0 documentation is not yet in the public domain as it is still under development by the FIRST IEP-SIG. We expect the final version of IEP to be released in the next 2-3 months, which should easily fit into the STIX 2.1 development timeframe. Please add this to the list of items to be included in STIX 2.1. Cheers Terry MacDonald   Chief Product Officer M:   +64 211 918 814 E:   terry.macdonald@cosive.com W:   www.cosive.com