CTI STIX Subcommittee

 View Only
  • 1.  Object Markings - Ballot Take 2

    Posted 07-12-2016 13:42




    All,
     
    I haven’t seen any further comments on the Object Markings text since the update to address the ballot comments, so I’ve copied it into the main document here:

    https://docs.google.com/document/d/1HJqhvzO35h62gQGPvghVRIAtQrZn3_J__0UcDAj-NXY/edit#heading=h.bnienmcktc0n
     
    Since it seems like most (though not all) of the disagreements are resolved,
    I move that the TC open a ballot to mark the Object-Level Markings section in the STIX 2.0-Core document as Consensus.
     
    Complete text of that section is below.
     
    John
     
    ---

    ?6.2.? Object-Level Markings






    Status:
    Review
    MVP :
    Yes




     
    Data markings provide the ability to mark data in STIX, typically to represent restrictions and permissions for how that data can be used and shared. For example, data may be
    shared with the restriction that it not be re-shared, or that it must be encrypted at rest. Object-level data markings define how markings are applied to TLOs.
     
    Object-level markings are contained in the
    object_marking_refs field, which is an optional list of ID references (of type
    identifier ) that resolve to objects of type
    marking-definition . The markings referenced by the
    object_marking_refs field and defined in the
    marking-definition object apply to that TLO and all of its fields.

    ?6.2.1.? Precedence
    Some types of marking definitions have rules about precedence. If the marking definition defines these rules, markings appearing earlier in the list have precedence over those
    appearing later. For example, a TLP marking appearing as the first element in the list has precedence over a TLP marking appearing as the second element.

    ?6.2.3.? Examples
    This example marks the indicator with the marking definition referenced by the ID.
    {
     "type": "indicator",
     "id": "indicator--089a6ecb-cc15-43cc-9494-767639779235",
     ...
     "object_marking_refs": ["marking-definition--089a6ecb-cc15-43cc-9494-767639779123"],
     ...
    }
     
     
    John






  • 2.  Re: [cti-stix] Object Markings - Ballot Take 2

    Posted 07-14-2016 15:09
    On 12.07.2016 13:41:29, Wunder, John A. wrote: > > I haven’t seen any further comments on the Object Markings text > since the update to address the ballot comments, so I’ve copied it > into the main document here: > https://docs.google.com/document/d/1HJqhvzO35h62gQGPvghVRIAtQrZn3_J__0UcDAj-NXY/edit#heading=h.bnienmcktc0n > > Since it seems like most (though not all) of the disagreements are > resolved, I move that the TC open a ballot to mark the Object-Level > Markings section in the STIX 2.0-Core document as Consensus. > Motion seconded. -- Cheers, Trey ++--------------------------------------------------------------------------++ Kingfisher Operations, sprl gpg fingerprint: 85F3 5F54 4A2A B4CD 33C4 5B9B B30D DD6E 62C8 6C1D ++--------------------------------------------------------------------------++ -- "It Has To Work." --RFC 1925 Attachment: signature.asc Description: Digital signature