Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ITU Feedback #322

Closed
9 tasks done
ejratl opened this issue Mar 29, 2024 · 4 comments
Closed
9 tasks done

ITU Feedback #322

ejratl opened this issue Mar 29, 2024 · 4 comments

Comments

@ejratl
Copy link
Contributor

ejratl commented Mar 29, 2024

Review and accept/reject alterations that were requested by the ITU as described in the draft document.

  • Reference STIX Best Practices Guidelines
  • Remove references to government documents
  • Remove FireEye references
  • Remove links to Github, including links to cti-stix2-json-schemas
  • Remove reference to Lockheed Martin Kill Chain
  • Remove language considered pejorative
  • Remove references to STIX 2.0
  • Remove references to Casey documents
  • Remove ANTLR Grammar
@ejratl
Copy link
Contributor Author

ejratl commented Mar 29, 2024

There is a request to remove the following:
This section including vocabulary items and their descriptions is based on the Threat Agent Library publication from Intel Corp in September 2007 <<Casey_2007>>.
This gives credit for the prior art in the field - if we remove the credit, do we need to also remove some of the vocabulary items?

@ejratl
Copy link
Contributor Author

ejratl commented Mar 29, 2024

There is a request to remove the following:
If objects are found where this property is not present, the implicit value for all STIX Objects other than SCOs is [stixliteral]#2.0#.
This damages the understandability of parsing an object, so it should go into the Best Practices document as a note.

@ejratl
Copy link
Contributor Author

ejratl commented Mar 29, 2024

Rather than removing the informative statement that actor types are not mutually exclusive, I would like to adapt it to change the types:
-Actor types are not mutually exclusive: a threat actor can be both a disgruntled insider and a spy. <<Casey_2007>>
+Actor types are not mutually exclusive: a threat actor can be both a disgruntled insider and a sensationalist.

@ejratl
Copy link
Contributor Author

ejratl commented Mar 29, 2024

The PR includes the feedback referenced at the beginning of the document. A full scan of the document is still needed to look for other changes - for example, IANA Considerations was renamed to Considerations - do we want to make this change as well?

@ejratl ejratl closed this as completed in d17c434 Apr 12, 2024
ejratl added a commit that referenced this issue Apr 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant