Hi Duncan, Thanks for your comments … Although "playbooks" is certainly worthy of discussion, we may want to start with the plain old COA work associated with getting the openc2 json up to snuff utilizing stix 2.0. I'm not even sure where to find the current openc2 stix json. There was a private repo (
https://github.com/OpenC2-org/subgroup-stix ) that was deprecated when we went to the new public repo structure. Once we find what we have, I suspect it needs updating with both openc2 changes and with stix2.0 [JV]: Completely agree that the OpenC2 STIX JSON should be the first order work to be done. We have an earlier version of the COA that needs to be updated based on the latest OpenC2 JSON along with the new Cyber Observables from STIX 2.0. There is a google doc here with the ongoing changes. Thanks, Jyoti Technical Leader Office of the CTO, Security Business Group, Cisco Systems From: <
cti@lists.oasis-open.org > on behalf of "
duncan@sfractal.com " <
duncan@sfractal.com > Date: Tuesday, February 28, 2017 at 1:56 PM To: "
cti@lists.oasis-open.org " <
cti@lists.oasis-open.org > Subject: RE: [cti] liaison group for OpenC2 I would also be interested in joining. How does a "formal liaison group" work? What I could find on oasis website (
https://www.oasis-open.org/policies-guidelines/liaison ) is on liaisons between oasis and other groups. Am I correct in assuming this 'formal liaison group' to be between the CTI TC and the openc2 TC? I'm guessing we can't be 'formal' until openc2 has had it's first oasis meeting but I presume we could informally do it until that point. Although "playbooks" is certainly worthy of discussion, we may want to start with the plain old COA work associated with getting the openc2 json up to snuff utilizing stix 2.0. I'm not even sure where to find the current openc2 stix json. There was a private repo (
https://github.com/OpenC2-org/subgroup-stix ) that was deprecated when we went to the new public repo structure. Once we find what we have, I suspect it needs updating with both openc2 changes and with stix2.0. Duncan Sparrell sFractal Consulting LLC iPhone, iTypo, iApologize
Original Message -------- Subject: Re: [cti] liaison group for OpenC2 From: JG on CTI-TC < jg@ctin.us > Date: Tue, February 28, 2017 3:35 pm To: cti@lists.oasis-open.org Jyoti: I will be interested in participating, too. Jane Ginn, MSIA, MRP Secretary, CTI TC (928) 399-0509 On 2/28/2017 12:26 PM, Jyoti Verma (jyoverma) wrote: Hi All, OpenC2 has had a STIX COA working sub-group that has been working on the representation of OpenC2 in the STIX COA and other related topics. The subgroup has representatives from OASIS as well as OpenC2. As OpenC2 moves into OASIS, it would make sense for members of this group to act as a liaison in OASIS for OpenC2 and deal with the intersection topics between STIX/Cybox/TAXII and OpenC2. Towards this I would like to propose the creation of a formal liaison group. One of the first topics this group could deal with is the Playbook. I know this has been discussed in the past but within this group it could get a head-start. Bret Jordan, Allan Thomson, Joseph Brule and some other members of OpenC2 have expressed interest in such a liaison group. If others agree with this proposal, we could take it through the formalities. Thanks, Jyoti Technical Leader Office of the CTO, Security Business Group, Cisco Systems -- Jane Ginn, MSIA, MRP CTI-TC Co-Secretary Cyber Threat Intelligence Network, Inc. jg@ctin.us --------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC that generates this mail. Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php