OASIS Cyber Threat Intelligence (CTI) TC

 View Only
Expand all | Collapse all

EUROPE adopts STIX and TAXII

  • 1.  EUROPE adopts STIX and TAXII

    Posted 01-09-2018 19:57
    Dear Members of the CTI TC, I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement. Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa.eu/ legal-content/EN/TXT/?qid= 1515520575463&uri=CELEX: 32017D2288 Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.* I am delighted that your excellent work has received such high level recognition . Dr Carol Cosgrove-Sacks Senior Advisor on International Standards Policy OASIS   *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom; EFTA: Iceland, Liechtenstein, Norway and Switzerland.) --


  • 2.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-09-2018 20:00
    Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018!  Good work!  /chet On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org > wrote: Dear Members of the CTI TC, I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement. Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa. eu/legal-content/EN/TXT/?qid=1 515520575463&uri=CELEX:32017D2 288 Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.* I am delighted that your excellent work has received such high level recognition . Dr Carol Cosgrove-Sacks Senior Advisor on International Standards Policy OASIS   *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom; EFTA: Iceland, Liechtenstein, Norway and Switzerland.) -- -- /chet  ---------------- Chet Ensign Director of Standards Development and TC Administration  OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393 


  • 3.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-09-2018 20:17
    I don't know anything at all about this
    process - but I noticed it specifically mentions the STIX 1.2 and TAXII
    1.1 versions.         ‘Structured Threat
    Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange
    of Indicator Information’ (‘TAXII 1.1’) developed by the Organization
    for the Advancement of Structured Information Standards (‘OASIS’). How would we get STIX 2.0 and TAXII
    2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have
    insights? - Jason Keirstead STSM, Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security "Things may come to those who wait, but only the things left by those
    who hustle." - Unknown From:      
      Chet Ensign <chet.ensign@oasis-open.org> To:      
      Carol Cosgrove-Sacks
    <carol.cosgrove-sacks@oasis-open.org> Cc:      
      OASIS CTI TC Discussion
    List <cti@lists.oasis-open.org> Date:      
      01/09/2018 03:59 PM Subject:    
        Re: [cti] EUROPE
    adopts STIX and TAXII Sent by:    
        <cti@lists.oasis-open.org> Let me add my congratulations folks. You've worked hard
    these past years. Seeing you get this recognition is a great start to 2018!  Good work!  /chet On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org >
    wrote: Dear Members of the CTI TC, I have just been informed  that the EU has made a
    formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use
    in public procurement. Please see Commission Implementing Decision (EU) 2017/2288
    of 11 December 2017:   http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1515520575463&uri=CELEX:32017D2288 Congratulations!  This
    Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.* I am delighted that your excellent work has
    received such high level recognition. Dr Carol Cosgrove-Sacks Senior Advisor on International Standards Policy OASIS   *(EU: Austria, Belgium,  Bulgaria, Croatia,
    Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany,
    Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta,
    Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden
    and United Kingdom; EFTA: Iceland, Liechtenstein, Norway and Switzerland.) -- -- /chet  ---------------- Chet Ensign Director of Standards Development and TC Administration  OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393 



  • 4.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-09-2018 20:35
    On 09.01.2018 16:16:09, Jason Keirstead wrote: > > How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have > any ideas? Or does it matter? Anyone have insights? > Hey, Jason - I was one of the folks consulted by the EC. In my comments I explicitly recommended standardizing on STIX/TAXII 2.0. I surmise that the EC went with STIX 1.2 / TAXII 1.1 because that's what most products support *today*. Now if we were to see a groundswell of support for 2.0 at RSA this year, that would likely impact the EC's position. -- Cheers, Trey ++--------------------------------------------------------------------------++ Director of Standards Development, New Context gpg fingerprint: 3918 9D7E 50F5 088F 823F 018A 831A 270A 6C4F C338 ++--------------------------------------------------------------------------++ -- "It is easier to move a problem around (for example, by moving the problem to a different part of the overall network architecture) than it is to solve it." --RFC 1925 Attachment: signature.asc Description: Digital signature


  • 5.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-09-2018 20:35
    Hello.  I can confirm that the recognition covers subsequent versions.  The Decision was taken based on the version that was available at the start of the process. Hoping this reassures you. Well done!  Carol  On 9 Jan 2018 9:16 p.m., "Jason Keirstead" < Jason.Keirstead@ca.ibm.com > wrote: I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.         ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’). How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights? - Jason Keirstead STSM, Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security "Things may come to those who wait, but only the things left by those who hustle." - Unknown From:         Chet Ensign < chet.ensign@oasis-open.org > To:         Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis- open.org > Cc:         OASIS CTI TC Discussion List < cti@lists.oasis-open.org > Date:         01/09/2018 03:59 PM Subject:         Re: [cti] EUROPE adopts STIX and TAXII Sent by:         < cti@lists.oasis-open.org > Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018!  Good work!  /chet On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis- open.org > wrote: Dear Members of the CTI TC, I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement. Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa. eu/legal-content/EN/TXT/?qid= 1515520575463&uri=CELEX: 32017D2288 Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.* I am delighted that your excellent work has received such high level recognition. Dr Carol Cosgrove-Sacks Senior Advisor on International Standards Policy OASIS   *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom; EFTA: Iceland, Liechtenstein, Norway and Switzerland.) -- -- /chet  ---------------- Chet Ensign Director of Standards Development and TC Administration  OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393  


  • 6.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-09-2018 20:39




    Carol et al – STIX/TAXII 2.0 are very different from STIX 1.2/TAXII 1.1.
     
    I agree it’s a good thing for EU recognition of a standard but STIX 1.2 is not compatible with STIX 2.0.
     
    I think OASIS need to help educate the marketplace and the governments that rely on the market to understand that versions matter in this regard.
     
    Therefore what does the recognition really mean when it comes to procurement?

     
    A STIX 1.2 product is not interchangeable with a STIX 2.0 product necessarily or vis-versa.
     
    Please advise.
     

    Allan Thomson,

    CTO,
    Lookingglass Cyber Solutions
    This electronic message transmission contains information from LookingGlass Cyber Solutions, Inc. which may be attorney-client privileged, proprietary and/or confidential.
    The information in this message is intended only for use by the individual(s) to whom it is addressed.  If you believe that you have received this message in error, please contact the sender, delete this message, and be aware that any review, use, disclosure,
    copying or distribution of the contents contained within is strictly prohibited

     
     

    From: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org> on behalf of Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org>
    Date: Tuesday, January 9, 2018 at 12:34 PM
    To: Jason Keirstead <Jason.Keirstead@ca.ibm.com>
    Cc: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>, Chet Ensign <chet.ensign@oasis-open.org>
    Subject: Re: [cti] EUROPE adopts STIX and TAXII


     


    Hello. 

    I can confirm that the recognition covers subsequent versions.  The Decision was taken based on the version that was available at the start of the process.


    Hoping this reassures you.


    Well done! 


    Carol 



     

    On 9 Jan 2018 9:16 p.m., "Jason Keirstead" < Jason.Keirstead@ca.ibm.com > wrote:

    I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.

            ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’).

    How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights?


    -
    Jason Keirstead
    STSM, Product Architect, Security Intelligence, IBM Security Systems
    www.ibm.com/security

    "Things may come to those who wait, but only the things left by those who hustle." - Unknown





    From:         Chet Ensign < chet.ensign@oasis-open.org >
    To:         Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org >
    Cc:         OASIS CTI TC Discussion List < cti@lists.oasis-open.org >
    Date:         01/09/2018 03:59 PM
    Subject:         Re: [cti] EUROPE adopts STIX and TAXII
    Sent by:         < cti@lists.oasis-open.org >






    Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018! 

    Good work! 

    /chet

    On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org >
    wrote:
    Dear Members of the CTI TC,

    I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement.


    Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1515520575463&uri=CELEX:32017D2288

    Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.*

    I am delighted that your excellent work has received such high level recognition.

    Dr Carol Cosgrove-Sacks
    Senior Advisor on International Standards Policy
    OASIS
     
    *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands,
    Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom;
    EFTA: Iceland, Liechtenstein, Norway and Switzerland.)

    --




    --

    /chet 
    ----------------
    Chet Ensign
    Director of Standards Development and TC Administration 
    OASIS: Advancing open standards for the information society
    http://www.oasis-open.org

    Primary: +1 973-996-2298
    Mobile: +1 201-341-1393  











  • 7.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-09-2018 20:42




    Carol – thanks for sharing this!
     
    All – we should be extremely proud of this recognition of our collective work in the CTI TC.  One of the primary reasons I advocated within DHS for the transition of STIX and TAXII to a formal standards body was to enable exactly this sort
    of ruling so I am extremely gratified to see this come to pass.
     
    This will only help accelerate the adoption and usage of STIX and TAXII globally, ensuring that the hard work we are doing within the TC has relevance for many years to come.
     
    Congratulations everyone!
     
    Rich
     
     
    Richard J. Struse
     
    Chair, OASIS Cyber Threat Intelligence Technical Committee
    Chief Strategist for Cyber Threat Intelligence
    The MITRE Corporation
    +1-703-983-7049 (office)
    +1-703-342-8368 (mobile)
     
     

    From: <cti@lists.oasis-open.org> on behalf of Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org>
    Date: Tuesday, January 9, 2018 at 3:35 PM
    To: Jason Keirstead <Jason.Keirstead@ca.ibm.com>
    Cc: OASIS CTI TC Discussion List <cti@lists.oasis-open.org>, Chet Ensign <chet.ensign@oasis-open.org>
    Subject: Re: [cti] EUROPE adopts STIX and TAXII


     


    Hello. 

    I can confirm that the recognition covers subsequent versions.  The Decision was taken based on the version that was available at the start of the process.


    Hoping this reassures you.


    Well done! 


    Carol 



     

    On 9 Jan 2018 9:16 p.m., "Jason Keirstead" < Jason.Keirstead@ca.ibm.com > wrote:

    I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.

            ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’).

    How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights?


    -
    Jason Keirstead
    STSM, Product Architect, Security Intelligence, IBM Security Systems
    www.ibm.com/security

    "Things may come to those who wait, but only the things left by those who hustle." - Unknown





    From:         Chet Ensign < chet.ensign@oasis-open.org >
    To:         Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org >
    Cc:         OASIS CTI TC Discussion List < cti@lists.oasis-open.org >
    Date:         01/09/2018 03:59 PM
    Subject:         Re: [cti] EUROPE adopts STIX and TAXII
    Sent by:         < cti@lists.oasis-open.org >






    Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018! 

    Good work! 

    /chet

    On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org >
    wrote:
    Dear Members of the CTI TC,

    I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement.


    Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1515520575463&uri=CELEX:32017D2288

    Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.*

    I am delighted that your excellent work has received such high level recognition.

    Dr Carol Cosgrove-Sacks
    Senior Advisor on International Standards Policy
    OASIS
     
    *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands,
    Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom;
    EFTA: Iceland, Liechtenstein, Norway and Switzerland.)

    --




    --

    /chet 
    ----------------
    Chet Ensign
    Director of Standards Development and TC Administration 
    OASIS: Advancing open standards for the information society
    http://www.oasis-open.org

    Primary: +1 973-996-2298
    Mobile: +1 201-341-1393  











  • 8.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-09-2018 23:01
      |   view attached
    Hi guys.  Congrats.  This EU approval process is a fairly formal and long-lead-time drill.  Also, nominations come only from EU member-state public administrations, not us.   Carol and I assist with that process somewhat, but it's ultimately sent to the Commission itself, via several review processes (including a panel on which Carol serves).  We can look into whether a re-review (or some other appropriate pointer) would be appropriate for v2.    Cordially  Jamie PS attached is the simple PDF/EN version, FWIW. James Bryce Clark, General Counsel OASIS: Advancing open standards for the information society https://www.oasis-open.org/staff www.twitter.com/JamieXML OASIS+FIRST.org Borderless Cyber Prague Dec 2017:  j.mp/praguecybersec EU Commission Rolling Plan for Open ICT Standards:  j.mp/EUstds2017 Cybersecurity standards at RSAc 2017:  j.mp/OASIS2017RSA On Tue, Jan 9, 2018 at 12:16 PM, Jason Keirstead < Jason.Keirstead@ca.ibm.com > wrote: I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.         ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’). How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights? - Jason Keirstead STSM, Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security "Things may come to those who wait, but only the things left by those who hustle." - Unknown From:         Chet Ensign < chet.ensign@oasis-open.org > To:         Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis- open.org > Cc:         OASIS CTI TC Discussion List < cti@lists.oasis-open.org > Date:         01/09/2018 03:59 PM Subject:         Re: [cti] EUROPE adopts STIX and TAXII Sent by:         < cti@lists.oasis-open.org > Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018!  Good work!  /chet On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis- open.org > wrote: Dear Members of the CTI TC, I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement. Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa. eu/legal-content/EN/TXT/?qid= 1515520575463&uri=CELEX: 32017D2288 Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.* I am delighted that your excellent work has received such high level recognition. Dr Carol Cosgrove-Sacks Senior Advisor on International Standards Policy OASIS   *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom; EFTA: Iceland, Liechtenstein, Norway and Switzerland.) -- -- /chet  ---------------- Chet Ensign Director of Standards Development and TC Administration  OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393   Attachment: CELEX_32017D2288_EN_TXT.pdf Description: Adobe PDF document

    Attachment(s)

    pdf
    CELEX_32017D2288_EN_TXT.pdf   375 KB 1 version


  • 9.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-09-2018 23:05




    Thanks Jamie. 
     
    Understanding what this means with respect to public procurements of the latest versions of STIX/TAXII will be helpful.  In the meantime, we’re all thrilled about this decision on the part of the EU!
     
    Thanks,
    Rich
     

    From: Jamie Clark <jamie.clark@oasis-open.org>
    Date: Tuesday, January 9, 2018 at 6:02 PM
    To: Jason Keirstead <Jason.Keirstead@ca.ibm.com>, Trey Darley <trey@newcontext.com>, OASIS CTI TC Discussion List <cti@lists.oasis-open.org>
    Cc: Chet Ensign <chet.ensign@oasis-open.org>, Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org>, Richard Struse <rjs@mitre.org>
    Subject: Re: [cti] EUROPE adopts STIX and TAXII


     




        Hi guys.  Congrats.  This EU approval process is a fairly formal and long-lead-time drill.  Also, nominations come only from EU member-state public administrations, not us.   Carol and I assist with that process somewhat, but it's ultimately
    sent to the Commission itself, via several review processes (including a panel on which Carol serves).  We can look into whether a re-review (or some other appropriate pointer) would be appropriate for v2.


       Cordially  Jamie

    PS attached is the simple PDF/EN version, FWIW.














    James Bryce Clark, General Counsel
    OASIS: Advancing open standards for the information society
    https://www.oasis-open.org/staff

    www.twitter.com/JamieXML


    OASIS+FIRST.org Borderless Cyber Prague Dec 2017: 
    j.mp/praguecybersec
    EU Commission Rolling Plan for Open ICT Standards: 
    j.mp/EUstds2017
    Cybersecurity standards at RSAc 2017: 
    j.mp/OASIS2017RSA










     

    On Tue, Jan 9, 2018 at 12:16 PM, Jason Keirstead < Jason.Keirstead@ca.ibm.com > wrote:

    I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.

            ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’).

    How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights?


    -
    Jason Keirstead
    STSM, Product Architect, Security Intelligence, IBM Security Systems
    www.ibm.com/security

    "Things may come to those who wait, but only the things left by those who hustle." - Unknown





    From:         Chet Ensign < chet.ensign@oasis-open.org >
    To:         Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org >
    Cc:         OASIS CTI TC Discussion List < cti@lists.oasis-open.org >
    Date:         01/09/2018 03:59 PM
    Subject:         Re: [cti] EUROPE adopts STIX and TAXII
    Sent by:         < cti@lists.oasis-open.org >








    Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018! 

    Good work! 

    /chet

    On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org >
    wrote:
    Dear Members of the CTI TC,

    I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement.


    Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1515520575463&uri=CELEX:32017D2288

    Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.*

    I am delighted that your excellent work has received such high level recognition.

    Dr Carol Cosgrove-Sacks
    Senior Advisor on International Standards Policy
    OASIS
     
    *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands,
    Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom;
    EFTA: Iceland, Liechtenstein, Norway and Switzerland.)

    --




    --

    /chet 
    ----------------
    Chet Ensign
    Director of Standards Development and TC Administration 
    OASIS: Advancing open standards for the information society
    http://www.oasis-open.org

    Primary: +1 973-996-2298
    Mobile: +1 201-341-1393  






     







  • 10.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-10-2018 12:02
    Jason, This occurred because those platforms were introduced at their inception into the ETSI Technical Committee on Cyber Security (TC CYBER) via the OASIS-ETSI MoU.  TC CYBER took several steps.  It included the platforms within a Technical Report on structured information sharing.  See TR 103331.  It then explicitly included the platforms in a published Technical Report that the platforms are essential to the EU implementation of the Network Information Security (NIS) Directive.  See TR 103456.   This was an especially significant step because of ETSI's formal relationship with the EU.  Within the EU governance system, ETSI enjoys special status somewhat unique special status as (along with CEN/CENELEC) the designated standards body for sector standards among EU Member countries. It also published the specifications within two other published works (TR 103303 on critical infrastructure protection and TR103303, the Global Cyber Security Ecosystem encyclopedic work, worked jointly with ENISA to make a similar recommendation.  Lastly, it also highlighted the platforms at the annual ETSI Security Week workshops over the past three years which include representatives from the EC and most EU Members.   The work also continues.  At the next plenary meeting in February, TR 103333 is being updated to include the latest OASIS CTI specification developments. All the documents are publicly, freely available and well-versioned with persistent identifiers at ETSI's document site.  See https://portal.etsi.org/webapp/WorkProgram/SimpleSearch/QueryForm.asp The portal for all technical committee groups, including the massive ensemble of 3GPP which develops the world's mobile communication standards, and for NFV, among others, is at https://portal.etsi.org/ --tony (ETSI-OASIS liaison, work item rapporteur, and ENISA expert at work) On 09-Jan-18 3:16 PM, Jason Keirstead wrote: I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.         ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’). How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights? - Jason Keirstead STSM, Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security Things may come to those who wait, but only the things left by those who hustle. - Unknown From:         Chet Ensign <chet.ensign@oasis-open.org> To:         Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org> Cc:         OASIS CTI TC Discussion List <cti@lists.oasis-open.org> Date:         01/09/2018 03:59 PM Subject:         Re: [cti] EUROPE adopts STIX and TAXII Sent by:         <cti@lists.oasis-open.org> Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018!  Good work!  /chet On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org > wrote: Dear Members of the CTI TC, I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement. Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1515520575463&uri=CELEX:32017D2288 Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.* I am delighted that your excellent work has received such high level recognition. Dr Carol Cosgrove-Sacks Senior Advisor on International Standards Policy OASIS   *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom; EFTA: Iceland, Liechtenstein, Norway and Switzerland.) -- -- /chet  ---------------- Chet Ensign Director of Standards Development and TC Administration  OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393 


  • 11.  RE: [cti] EUROPE adopts STIX and TAXII

    Posted 01-11-2018 00:01
    Dear all,   The listing was based on Regulation (EU) No. 1025/2012 on European standardisation ( http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2012:316:0012:0033:EN:PDF ) that lays down in its Article 13 the procedure for the identification of ICT technical specifications which are not issued by European, international or national standardisation organisations but that still could be referenced in public procurement acts by public authorities, provided that these ICT specifications comply with the requirements set by Annex II of the Regulation. The process was supported by Freddy/EclecticIQ, Trey/NewContext and myself to cover the part of external expert consultation … of course we have governance procedures for this in EU as well ,-) This does not make use of STIX/TAXI as feature or using products being compliant to it mandatory but is the first step as it is now on the list of eligible features/supported spec to be evaluated as a decisive feature/functionality. First and important step to open an eco system.   In addition to what Tony contributed form the ETSI perspective the I took similar steps within European standardization work (mandated by council and parliament) within Cyber Security Focus Group (see https://www.cencenelec.eu/standards/sectors/defencesecurityprivacy/security/pages/cybersecurity.aspx ) and upcoming CEN/CENELEC TC 13 which is about strategic advisory on where/how to standardize in close cooperation with ENISA. Also keeping relation and exchange with ETSI but working based on a EU mandate. If STIX/TAXI would be already “accredited” by eligible national or international standard organization like NIST or ISO we could easily have it transferred into a matching European standard as we did already with some of the ISO standards on e.g. IT forensics. But actually as STIX/TAXI is more about protocol and structured language it still would have to be evaluated if it makes sense to lift it in this level of standardization or rather produce a more generic standard which could be met then by utilizing STIX/TAXI.   Happy to elaborate further p2p or provide an overview on the European standardization landscape when possibly meeting f2f during RSA Conference in SF.   Cheers from Germany, Joerg       From: cti@lists.oasis-open.org [mailto:cti@lists.oasis-open.org] On Behalf Of Tony Rutkowski Sent: Wednesday, January 10, 2018 13:02 To: Jason Keirstead <Jason.Keirstead@ca.ibm.com>; Chet Ensign <chet.ensign@oasis-open.org> Cc: Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org>; OASIS CTI TC Discussion List <cti@lists.oasis-open.org> Subject: Re: [cti] EUROPE adopts STIX and TAXII   Jason, This occurred because those platforms were introduced at their inception into the ETSI Technical Committee on Cyber Security (TC CYBER) via the OASIS-ETSI MoU.  TC CYBER took several steps.  It included the platforms within a Technical Report on structured information sharing.  See TR 103331.  It then explicitly included the platforms in a published Technical Report that the platforms are essential to the EU implementation of the Network Information Security (NIS) Directive.  See TR 103456.   This was an especially significant step because of ETSI's formal relationship with the EU.  Within the EU governance system, ETSI enjoys special status somewhat unique special status as (along with CEN/CENELEC) the designated standards body for sector standards among EU Member countries. It also published the specifications within two other published works (TR 103303 on critical infrastructure protection and TR103303, the Global Cyber Security Ecosystem encyclopedic work, worked jointly with ENISA to make a similar recommendation.  Lastly, it also highlighted the platforms at the annual ETSI Security Week workshops over the past three years which include representatives from the EC and most EU Members.   The work also continues.  At the next plenary meeting in February, TR 103333 is being updated to include the latest OASIS CTI specification developments. All the documents are publicly, freely available and well-versioned with persistent identifiers at ETSI's document site.  See https://portal.etsi.org/webapp/WorkProgram/SimpleSearch/QueryForm.asp The portal for all technical committee groups, including the massive ensemble of 3GPP which develops the world's mobile communication standards, and for NFV, among others, is at https://portal.etsi.org/ --tony (ETSI-OASIS liaison, work item rapporteur, and ENISA expert at work)   On 09-Jan-18 3:16 PM, Jason Keirstead wrote: I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.         ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’). How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights? - Jason Keirstead STSM, Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security "Things may come to those who wait, but only the things left by those who hustle." - Unknown From:         Chet Ensign <chet.ensign@oasis-open.org> To:         Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org> Cc:         OASIS CTI TC Discussion List <cti@lists.oasis-open.org> Date:         01/09/2018 03:59 PM Subject:         Re: [cti] EUROPE adopts STIX and TAXII Sent by:         <cti@lists.oasis-open.org> Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018!  Good work!  /chet On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org > wrote: Dear Members of the CTI TC, I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement. Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1515520575463&uri=CELEX:32017D2288 Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.* I am delighted that your excellent work has received such high level recognition. Dr Carol Cosgrove-Sacks Senior Advisor on International Standards Policy OASIS   *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom; EFTA: Iceland, Liechtenstein, Norway and Switzerland.) -- -- /chet  ---------------- Chet Ensign Director of Standards Development and TC Administration  OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393   


  • 12.  RE: [cti] EUROPE adopts STIX and TAXII

    Posted 01-11-2018 00:01
    Dear all,   The listing was based on Regulation (EU) No. 1025/2012 on European standardisation ( http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=OJ:L:2012:316:0012:0033:EN:PDF ) that lays down in its Article 13 the procedure for the identification of ICT technical specifications which are not issued by European, international or national standardisation organisations but that still could be referenced in public procurement acts by public authorities, provided that these ICT specifications comply with the requirements set by Annex II of the Regulation. The process was supported by Freddy/EclecticIQ, Trey/NewContext and myself to cover the part of external expert consultation … of course we have governance procedures for this in EU as well ,-) This does not make use of STIX/TAXI as feature or using products being compliant to it mandatory but is the first step as it is now on the list of eligible features/supported spec to be evaluated as a decisive feature/functionality. First and important step to open an eco system.   In addition to what Tony contributed form the ETSI perspective the I took similar steps within European standardization work (mandated by council and parliament) within Cyber Security Focus Group (see https://www.cencenelec.eu/standards/sectors/defencesecurityprivacy/security/pages/cybersecurity.aspx ) and upcoming CEN/CENELEC TC 13 which is about strategic advisory on where/how to standardize in close cooperation with ENISA. Also keeping relation and exchange with ETSI but working based on a EU mandate. If STIX/TAXI would be already “accredited” by eligible national or international standard organization like NIST or ISO we could easily have it transferred into a matching European standard as we did already with some of the ISO standards on e.g. IT forensics. But actually as STIX/TAXI is more about protocol and structured language it still would have to be evaluated if it makes sense to lift it in this level of standardization or rather produce a more generic standard which could be met then by utilizing STIX/TAXI.   Happy to elaborate further p2p or provide an overview on the European standardization landscape when possibly meeting f2f during RSA Conference in SF.   Cheers from Germany, Joerg       From: cti@lists.oasis-open.org [mailto:cti@lists.oasis-open.org] On Behalf Of Tony Rutkowski Sent: Wednesday, January 10, 2018 13:02 To: Jason Keirstead <Jason.Keirstead@ca.ibm.com>; Chet Ensign <chet.ensign@oasis-open.org> Cc: Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org>; OASIS CTI TC Discussion List <cti@lists.oasis-open.org> Subject: Re: [cti] EUROPE adopts STIX and TAXII   Jason, This occurred because those platforms were introduced at their inception into the ETSI Technical Committee on Cyber Security (TC CYBER) via the OASIS-ETSI MoU.  TC CYBER took several steps.  It included the platforms within a Technical Report on structured information sharing.  See TR 103331.  It then explicitly included the platforms in a published Technical Report that the platforms are essential to the EU implementation of the Network Information Security (NIS) Directive.  See TR 103456.   This was an especially significant step because of ETSI's formal relationship with the EU.  Within the EU governance system, ETSI enjoys special status somewhat unique special status as (along with CEN/CENELEC) the designated standards body for sector standards among EU Member countries. It also published the specifications within two other published works (TR 103303 on critical infrastructure protection and TR103303, the Global Cyber Security Ecosystem encyclopedic work, worked jointly with ENISA to make a similar recommendation.  Lastly, it also highlighted the platforms at the annual ETSI Security Week workshops over the past three years which include representatives from the EC and most EU Members.   The work also continues.  At the next plenary meeting in February, TR 103333 is being updated to include the latest OASIS CTI specification developments. All the documents are publicly, freely available and well-versioned with persistent identifiers at ETSI's document site.  See https://portal.etsi.org/webapp/WorkProgram/SimpleSearch/QueryForm.asp The portal for all technical committee groups, including the massive ensemble of 3GPP which develops the world's mobile communication standards, and for NFV, among others, is at https://portal.etsi.org/ --tony (ETSI-OASIS liaison, work item rapporteur, and ENISA expert at work)   On 09-Jan-18 3:16 PM, Jason Keirstead wrote: I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.         ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’). How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights? - Jason Keirstead STSM, Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security "Things may come to those who wait, but only the things left by those who hustle." - Unknown From:         Chet Ensign <chet.ensign@oasis-open.org> To:         Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org> Cc:         OASIS CTI TC Discussion List <cti@lists.oasis-open.org> Date:         01/09/2018 03:59 PM Subject:         Re: [cti] EUROPE adopts STIX and TAXII Sent by:         <cti@lists.oasis-open.org> Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018!  Good work!  /chet On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org > wrote: Dear Members of the CTI TC, I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement. Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1515520575463&uri=CELEX:32017D2288 Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.* I am delighted that your excellent work has received such high level recognition. Dr Carol Cosgrove-Sacks Senior Advisor on International Standards Policy OASIS   *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom; EFTA: Iceland, Liechtenstein, Norway and Switzerland.) -- -- /chet  ---------------- Chet Ensign Director of Standards Development and TC Administration  OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393   


  • 13.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-11-2018 18:19




    Tony,
     
    Thank you for your work to advance CTI and STIX/TAXII within ETSI and the larger community!
     
    Regards,
    Rich
     
     
    Richard J. Struse
     
    Chair, OASIS Cyber Threat Intelligence Technical Committee
    Chief Strategist for Cyber Threat Intelligence
    The MITRE Corporation
    +1-703-983-7049 (office)
    +1-703-342-8368 (mobile)
     
     

    From: <cti@lists.oasis-open.org> on behalf of Tony Rutkowski <tony@yaanatech.co.uk>
    Organization: Yaana Limited
    Reply-To: "tony@yaanatech.co.uk" <tony@yaanatech.co.uk>
    Date: Wednesday, January 10, 2018 at 7:02 AM
    To: Jason Keirstead <Jason.Keirstead@ca.ibm.com>, Chet Ensign <chet.ensign@oasis-open.org>
    Cc: Carol Cosgrove-Sacks <carol.cosgrove-sacks@oasis-open.org>, OASIS CTI TC Discussion List <cti@lists.oasis-open.org>
    Subject: Re: [cti] EUROPE adopts STIX and TAXII


     

    Jason,
    This occurred because those platforms were introduced at their inception into the ETSI Technical Committee on Cyber Security (TC CYBER) via the OASIS-ETSI MoU.  TC CYBER took several steps.  It included the platforms within a Technical Report on structured
    information sharing.  See TR 103331.  It then explicitly included the platforms in a published Technical Report that the platforms are essential to the EU implementation of the Network Information Security (NIS) Directive.  See TR 103456.   This was an especially
    significant step because of ETSI's formal relationship with the EU.  Within the EU governance system, ETSI enjoys special status somewhat unique special status as (along with CEN/CENELEC) the designated standards body for sector standards among EU Member countries.

    It also published the specifications within two other published works (TR 103303 on critical infrastructure protection and TR103303, the Global Cyber Security Ecosystem encyclopedic work, worked jointly with ENISA to make a similar recommendation.  Lastly,
    it also highlighted the platforms at the annual ETSI Security Week workshops over the past three years which include representatives from the EC and most EU Members.   The work also continues.  At the next plenary meeting in February, TR 103333 is being updated
    to include the latest OASIS CTI specification developments.
    All the documents are publicly, freely available and well-versioned with persistent identifiers at ETSI's document site.  See
    https://portal.etsi.org/webapp/WorkProgram/SimpleSearch/QueryForm.asp
    The portal for all technical committee groups, including the massive ensemble of 3GPP which develops the world's mobile communication standards, and for NFV, among others, is at
    https://portal.etsi.org/
    --tony (ETSI-OASIS liaison, work item rapporteur, and ENISA expert at work)
     

    On 09-Jan-18 3:16 PM, Jason Keirstead wrote:


    I don't know anything at all about this process - but I noticed it specifically mentions the STIX 1.2 and TAXII 1.1 versions.

            ‘Structured Threat Information _expression_’ (‘STIX 1.2’) and ‘Trusted Automated Exchange of Indicator Information’ (‘TAXII 1.1’) developed by the Organization for the Advancement of Structured Information Standards (‘OASIS’).

    How would we get STIX 2.0 and TAXII 2.0 added to this? Anyone have any ideas? Or does it matter? Anyone have insights?


    -
    Jason Keirstead
    STSM, Product Architect, Security Intelligence, IBM Security Systems
    www.ibm.com/security

    "Things may come to those who wait, but only the things left by those who hustle." - Unknown





    From:         Chet Ensign
    <chet.ensign@oasis-open.org>
    To:         Carol Cosgrove-Sacks
    <carol.cosgrove-sacks@oasis-open.org>
    Cc:         OASIS CTI TC Discussion List
    <cti@lists.oasis-open.org>
    Date:         01/09/2018 03:59 PM
    Subject:         Re: [cti] EUROPE adopts STIX and TAXII
    Sent by:         <cti@lists.oasis-open.org>






    Let me add my congratulations folks. You've worked hard these past years. Seeing you get this recognition is a great start to 2018! 

    Good work! 

    /chet

    On Tue, Jan 9, 2018 at 2:56 PM, Carol Cosgrove-Sacks < carol.cosgrove-sacks@oasis-open.org >
    wrote:
    Dear Members of the CTI TC,

    I have just been informed  that the EU has made a formal Decision to recognize the use of STIX 1.2 and TAXII 1.1 for use in public procurement.


    Please see Commission Implementing Decision (EU) 2017/2288 of 11 December 2017:   http://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1515520575463&uri=CELEX:32017D2288

    Congratulations!  This Decision covers all 28 EU countries and is also applied by the 4 EFTA countries.*

    I am delighted that your excellent work has received such high level recognition.

    Dr Carol Cosgrove-Sacks
    Senior Advisor on International Standards Policy
    OASIS
     
    *(EU: Austria, Belgium,  Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland,  France, Germany, Greece, Hungary, Ireland,  Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands,
    Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden and United Kingdom;
    EFTA: Iceland, Liechtenstein, Norway and Switzerland.)

    --




    --

    /chet 
    ----------------
    Chet Ensign
    Director of Standards Development and TC Administration 
    OASIS: Advancing open standards for the information society
    http://www.oasis-open.org

    Primary: +1 973-996-2298
    Mobile: +1 201-341-1393 












  • 14.  Re: [cti] EUROPE adopts STIX and TAXII

    Posted 01-10-2018 12:36
    Jason et al., OASIS CTI and its critically important platforms are formally recognized within the European system and around the world.  ITU-T SG17 even has a new work item on use cases being advanced by Korea. Unfortunately, it appears as if the U.S. Federal Government seems not only to omit recognition, but is utterly oblivious.  See https://www.ntia.doc.gov/files/ntia/publications/eo_13800_botnet_report_for_public_comment.pdf The embarrassing obliviousness and utter lack of knowledge evidenced in this report goes far beyond just OASIS and CTI.  Some remedial cybersecurity tutorials seem needed, starting with being aware of the Global Cyber Security Ecosystem. http://www.etsi.org/deliver/etsi_tr/103300_103399/103306/01.02.01_60/tr_103306v010201p.pdf --tony