OASIS Common Security Advisory Framework (CSAF) TC

 View Only
  • 1.  Promote the OASIS CSAF v2.0 Press Release

    Posted 05-20-2025 11:42
    Hello CSAF TC Members,
    The press release announcing CSAF v2.0's approval as ISO/IEC 20153 has been published. You can read it [here] on the OASIS website. 

    As TC members, your support is invaluable in raising awareness and encouraging broader participation. We kindly ask that you help us amplify the announcement by sharing these links across your networks:
    Congratulations on achieving this milestone and thank you for your continued commitment to advancing CSAF!

    -Mary Beth



    --

    Mary Beth Minto

    Content Manager

    OASIS Open

       

    marybeth.minto@oasis-open.org
    www.oasis-open.org


  • 2.  RE: Promote the OASIS CSAF v2.0 Press Release

    Posted 05-20-2025 11:57
    Congrats to all and a big thank you to the OASIS staff members that supported us along the way.

    --
    Thomas Schmidt




  • 3.  RE: Promote the OASIS CSAF v2.0 Press Release

    Posted 05-20-2025 12:24
    Group,

    Did we drop the concept of having the ISO/IEC variant being freely available? The version pointed to by the press release appears to still be paywalled.

    Denny


    On May 20, 2025, at 08:57, Thomas Schmidt via OASIS <Mail@mail.groups.oasis-open.org> wrote:







  • 4.  RE: Promote the OASIS CSAF v2.0 Press Release

    Posted 05-20-2025 12:41
    Denny, we did renew and JTC 1 acknowledged our application to JTC 1 to have a freely available copy posted -- after asking for it in the initial submission when sent to them, as we always do.  All of our past requests to do so for our PAS submissions have been honored:  the principal criteria is that OASIS offers the document online for free, which of course we do.  But JTC 1 have added a number of forms, format requirements and procedural steps over time.  It now apparently requires an internal caucus or vote process, which they have committed to us should be done by early June. 

    In terms of finding the document:  Even when this request is granted, the result has been that there is a separate source of links to the document for free access, on a distinct ISO/IEC page.  The "official" landing page for the spec, under their banner, always has continued to offer the document for sale to anyone for Swiss Francs.  This is perhaps understandable when you recall that the sale of copies of their specifications is a key source of revenue for ISO, IEC, and their respective national bodies.   Kind regards  Jamie






  • 5.  RE: Promote the OASIS CSAF v2.0 Press Release

    Posted 05-20-2025 12:45
    Hi,

    On Tue, May 20, 2025, at 18:40, James Bryce Clark via OASIS wrote:
    > Denny, we did renew and JTC 1 acknowledged our application to JTC 1 to have a freely available copy posted -- after asking for it in the initial submission when sent to them, as we always do. All of our past requests to do so for our PAS submissions have been honored: the principal criteria is that OASIS offers the document online for free, which of course we do. But JTC 1 have added a number of forms, format requirements and procedural steps over time. It now apparently requires an internal caucus or vote process, which they have committed to us should be done by early June.
    >
    > In terms of finding the document: Even when this request is granted, the result has been that there is a separate source of links to the document for free access, on a distinct ISO/IEC page. The "official" landing page for the spec, under their banner, always has continued to offer the document for sale to anyone for Swiss Francs. This is perhaps understandable when you recall that the sale of copies of their specifications is a key source of revenue for ISO, IEC, and their respective national bodies. Kind regards Jamie
    >
    >
    > James Bryce Clark
    >
    > General Counsel & CPO
    >
    > OASIS Open [...]
    > -------------------------------------------
    > Original Message:
    > Sent: 5/20/2025 12:24:00 PM
    > From: Denny Page
    > Subject: RE: Promote the OASIS CSAF v2.0 Press Release
    >
    > Group,
    >
    > Did we drop the concept of having the ISO/IEC variant being freely available? The version pointed to by the press release appears to still be paywalled.
    >
    > Denny
    >
    > [...] note: initial message citation was lost in OASIS mail transport systems.

    The ISO page of publicly free available standards is:

    https://standards.iso.org/ittf/PubliclyAvailableStandards/

    Best,
    Stefan.




  • 6.  RE: Promote the OASIS CSAF v2.0 Press Release

    Posted 05-20-2025 13:48

    Thomas could not have said it any better. Congrats and thank you to all!

    - Justin



    ------------------------------
    Justin Murphy
    US DHS Cybersecurity and Infrastructure Security Agency (CISA)
    Williston VT
    ------------------------------