
From david.oliva@verizon.net  Tue Jun  5 07:04:21 2012
Return-Path: <david.oliva@verizon.net>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A6DD21F8683 for <sacm@ietfa.amsl.com>; Tue,  5 Jun 2012 07:04:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.37
X-Spam-Level: *
X-Spam-Status: No, score=1.37 tagged_above=-999 required=5 tests=[BAYES_40=-0.185, HTML_MESSAGE=0.001, HTML_MIME_NO_HTML_TAG=0.097, MIME_HTML_ONLY=1.457]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OC89EIeJ0nOa for <sacm@ietfa.amsl.com>; Tue,  5 Jun 2012 07:04:20 -0700 (PDT)
Received: from vms173005pub.verizon.net (vms173005pub.verizon.net [206.46.173.5]) by ietfa.amsl.com (Postfix) with ESMTP id CFEB321F86C6 for <sacm@ietf.org>; Tue,  5 Jun 2012 07:04:19 -0700 (PDT)
Received: from vznit170132pub.verizon.net ([unknown] [192.168.1.3]) by vms173005.mailsrvcs.net (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009)) with ESMTPA id <0M5500453DQQ6KAB@vms173005.mailsrvcs.net> for sacm@ietf.org; Tue, 05 Jun 2012 09:04:04 -0500 (CDT)
Received: from 71.126.165.30 ([71.126.165.30]) by vznit170132 (Verizon Webmail) with HTTP; Tue, 05 Jun 2012 09:04:02 -0500 (CDT)
Date: Tue, 05 Jun 2012 09:04:02 -0500 (CDT)
From: david.oliva@verizon.net
To: david.waltermire@nist.gov, michael.hammer@yaanatech.com, Gunnar.Engelbach@ThreatGuard.com
Message-id: <24531208.650886.1338905042749.JavaMail.root@vznit170132>
MIME-version: 1.0
Content-type: text/html; charset=UTF-8
Content-transfer-encoding: quoted-printable
X-Mailer: Verizon Webmail
X-Originating-IP: [71.126.165.30]
Cc: SCAP-DEV@nist.gov, sacm@ietf.org
Subject: Re: [sacm] [scap-dev] Request for participants - Content Repository Specification Development
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Jun 2012 14:04:21 -0000

<div style=3D"FONT-FAMILY: Arial; COLOR: #000000; FONT-SIZE: 12px"><DIV>&nb=
sp;</DIV><DIV>&nbsp;I think that the hub idea may be needed at the beginnin=
g.&nbsp; The rationale is probably that standardization cannot be achieved =
without one.&nbsp; However, after some level of performance is achieved the=
 effort can be decentralized.&nbsp; The management can be perhaps rotated t=
o reduce/share the burden.&nbsp; The rotated management approach may give t=
he participants a better feel for what works in the best&nbsp;interest of s=
tandardization and all particpating parties.</DIV><DIV></DIV><DIV>&nbsp;</D=
IV><DIV>David Oliva</DIV><DIV>&nbsp;</DIV><DIV style=3D"MARGIN: 5px 0px; BO=
RDER-TOP: #bcbcbc 1px solid"></DIV><SPAN style=3D"FONT-FAMILY: arial; COLOR=
: #000000; FONT-SIZE: 12px">On 05/21/12, <SPAN>Waltermire, David A.&lt;davi=
d.waltermire@nist.gov&gt;</SPAN> wrote:</SPAN><DIV>&nbsp;</DIV><DIV style=
=3D"FONT-FAMILY: arial; COLOR: #000000; FONT-SIZE: 12px">The centralized st=
ar is interesting, but I am not sure we want to get into the management con=
cerns around who would maintain the "hub". My preference has been for loose=
 federation with distributed management of the nodes.<BR><BR>Any other thou=
ghts?<BR><BR>Sincerely,<BR>Dave<BR><BR><BR>-----Original Message-----<BR>Fr=
om: Michael Hammer [<A class=3DparsedLink href=3D"mailto:michael.hammer@yaa=
natech.com" target=3D_blank>mailto:michael.hammer@yaanatech.com</A>]<BR>Sen=
t: Monday, May 21, 2012 1:18 PM<BR>To: Waltermire, David A.; <A class=3Dpar=
sedEmail href=3D"mailto:Gunnar.Engelbach@ThreatGuard.com" target=3D_blank>G=
unnar.Engelbach@ThreatGuard.com</A><BR>Cc: SCAP-DEV; <A class=3DparsedEmail=
 href=3D"mailto:sacm@ietf.org" target=3D_blank>sacm@ietf.org</A><BR>Subject=
: RE: [sacm] [scap-dev] Request for participants - Content Repository Speci=
fication Development<BR><BR>It would be possible for centralized star, with=
 reciprocal subscriptions.<BR>Sources publish, and central devise broadcast=
s to subscribers.<BR>Filters could also be applied.<BR><BR>Guess it depends=
 on whether you want a pull or push model.<BR>May depend on how often you s=
ee data needing to be transferred.<BR>And whether an intra-poll delay is ac=
ceptable or not.<BR><BR>Mike<BR><BR><BR>-----Original Message-----<BR>From:=
 Waltermire, David A. [<A class=3DparsedLink href=3D"mailto:david.waltermir=
e@nist.gov" target=3D_blank>mailto:david.waltermire@nist.gov</A>]<BR>Sent: =
Monday, May 21, 2012 1:09 PM<BR>To: Michael Hammer; <A class=3DparsedEmail =
href=3D"mailto:Gunnar.Engelbach@ThreatGuard.com" target=3D_blank>Gunnar.Eng=
elbach@ThreatGuard.com</A><BR>Cc: SCAP-DEV; <A class=3DparsedEmail href=3D"=
mailto:sacm@ietf.org" target=3D_blank>sacm@ietf.org</A><BR>Subject: RE: [sa=
cm] [scap-dev] Request for participants - Content Repository<BR>Specificati=
on Development<BR><BR>That is also an option. It could be supported in addi=
tion to a polling<BR>method also. The challenge with pub-sub is that conten=
t servers would need<BR>to register with other content servers to make this=
 work. The DNS model<BR>doesn't require any prior knowledge on behalf of th=
e content servers and it<BR>is essentially stateless. A pub-sub model would=
 require a lot of state<BR>tracking.<BR><BR>Sincerely,<BR>Dave<BR><BR><BR>-=
----Original Message-----<BR>From: Michael Hammer [<A class=3DparsedLink hr=
ef=3D"mailto:michael.hammer@yaanatech.com" target=3D_blank>mailto:michael.h=
ammer@yaanatech.com</A>]<BR>Sent: Monday, May 21, 2012 12:59 PM<BR>To: Walt=
ermire, David A.; <A class=3DparsedEmail href=3D"mailto:Gunnar.Engelbach@Th=
reatGuard.com" target=3D_blank>Gunnar.Engelbach@ThreatGuard.com</A><BR>Cc: =
SCAP-DEV; <A class=3DparsedEmail href=3D"mailto:sacm@ietf.org" target=3D_bl=
ank>sacm@ietf.org</A><BR>Subject: RE: [sacm] [scap-dev] Request for partici=
pants - Content Repository<BR>Specification Development<BR><BR>Rather than =
having a lot of polling, could you use a Subscribe-Notify type<BR>of framew=
ork, where notices of new information or updates get distributed?<BR><BR>Po=
lling seems like it could get chatty, and raises the question of how<BR>oft=
en.<BR><BR>Mike<BR><BR><BR>-----Original Message-----<BR>From: <A class=3Dp=
arsedEmail href=3D"mailto:sacm-bounces@ietf.org" target=3D_blank>sacm-bounc=
es@ietf.org</A> [<A class=3DparsedLink href=3D"mailto:sacm-bounces@ietf.org=
" target=3D_blank>mailto:sacm-bounces@ietf.org</A>] On Behalf Of<BR>Walterm=
ire, David A.<BR>Sent: Monday, May 21, 2012 10:42 AM<BR>To: Gunnar Engelbac=
h<BR>Cc: SCAP-DEV; <A class=3DparsedEmail href=3D"mailto:sacm@ietf.org" tar=
get=3D_blank>sacm@ietf.org</A><BR>Subject: Re: [sacm] [scap-dev] Request fo=
r participants - Content Repository<BR>Specification Development<BR><BR>Com=
ments inline marked [DAW].<BR><BR>Sincerely,<BR>Dave<BR><BR><BR>-----Origin=
al Message-----<BR>From: <A class=3DparsedEmail href=3D"mailto:sacm-bounces=
@ietf.org" target=3D_blank>sacm-bounces@ietf.org</A> [<A class=3DparsedLink=
 href=3D"mailto:sacm-bounces@ietf.org" target=3D_blank>mailto:sacm-bounces@=
ietf.org</A>] On Behalf Of<BR>Gunnar Engelbach<BR>Sent: Friday, May 18, 201=
2 1:04 PM<BR>Cc: SCAP-DEV; <A class=3DparsedEmail href=3D"mailto:sacm@ietf.=
org" target=3D_blank>sacm@ietf.org</A><BR>Subject: Re: [sacm] [scap-dev] Re=
quest for participants - Content Repository<BR>Specification Development<BR=
><BR><BR>Dave,<BR><BR>It sounds like you are trying to solve two separate p=
roblems here.<BR><BR>The first is the ability to retrieve content from a re=
pository, the second<BR>is the ability to locate repositories.<BR><BR>I'm n=
ot seeing enough of an overlap between these two sets to need to<BR>address=
 them in the same standard.<BR><BR>[DAW: We would be introducing significan=
t complexity into the client if we<BR>separate these concerns. By mirroring=
 the DNS approach for repository<BR>federation, we can keep things simple o=
n the client side. In my view, both<BR>of these operations would be handled=
 by the local content repository<BR>associated with the client. Just like i=
n DNS, the local content repository<BR>server will resolve the location of =
each content repository based on the<BR>content identifier namespace using =
the corresponding SRV record. It will<BR>then dispatch a request to these c=
ontent repositories to retrieve the<BR>content. It can optionally cache the=
 content and then provide it back to<BR>the client. This entire process is =
transparent to the client.<BR><BR>For example, a configuration scanning age=
nt is ordered by the scanning<BR>manager to perform a scan on a repeating i=
nterval using a set of content.<BR>The set of content required is a list of=
 OVAL definition IDs developed by a<BR>third party vendor hosted in the thi=
rd party vendor's content repository.<BR>The agent has been preconfigured t=
o point to the local content repository to<BR>which it sends a request to f=
or the content. The local repository looks up<BR>the namespace associated w=
ith the third party content IDs in DNS retrieving<BR>the SRV record for the=
 third party content repository. It dispatches a<BR>request for the content=
 to the third party repository and retrieves the<BR>content, caching it, an=
d providing it to the client.]<BR><BR>As far as modeling discovery on DNS, =
I'm not sold, but that could just be a<BR>lack of understanding on my part =
-- and I still haven't had time to read<BR>your draft spec.<BR><BR>[DAW: Wh=
at I am suggesting is not "discovery" per se, it is resolution using<BR>DNS=
 SRV records. This is the general purpose of the SRV mechanism.]<BR><BR>But=
 it sounds like a chicken-and-egg problem. In order to locate a<BR>reposito=
ry you first have to know something about the repository -- the<BR>publishe=
r's namespace URI from your example.<BR><BR>In my experience discovery is m=
ore likely to be based on search<BR>criteria: affected platform, guidance s=
ource, supported languages, content<BR>formats, regulation applicability (S=
OX, HIPAA, etc), and so on.<BR>That's more like a searchable registry -- I =
don't see where DNS-style name<BR>resolution comes into it.<BR><BR>[DAW: My=
 example pre-supposes that the content IDs have already been<BR>selected. M=
eaning that the organization performing the scan pre-selected<BR>content fr=
om the third party registry. This introduces a third problem that<BR>needs =
to be solved that is a discovery style problem. For the web, we have<BR>web=
-based search engines that index content from a variety of sources and<BR>t=
hen provide persistent pointers to the location of the content. We<BR>proba=
bly need something like this too, but that is a concept that more than<BR>l=
ikely needs to be addressed by one or more additional specifications.<BR><B=
R>Initially, organizations are going to seek content from sources that act =
as<BR>authorities for their organization or that are trusted. Discovery mat=
ters<BR>at the point where digital policy is constructed. In this scenario,=
 if a<BR>content repository supports simple standardized query capabilities=
, we<BR>probably have a workable solution for the short-term. In my example=
 above,<BR>the scanning manager is responsible for many different agents on=
 many<BR>different hosts. The system user would create scanning configurati=
ons based<BR>on content they have pre-selected and these configurations wou=
ld then get<BR>propagated to the individual scanners. The pre-selection cou=
ld be the<BR>result of querying a list of authoritative and trusted reposit=
ories. This<BR>usage pattern also applies to single host and agentless appr=
oaches.]<BR><BR>--gun<BR><BR><BR><BR>On 5/18/2012 8:42 AM, Waltermire, Davi=
d A. wrote:<BR>&gt; My comments marked with [DAW2].<BR>&gt;<BR>&gt; Sincere=
ly,<BR>&gt; Dave<BR>&gt;<BR>&gt;<BR>&gt; -----Original Message-----<BR>&gt;=
 From: Chandrashekhar B [<A class=3DparsedLink href=3D"mailto:bchandra@secp=
od.com" target=3D_blank>mailto:bchandra@secpod.com</A>]<BR>&gt; Sent: Frida=
y, May 18, 2012 1:50 AM<BR>&gt; To: Waltermire, David A.; 'Kurt Seifried'<B=
R>&gt; Cc: <A class=3DparsedEmail href=3D"mailto:sacm@ietf.org" target=3D_b=
lank>sacm@ietf.org</A>; SCAP-DEV<BR>&gt; Subject: RE: [sacm] [scap-dev] Req=
uest for participants - Content<BR>&gt; Repository Specification Developmen=
t<BR>&gt;<BR>&gt; My comments marked [CHA]<BR>&gt;<BR>&gt; Chandra.<BR>&gt;=
<BR>&gt; -----Original Message-----<BR>&gt; From: <A class=3DparsedEmail hr=
ef=3D"mailto:sacm-bounces@ietf.org" target=3D_blank>sacm-bounces@ietf.org</=
A> [<A class=3DparsedLink href=3D"mailto:sacm-bounces@ietf.org" target=3D_b=
lank>mailto:sacm-bounces@ietf.org</A>] On Behalf<BR>&gt; Of<BR>Waltermire, =
David A.<BR>&gt; Sent: Friday, May 18, 2012 8:02 AM<BR>&gt; To: Kurt Seifri=
ed<BR>&gt; Cc: <A class=3DparsedEmail href=3D"mailto:sacm@ietf.org" target=
=3D_blank>sacm@ietf.org</A><BR>&gt; Subject: Re: [sacm] [scap-dev] Request =
for participants - Content<BR>&gt; Repository Specification Development<BR>=
&gt;<BR>&gt; Comments inline marked [DAW].<BR>&gt;<BR>&gt; Sincerely,<BR>&g=
t; Dave<BR>&gt;<BR>&gt;<BR>&gt; -----Original Message-----<BR>&gt; From: Ku=
rt Seifried [<A class=3DparsedLink href=3D"mailto:kseifried@redhat.com" tar=
get=3D_blank>mailto:kseifried@redhat.com</A>]<BR>&gt; Sent: Thursday, May 1=
7, 2012 10:18 PM<BR>&gt; To: Waltermire, David A.<BR>&gt; Cc: <A class=3Dpa=
rsedEmail href=3D"mailto:sacm@ietf.org" target=3D_blank>sacm@ietf.org</A><B=
R>&gt; Subject: Re: [scap-dev] [sacm] Request for participants - Content<BR=
>&gt; Repository Specification Development<BR>&gt;<BR>&gt; -----BEGIN PGP S=
IGNED MESSAGE-----<BR>&gt; Hash: SHA1<BR>&gt;<BR>&gt; Note: all opinions/co=
mments are my own, not official Red Hat policy<BR>&gt; and so<BR>on.<BR>&gt=
;<BR>&gt; On 05/17/2012 07:19 PM, Waltermire, David A. wrote:<BR>&gt;&gt; K=
urt,<BR>&gt;&gt;<BR>&gt;&gt; My assumption is that each organization would =
stand up a content<BR>&gt;&gt; repository based on this specification for t=
heir own authoritative<BR>&gt;&gt; content, content they produce. They woul=
d sign the content using<BR>&gt;&gt; their own private key. I haven't worke=
d out an approach for public<BR>&gt;&gt; key distribution yet. It would be =
if we could use DNS or some other<BR>&gt;&gt; standardized key distribution=
 mechanism. I am open to ideas.<BR>&gt;<BR>&gt; Ah my bad I assumed you guy=
s were talking about the central repo<BR>&gt; (although<BR>at some point th=
ere has to be a head repo, right?). As far as keys go why<BR>recreate the w=
heel? Use X.509 and sign stuff, then key distribution is<BR>trivial (use th=
e system keys, allow import of a custom key, etc.). Plus this<BR>way you're=
 using well tested system libraries/etc. which are available by<BR>default =
(well on any sane OS).<BR>&gt;<BR>&gt; [DAW: I am assuming that there will =
be no central repo. From talking<BR>&gt; with<BR>content publishers, there =
are IP rights and other issues with this type of<BR>approach. I think the b=
etter solution is to support a distributed network<BR>of repositories. Some=
 organizations and consortiums may decide to stand up<BR>centralized repos =
for their own purposes. This should be allowed, but not<BR>required.<BR>&gt=
;<BR>&gt; [CHA: Yes, distributed network of repository, with may be a centr=
al<BR>&gt; registry. Even for a central registry, I feel we aren't there ye=
t.<BR>&gt; Central repository or a registry would mean getting into operati=
onal<BR>&gt; aspects, who'll own, manage, control etc., So, limiting it to<=
BR>&gt; organizational repositories and content providers repository is goo=
d<BR>&gt; in my view.]<BR>&gt;<BR>&gt; [DAW2: This is why I am advocating f=
or a federated system. With the<BR>&gt; right approach, we can avoid having=
 to stand up a single central<BR>&gt; registry and all the operational and =
logistical aspects involved.<BR>&gt; Using the DNS SRV approach below, DNS =
essentially becomes the<BR>&gt; registry. Using DNS, every organization tha=
t produces content is able<BR>&gt; to point to the authoritative content re=
positories that they use to<BR>&gt; host their content. They can create as =
many namespaces as needed, by<BR>&gt; using sub-domains within their own do=
main(s). A SRV record would be<BR>&gt; associated with each sub-domain in t=
his case.]<BR>&gt;<BR>&gt; As far as supporting repo resolution, I am recom=
mending a namespaced<BR>content identifier approach based on DNS names. Man=
y of the security<BR>automation identifiers have reverse DNS names incorpor=
ated into them. For<BR>those that done, simple DNS namespace qualification =
would provide the same<BR>effect. In either case, this info can be used to =
lookup the content<BR>repository that is authoritative for the content refe=
renced by the ID. This<BR>can be handled using a DNS SRV record (RFC2783). =
We would need to get an<BR>IANA allocation for this (RFC6335). This approac=
h avoids having to create a<BR>root server infrastructure for content repos=
itories.<BR>&gt;<BR>&gt; I'd like to hear other thoughts related to X.509.]=
<BR>&gt;<BR>&gt; [CHA: I am not sure if I understand the DNS resolution app=
roach here<BR>&gt; completely, will anyway pose a question. If one content =
repository<BR>&gt; were to host a content authored by someone else and the =
namespace<BR>&gt; wasn't modified, may be for IP reasons. DNS namespace qua=
lification<BR>&gt; would not work if I want to pick the content from this r=
epository<BR>&gt; instead of the original author. Not sure if I am making s=
ense :) ]<BR>&gt;<BR>&gt; [DAW2: I am modeling this approach after DNS. The=
re are authoritative<BR>content servers that originate content. The DNS SRV=
 records would be mapped<BR>to the DNS namespaces hosted by a given authori=
tative content server. This<BR>is an analog to domains hosted by an authori=
tative DNS server. Here is a<BR>basic communication flow:<BR>&gt;<BR>&gt; 1=
) Client: sends request for content by ID to local, organizational<BR>conte=
nt repository.<BR>&gt; 2) Organizational repository: retrieve the requested=
 content<BR>&gt; a) If the namespace is a local namespace, return the conte=
nt.<BR>&gt; b) If the namespace is a foreign namespace, check if the conten=
t is<BR>&gt; in<BR>the local cache.<BR>&gt; c) Lookup the DNS SRV record as=
sociated with the ID's namespace.<BR>&gt; d) Dispatch a request to the fore=
ign authoritative content<BR>&gt; repository<BR>based on the SRV record to =
retrieve the content<BR>&gt; e) Cache the retrieved content using the time-=
to-live (TTL) value<BR>provided by the remote server.<BR>&gt; 3) Organizati=
onal repository: respond to the client with the content<BR>&gt;<BR>&gt; Thi=
s approach allows content for a given namespace to be managed by a<BR>singl=
e authoritative content repository. If a third party is hosting<BR>content =
for another (e.g. repository-as-a-service), then the DNS SRV record<BR>for =
the content's ID namespace would point to the 3rd party hosted<BR>repositor=
y.<BR>&gt;<BR>&gt; Access to local cache can (and probably should) be limit=
ed to IPs<BR>&gt; within an organization or thru the use of access controls=
 to prevent<BR>&gt; leakage of cached content.]<BR>&gt;<BR>&gt;&gt; It may =
also make sense to allow for counter signing of content to<BR>&gt;&gt; allo=
w 3rd parties to sign content. Again, I have not worked out how<BR>&gt;&gt;=
 best to do this. Any ideas?<BR>&gt;<BR>&gt; Chained signatures would be re=
ally nice, e.g. Linux vendor releases an<BR>&gt; RPM<BR>with signed files, =
customer can then certify them and sign them, so if you<BR>allowed people t=
o simply sign data (so "sign1(data)") and in turn that to be<BR>signed (e.g=
. "sign2(sign1(data))") you could support any reasonably sane use<BR>case (=
e.g. we require the sysadmin to use a departmentally signed thing<BR>which =
in turn requires an org cert which requires a gov cert which requires<BR>to=
 vendor signature, etc.). I don't think the case of having multiple<BR>sign=
atures "At the same level" is significant, and can be fudged using<BR>signa=
ture chains.<BR>&gt;<BR>&gt; [DAW: agreed.]<BR>&gt;<BR>&gt;&gt; Related to =
restricting access to content, it is my hope that content<BR>&gt;&gt; is ma=
de freely available. For some kinds of content, it probably<BR>&gt;&gt; mak=
es sense to support some kind of access control. This could be<BR>&gt;&gt; =
driven by commercialization of content or to restrict access to some<BR>&gt=
;&gt; content to authorized users within an organization.<BR>&gt;&gt; Clien=
t/Server certificates might be a mechanism to support this.<BR>&gt;<BR>&gt;=
 I would classify content rights management as well beyond the scope of<BR>=
this project (you know have to basically build a CA type entity, handle cer=
t<BR>revocation for expired clients, etc, etc, etc.) and something to be le=
ft up<BR>to the end vendor/customer that actually wants this. Building in D=
RM is a<BR>huge amount of effort and I suspect it would mostly be wasted. A=
ny content<BR>management you build in will:<BR>&gt;<BR>&gt; 1) be incompati=
ble (and thus either removed, or an active problem) for<BR>&gt; many vendor=
s/customers (I doubt any existing system for selling<BR>&gt; content will e=
nd up being super compatible with what you guys build)<BR>&gt; 2) be unnece=
ssary in most (if not almost all) cases<BR>&gt; 3) add significantly to the=
 overhead of building this and not add any<BR>&gt; real value to the actual=
 problem space of securing machines<BR>&gt;<BR>&gt; For some idea of the sc=
ope of this type of problem check out<BR>&gt; <A class=3DparsedLink href=3D=
"http://www.candlepinproject.org/" target=3D_blank>http://www.candlepinproj=
ect.org/</A> which provides subscription and<BR>&gt; entitlement management=
. Even without reinventing the wheel, but just<BR>integrating with somethin=
g like candlepin would be a huge effort. I would<BR>say this problem is lef=
t to any vendors that want to put DRM on the<BR>content/etc.<BR>&gt;<BR>&gt=
; TLDR: Please, please don't do this, it'll be a huge time/effort sink<BR>&=
gt; and<BR>not worth it. Anyone that wants to sell this kind of thing alrea=
dy has<BR>systems capable of delivering files and managing access/rights to=
 them.<BR>&gt;<BR>&gt; [DAW: Points well taken. I am interested in other th=
oughts on how<BR>&gt; best to address this. What I was recommending was loo=
king more<BR>&gt; towards service authentication and less towards DRM. Mayb=
e we don't<BR>&gt; address this in the first pass. Thoughts?]<BR>&gt;<BR>&g=
t; [CHA: Access control is definitely a requirement for organizational<BR>c=
ontent server as well as content providers repository. Once the service is<=
BR>authenticated, it should be left to the implementers to define/implement=
<BR>their own access rights. Because, an entity communicating with the<BR>r=
epository will not see any difference in the behavior.<BR>&gt;<BR>&gt; In o=
ur repository, we have implemented a policy driven access control<BR>&gt; a=
nd<BR>the policy parameters are the attributes of SCAP metadata. But, someo=
ne else<BR>might choose an hierarchical database and define container level=
 access<BR>control.<BR>&gt;<BR>&gt; So, service authentication is required =
to be standardized. For access<BR>&gt; control, may be an error condition i=
f one is not allowed to fetch the<BR>&gt; content?]<BR>&gt;<BR>&gt; [DAW2: =
agreed. I see this as a minimal standardization approach.]<BR>&gt;<BR>&gt;&=
gt; I hope this answers your questions.<BR>&gt;&gt;<BR>&gt;&gt; Sincerely, =
Dave<BR>&gt;&gt;<BR>&gt;&gt;<BR>&gt;&gt; -----Original Message----- From: K=
urt Seifried<BR>&gt;&gt; [<A class=3DparsedLink href=3D"mailto:kseifried@re=
dhat.com" target=3D_blank>mailto:kseifried@redhat.com</A>] Sent: Thursday, =
May 17, 2012 9:11 PM<BR>&gt;&gt; To: Waltermire, David A. Subject: Re: [sca=
p-dev] [sacm] Request for<BR>&gt;&gt; participants - Content Repository Spe=
cification Development<BR>&gt;&gt;<BR>&gt;&gt; On 05/17/2012 04:44 PM, Walt=
ermire, David A. wrote:<BR>&gt;&gt;&gt; Good points. It makes sense to use =
the mechanisms provided by XML<BR>&gt;&gt;&gt; (e.g. XMLDsig, XML Encryptio=
n) and capabilities provided by the<BR>&gt;&gt;&gt; underlying transport (e=
.g. TLS) to address as much of this as<BR>&gt;&gt;&gt; possible. It may be =
desirable to provide mechanisms for<BR>&gt;&gt;&gt; authentication to restr=
ict access to content. This may also need to<BR>&gt;&gt;&gt; be integrated =
into the underlying transport.<BR>&gt;&gt; I have some questions, asking of=
f list, not sure if they are<BR>&gt;&gt; appropriate, if they are feel free=
 to reply on the list.<BR>&gt;&gt;<BR>&gt;&gt; 1) if using XMLDsig who woul=
d be the signing authority? How secure<BR>&gt;&gt; would signing be (e.g. u=
sing a hardware card/appliance/etc?).<BR>&gt;&gt; Where would the key be pu=
blished/would it be signed/etc? 2) You<BR>&gt;&gt; mention restricting acce=
ss to content, why would the content need to<BR>&gt;&gt; be restricted? Are=
 there IP issues I am unaware of?<BR>&gt;&gt;<BR>&gt;&gt; Thanks<BR>&gt;&gt=
;<BR>&gt;&gt;&gt; Sincerely, Dave<BR>&gt;&gt;<BR>&gt; - - --<BR>&gt; Kurt S=
eifried Red Hat Security Response Team (SRT)<BR>&gt; PGP: 0x5E267993 A90B F=
995 7350 148F 66BF 7554 160D 4553 5E26 7993<BR>&gt; -----BEGIN PGP SIGNATUR=
E-----<BR>&gt; Version: GnuPG v1.4.12 (GNU/Linux)<BR>&gt; Comment: Using Gn=
uPG with Mozilla - <A class=3DparsedLink href=3D"http://enigmail.mozdev.org=
/" target=3D_blank>http://enigmail.mozdev.org/</A><BR>&gt;<BR>&gt; iQIcBAEB=
AgAGBQJPtbFIAAoJEBYNRVNeJnmTuwsQANiygjm9i8AAjiwXMWb3K/RZ<BR>&gt; uIcqM+kbO1=
8cFIWce7p5njzcmRx2eeFFpmMfMTWPrfs7AMjSRjpGy9DNQ9wvlIyR<BR>&gt; GVgwpeWiIK3c=
ZJza3YFEhUfpng3Ivek3kp3nKDgTgm7wBATi0NrRMG6/QRPxxJnK<BR>&gt; MXPjON4aenqInI=
FxRGoDqplR7e6g6RXuaD4B376f+LC0R7j8lWUK4ug/GTkBPkXf<BR>&gt; LfDuY1Q4u9ctB+tX=
WQyCwRe4sQ2Gd+PXYzyDENa9kd3e5P/6LTWn3spZQvfEa0Ew<BR>&gt; xQj8YB5VbsyT39Gvtl=
JOV0cJ35HOZBGhwtqwa3vJ6xE3sWCNuJdWqvHr7T8A0Qus<BR>&gt; u4VO6Gc6S6Nrq6DbU9tn=
11jMoDwwP1wtqFx+l9bhhzSw5VNKVnkTq7/Q0fXd9Q2r<BR>&gt; GfPp0ZplyL4lRfhfglt/dK=
bGPOoiOhuFXKeJw9MVQRU0ZHRKxnpw+DeFoBCQXpUH<BR>&gt; TdHBg7gu37yB/dAxs63CZKlC=
1GDi8nXNZ4+myTDDsnqogzbkP61p3acoYFuunLGK<BR>&gt; +JMj0f3OktzZRFqylUbrqw/ONH=
O5zvZOjZp6pQAikG9Vvn89PsmuXHZvbNJRlaqi<BR>&gt; oiTDzeONz3yyvwjEYg5J1i11e+tz=
M6x248ulclh+82CwhKL9G1AotFIi803iXrbv<BR>&gt; XCldnHSPS6O7qeRTgMtL<BR>&gt; =
=3DQJsL<BR>&gt; -----END PGP SIGNATURE-----<BR>&gt; _______________________=
________________________<BR>&gt; sacm mailing list<BR>&gt; <A class=3Dparse=
dEmail href=3D"mailto:sacm@ietf.org" target=3D_blank>sacm@ietf.org</A><BR>&=
gt; <A class=3DparsedLink href=3D"https://www.ietf.org/mailman/listinfo/sac=
m" target=3D_blank>https://www.ietf.org/mailman/listinfo/sacm</A><BR>&gt;<B=
R>&gt; _______________________________________________<BR>&gt; sacm mailing=
 list<BR>&gt; <A class=3DparsedEmail href=3D"mailto:sacm@ietf.org" target=
=3D_blank>sacm@ietf.org</A><BR>&gt; <A class=3DparsedLink href=3D"https://w=
ww.ietf.org/mailman/listinfo/sacm" target=3D_blank>https://www.ietf.org/mai=
lman/listinfo/sacm</A><BR>_______________________________________________<B=
R>sacm mailing list<BR><A class=3DparsedEmail href=3D"mailto:sacm@ietf.org"=
 target=3D_blank>sacm@ietf.org</A><BR><A class=3DparsedLink href=3D"https:/=
/www.ietf.org/mailman/listinfo/sacm" target=3D_blank>https://www.ietf.org/m=
ailman/listinfo/sacm</A><BR>_______________________________________________=
<BR>sacm mailing list<BR><A class=3DparsedEmail href=3D"mailto:sacm@ietf.or=
g" target=3D_blank>sacm@ietf.org</A><BR><A class=3DparsedLink href=3D"https=
://www.ietf.org/mailman/listinfo/sacm" target=3D_blank>https://www.ietf.org=
/mailman/listinfo/sacm</A><BR>_____________________________________________=
__<BR>sacm mailing list<BR><A class=3DparsedEmail href=3D"mailto:sacm@ietf.=
org" target=3D_blank>sacm@ietf.org</A><BR><A class=3DparsedLink href=3D"htt=
ps://www.ietf.org/mailman/listinfo/sacm" target=3D_blank>https://www.ietf.o=
rg/mailman/listinfo/sacm</A><BR></DIV></div>

From bchandra@secpod.com  Thu Jun 14 13:10:16 2012
Return-Path: <bchandra@secpod.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E6C0521F877A for <sacm@ietfa.amsl.com>; Thu, 14 Jun 2012 13:10:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.242
X-Spam-Level: *
X-Spam-Status: No, score=1.242 tagged_above=-999 required=5 tests=[BAYES_50=0.001, HTML_MESSAGE=0.001, SARE_LWSHORTT=1.24]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EpN5SdIgBnFh for <sacm@ietfa.amsl.com>; Thu, 14 Jun 2012 13:10:05 -0700 (PDT)
Received: from cpanel23.interactivedns.com (cpanel23.interactivedns.com [184.173.122.2]) by ietfa.amsl.com (Postfix) with ESMTP id A9F4321F873A for <sacm@ietf.org>; Thu, 14 Jun 2012 13:10:04 -0700 (PDT)
Received: from [122.172.14.165] (port=27490 helo=hpPC) by cpanel23.interactivedns.com with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.77) (envelope-from <bchandra@secpod.com>) id 1SfGMi-0002Ps-Mk; Fri, 15 Jun 2012 01:40:03 +0530
From: "Chandrashekhar B" <bchandra@secpod.com>
To: "'Multiple recipients of list'" <scap-dev@nist.gov>, <sacm@ietf.org>
References: <15D0981C9BE53042A4C9D0F3D0B6826B2900F2@MSIS-GH1-UEA10.corp.nsa.gov> <CBD00675.32964%kent_landfield@mcafee.com>
In-Reply-To: <CBD00675.32964%kent_landfield@mcafee.com>
Date: Fri, 15 Jun 2012 01:39:54 +0530
Organization: SecPod Technologies
Message-ID: <00a801cd4a69$aba5be40$02f13ac0$@secpod.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_00A9_01CD4A97.C567E550"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQJt5r4nvn6Xg4466qYgTE+iSkxyIpW5BFnQ
Content-Language: en-us
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - cpanel23.interactivedns.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - secpod.com
X-Source: 
X-Source-Args: 
X-Source-Dir: 
Subject: Re: [sacm] Request for participants - Content Repository Specification Development
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: bchandra@secpod.com
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Jun 2012 20:10:17 -0000

This is a multipart message in MIME format.

------=_NextPart_000_00A9_01CD4A97.C567E550
Content-Type: text/plain;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

We have hosted our SCAP Content Repository at www.scaprepo.com. Feedback =
is
certainly appreciated. A simple web service interface will be published
soon.

=20

Chandra.

=20

From: scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of
Kent_Landfield@mcafee.com
Sent: Friday, May 11, 2012 10:14 PM
To: Multiple recipients of list
Subject: Request for participants - Content Repository Specification
Development

=20

Mike I love it when you tee something up like that.. ;-)  Thank you. ;)

=20

Mike wrote:=20

I still think that any specification for a repository is wishful =
thinking
until someone builds one and learns the lessons it will just be another
whitepaper spec.  I believe the DoD needs to incorporate a metadata
repository as part of it and other customizations that may not be useful =
for
everyone.

We need to talk more.

=20

If you are talking about a holistic, complete federated approach to a
content repository, I some what agree.  If you are talking about an
organizational repository, I totally disagree. But you knew I would. ;)

=20

Here is how I see the problem.  There is an immediate need for SCAP and
other related content to be served up inside an organization.  Today we =
have
situation where the standards allow us to provide sites the capability =
to
have a single SCAP implemented policy they call official for their
environment. Yes this is a rather simplistic since there are things such =
as
targeting specific platforms, specific operational use needs, but for =
now
lets agree SCAP is a massive improvement over the proprietary situations =
of
the past. While we have created this standard content so that sites can
implement their local site security once and then assure they are =
measuring
all appropriately targeted devices the same way, we have failed to =
support
the operational needs of the sites.  We have a situation where no two
vendors distribute content the same way.  This causes massive problems =
for
the administration staff when they need to incorporate a new SCAP =
enabled
product into their architecture.  They need to discover how the new =
product
supports distributing SCAP content to it's various components.  If they =
have
one product then they do this one and they are done.  If they have =
multiple
products they will have to figure out how to minimize the impact by
incorporating the update process for the new product into the existing =
SCAP
security content processes. Now when the inevitable happens and the site
staff needs to make a change to their security policy, they have to make =
the
modifications to the benchmark or checks or both and then distribute =
those
updates across their network.  For each SCAP enabled product they have =
in
place, they have doubled, tripled or more the work needed to make those
updates available.=20

=20

There is another content repository problem and that is the Federated
Content Distribution.  If you think global DNS you have a general frame =
of
reference.  The guidance authors need to be able to publish content in =
an
authoritative manner so their content is updated in a timely fashion.  =
This
is a much harder problem to solve if there is no local organizational
infrastructure to support it. ;)

=20

So here is what I am thinking.  We should consider addressing these as =
two
separate but integrated efforts.  I believe the Organizational Content
Repository is the more critical piece that is actually easier to =
address.
The Federated Content Distribution should be a subsequent effort =
integrating
/ augmenting the Organizational repository specification.=20

=20

Mike, to your point that we need someone to build one first. That has
happened already.  I have one as do other vendors but what we don't have =
is
the access specification.  Ours are focused on our specific product =
needs.
Additionally there is a company that has developed a commercial SCAP =
content
repository that will be announced later this month. I won't steal their
thunder but I was recently given a sneak peek at it and I must admit I =
was
very impressed.  Again, to your point, it has been done. What is needed =
to
address the initial operational problem is to develop a specification =
that
provides a consistent means for all SCAP products to retrieve the
appropriate content as configured and managed but the site. =20

=20

TO THAT END..

=20

I am requesting participation from those in the community that see the =
need
and want to put in the work to make this specification happen.  I have
talked to a couple of you but I do not want to assume your =
participation.
If you are interested please contact me so we can get this started.=20

=20

Thanks!

=20

Kent Landfield
Director Content Strategy, Architecture and Standards

McAfee | An Intel Company
5000 Headquarters Dr.
Plano, Texas 75024

Direct: +1.972.963.7096=20
Mobile: +1.817.637.8026
Web: www.mcafee.com <http://www.mcafee.com/>=20

=20

From: <Kinney>, Michael A <m.kinne@radium.ncsc.mil>
To: David Waltermire <david.waltermire@nist.gov>, SCAP-DEV
<SCAP-DEV@nist.gov>, "sacm@ietforg <mailto:sacm@ietf.org> " =
<sacm@ietf.org>
Subject: Re: [sacm] [OVAL-DEVELOPER-LIST] Security Automation Developer
Days: Summer 2012 at MITRE in Bedford, MA

=20

Dave,

I have no problem with webinars, I do want to keep developer days =
actionable
and use it to make decisions, and vote and accomplish things good or =
bad.  I
do not want this to be an informational briefing conference.

Thanks for the links.

=20

I still think that any specification for a repository is wishful =
thinking
until someone builds one and learns the lessons it will just be another
whitepaper spec.  I believe the DoD needs to incorporate a metadata
repository as part of it and other customizations that may not be useful =
for
everyone.

We need to talk more.

=20

-Mike =20

=20

From: Waltermire, David A. [mailto:david.waltermire@nist.gov]=20
Sent: Tuesday, May 08, 2012 10:44 AM
To: Kinney, Michael A; SCAP-DEV; sacm@ietf.org
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Mike,

=20

What about having webinars in-place of the 30 minute briefs?

=20

Regarding content management, we are building the prototype content
repository for use in a production environment.  As an open source =
project,
it will be free for use by anyone interested.  My thinking is that this
project can bridge the gap until commercial solutions are available to
augment it.  This is a similar path that was followed with DNS (bind) =
and
HTTP (apache).  When it is ready for use, I am hoping to use it to host
USGCB content.  You would be welcome to use it for your needs.

=20

It is good that OCIL is moving forward.  This is an important piece of
supporting risk management and aspects of continuous monitoring.  I =
would
also like to see some discussion on OCIL at Developer Days.  With the
proposals we will likely have a sense of what needs to be discussed and =
what
we can achieve consensus on outside the meeting.

=20

Remediation is a topic near and dear to my heart.  I too would like to =
see
it move forward.

=20

We just published the draft ASR specification for public comment.  This
specification supports enterprise aggregate reporting which greatly =
reduces
the data volumes needed verses detailed host-based reports. This
specification has been designed as a more robust replacement for LASR  =
It
can be used in continuous monitoring applications to support aggregate =
data
reporting needs (e.g. FISMA reporting,  CyberScope).

=20

Here are the links:

=20

http://csrc.nist.gov/publications/PubsDrafts.html

http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848

=20

The primary reason we have suggested waiting on XCCDF is not the
internationalization issue. Many vendors have commented that they are =
still
working on implementing the XCCDF 1.2.1 specification. We will be in a
better place in a few months once more development around XCCDF has
occurred.  As we consider changes to the SCAP stack to address OCIL and
other issues, we will identify areas that need improvement in XCCDF.  =
These
are good and necessary discussions to have now, but we have a good deal =
of
work to do before we are ready to open up XCCDF.  My suggestion is to =
work
on these related areas and then work up change proposals for XCCDF as
needed.  By that time we should be ready to work on a new revision of =
XCCDF.

=20

I am also looking forward to the discussions at the conference.  It has =
been
too long.

=20

Sincerely,

Dave

=20

From: Kinney, Michael A [mailto:m.kinne@radium.ncsc.mil
<mailto:m.kinne@radium.ncscmil> ]=20
Sent: Tuesday, May 08, 2012 7:09 AM
To: SCAP-DEV
Cc: Waltermire, David A.
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Kent,

=20

It's good to read your thoughts, and a realistic actionable approach is
indeed needed  Since all the activity hasn't been on the lists a brief =
1=AE2
hour recap may be in order to bring everyone up to speed since there has
been a lot of activity on CPE/SWID, OCIl, MAEC/CybOX CEE and others.

=20

We could write a content repository specification, but without someone
willing to stand one up it will be as valuable as the CCSS specification =
is
today.  I've been trying for two years to get my management to get a
coordinated effort together for the DoD to stand up a repository, it is =
a
tough problem and will require funding with a tail, I'm not sure a
specification will solve that problem.

=20

We (DoD) have been putting a lot of effort into OCIL over the last year
trying to make it useful in an enterprise environment and will be =
posting
our ideas to the list before developer days it should have already =
started,
we need to get consensus and a vote on how the community wishes to =
proceed.

=20

Remediation is stalled but I'm making every effort to get it kick =
started
from our perspective. I hope to assist in getting the draft ERI finished
this year.  We are writing some new STIG content and intend to used the
draft CRE specification to insert CRE into the content so we (DoD) can =
do
some automatic configuration fixes, part of a self healing network =
concept.
It is just a start but the best we can do at this point.

=20

Enterprise reporting is an interesting subject, since XML adds size to =
and
content to roll up reporting, in any enterprise of size the problem gets
greater, I look forward to your thoughts on that subject.

=20

I am concerned that the internationalization efforts are detracting from
efforts to meet use cases, we have some things we would like changed in
XCCDF to support our OCIl use case and I have been told that I need to =
wait.
I didn't think that a move to internationalization should impede efforts =
to
move forward with use cases.

=20

I look forward to talking with you at the conference.

=20

v/r

=20

Mike Kinney

Project Director

Computer Network Defense Research and Technology (CND R&T) Office

9800 Savage Road Ste 6767
Ft Meade, MD 20755-6767
Phone: 410-854-4422
NSTS: 968-8886
Fax 410-854-4681

 <mailto:M.kinne@radium.ncsc.mil> makinn2@nsa.gov

=20

=20

=20

From:scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of =
Waltermire,
David A.
Sent: Monday, May 07, 2012 7:09 PM
To: Multiple recipients of list
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Kent,

=20

I like what you are saying here.  We are also in support of this type of
approach.  We would like to see some community discussion around what =
are
the key areas/priorities that the community would like to see discussed =
at
Dev Days.  Your topics below look like a good start. The SACM list might =
be
a better venue than the OVAL list for this discussion.  For each area we
should focus the discussion around developing objectives for each =
session.
The sessions can be time boxed based on what would be a reasonable =
amount of
time to accomplish each objective.  For example if continuous monitoring =
is
a priority and collectively it takes 3 days to work through all the
objectives, I see no problem with that.  We can also keep a few sessions =
"on
deck" if all the objectives are reached and we complete all the =
scheduled
sessions early.

=20

Thoughts?

=20

Sincerely,

=20

David Waltermire

SCAP Architect

National Institute of Standards and Technology

(301) 975-3390

david.waltermire@nist.gov

=20

From:scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of
Kent_Landfield@mcafee.com
Sent: Monday, May 07, 2012 4:25 PM
To: SCAP-DEV
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

All,

=20

I would like to discuss the format for the SCAP Developer Days that =
seems to
be listed below.

=20

I see this appears to follow a path we have discussed in the past as the =
way
not to hold a Dev Days event.  We have been trying to get away from =
'Death
by Powerpoint' and back to the type of event we held years ago when we =
were
highly productive.  In the past we had a topic to be discussed and a =
time
box to work within.  That allowed us to have very active brainstorming
sessions in a high bandwidth environment.

=20

At past Summer events we have got into a pattern of lots of powerpoint, =
lots
of status of the efforts and very little discussion about things that =
need
active discussions.  We need to keep moving forward and making progress =
as
an effort. We can get status from various places such as the lists, a
presentation being sent out in advance, a webinar if it is felt there =
will
be questions and answers from those that are new to the efforts.  We =
have a
limited amount of time and all who are attending are investing a great =
deal
of time and money to be there.  We should not  be spending a great deal =
of
time reeducating everyone when we could be focused on advancing needed
efforts.

=20

The type of approach to a Dev Days event was discussed at the last =
Summer
Dev Days.  I have seen the following work quite well in other efforts.

1.	Presentations are sent out to the attendees and the lists a week in
advance
2.	Status for any effort is limited to 30 minutes
3.	Focused brainstorming time should be established for certain areas
that need real work by the community
4.	Efforts to be discussed should be based on needs of the security
automation space to move existing efforts to completion.

For example:

=20

Continuous monitoring is a major direction the efforts are becoming =
involved
with. There are going to be things we need to do as a security =
automation
community to be able to accomplish what is listed in the CAESARS FE.  =
There
are interfaces that need to be worked and established.  That is one area
that is not listed below.  CM will have a major impact on all of us in =
the
next couple years and it is being ignored.  We can't keep trying to =
solve
what has already been solved.  We need to address the needed interface
development now. This is an effort that could take nearly a whole day by
itself.

=20

Operationally we have a real need to be able to deliver SCAP content
internally within an organization. Today the SCAP vendors cannot share a
single local site security policy (XCCDF + OVAL + CPE +.) without the =
site
staff having to go to each of the individual products and figuring out =
how
to inject that new or updated policy into that products delivery =
mechanisms.
That is limiting sites from wanting to buy multiple focused SCAP =
products
since they are such a pain to manage from a content perspective.  It is
easier to buy from one vendor that has a single means for distributing
content than it is to deal with the management issues that having =
multiple
SCAP products presents.  We need to have at least an entire 1/2 a day on =
the
development of a Content Repository specification.

=20

OCIL is a positive and a negative at the same time. It has real value =
that
is being underutilized and under implemented because of the limitations =
of
how it addresses uses in an enterprise environment.  People don't need
security automation to do things on/for a single host.  They need =
security
automation to focus on the enterprise issues that reduce their costs and
improve their efficiencies.  OCIL is failing in the enterprise and we =
all
understand that.  We need to address developing a definitive solution =
for
incorporating OCIL into the enterprise and that means into the existing
specifications. Scheduling and tracking are key to it's success.  We =
need to
make that happen.  This too needs a focused brainstorming time box to
discuss options.

=20

I am really disappointed that Remediation is not on the list below.  =
Yes,
last Summer Dev Days, the time spent on Remediation was wasted time but =
that
does not mean we should ignore it and not try to make some real =
progress.
As far as I am concerned we need to reboot the remediation effort.  We
cannot keep being the set of specifications / tools that act as the =
little
boy crying "Wolf" in the night.  We need to be able to find and fix =
issues
if we are going to really make a difference in organizational security
postures.  But today we think it is too hard so we don't try ?  I think =
we
need a couple hours to discuss the reboot of the effort even if that =
means
minimizing work already done.

=20

A focused discussion on enterprise reporting is also critically needed.  =
For
the vendors here, we have all gone through the Cyberscope goat rope,
delivering limited capabilities to specific data call requirements of =
the
Federal Agencies.  The initial effort was a mess, did little more than =
prove
it was possible and cause the vendor community a great deal of thrashing =
to
put a kludgey 'solution' in place.  Reality is all our customers need =
roll
up reporting and an infrastructure that supports it.  A data call should =
not
be special to anyone other than the agencies responding. The tools =
should be
able to select the types of data needed and deliver that on a scheduled
basis automatically.    Enterprise Reporting pertains to commercial as =
well
as Federal customers.  We need to focus some time on what that would =
look
like using the ARF and ASR as the foundational pieces.  But there are
missing pieces..  We need this discussed.

=20

I would hope we can make this summer's SCAP Dev Days useful in advancing =
the
security automation efforts by addressing some of the more critical =
issues
our customers are facing now or will be facing in the very short term.
Status presentations are not interesting to those active in the efforts.
Let's try to do those before we get to Bedford so we can real make some
progress while we are all in the same room.  This is always a big event =
for
the 'consensus of the willing' that assemble and driven to see security
automation make a difference.  Let's see if we can have an event that, =
when
we all walk out the last day, we all feel that every minute was well =
spent
and moves us forward.

=20

Thanks.

=20

Kent Landfield
Director Content Strategy, Architecture and Standards

McAfee | An Intel Company
5000 Headquarters Dr.
Plano, Texas 75024

Direct: +1.972.963.7096=20
Mobile: +1.817.637.8026
Web: www.mcafee.com <http://www.mcafee.com/>=20

=20

From: <Boczenowski>, Steve <sboczeno@MITRE.ORG>
Reply-To: "OVAL Developer List (Closed Public Discussion)"
<OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG>
To: "OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG"
<OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG>
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Frank;

=20

We hope to have the registration site up next week.  The event will be
during the week of July 9 - starting Monday at 10:00 AM and ending on =
Friday
at 12:00.

=20

Meanwhile, we are working on the agenda and are currently considering =
this
list of topics:

=20

CCE

CPE/SWID

CEE

XCCDF

OVAL

ASR

Enterprise OCIL

CybOX/MAEC

Federated Content Repository Spec

Endpoint Reporting for Continuous Monitoring and Compliance (ERCC)

MILE

TAXII

IF-M for SCAP

IF-MAP

SCAP Releases

SCAP and IETF

NETCONF and SCAP

=20

Steve

=20

From: Frank Lindsay Acker [mailto:afrank@NOVA.EDU]=20
Sent: Tuesday, May 01, 2012 9:32 AM
To: oval-developer-list OVAL Developer List/Closed Public Discussion
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Steve....

Has there been any additional information regarding this event?

Thanks,
Frank Acker


  _____ =20


From: Boczenowski, Steve [sboczeno@MITRE.ORG]
Sent: Tuesday, March 20, 2012 16:38
To: OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG
Subject: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer
2012 at MITRE in Bedford, MA

Save the Date: week of July 9, 2012

=20

This year's MITRE-hosted Security Automation Developer Days event will =
be
held during the week of July 9, 2012 at MITRE's facility in Bedford, MA.

=20

Details to follow.

=20

Regards,

    Steve

=20

______________________________________________

Stephen P. Boczenowski

      The MITRE Corporation

      Office: (781) 271-7682

      Cell: (978) 302-3849

     sboczeno@mitre.org

=20

To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.=20

To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.=20

To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.=20


------=_NextPart_000_00A9_01CD4A97.C567E550
Content-Type: text/html;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Diso-8859-2">
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta name=3DGenerator =
content=3D"Microsoft Word 14 (filtered medium)"><!--[if =
!mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:MITRE;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.apple-style-span
	{mso-style-name:apple-style-span;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
p.msochpdefault, li.msochpdefault, div.msochpdefault
	{mso-style-name:msochpdefault;
	mso-style-priority:99;
	margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Calibri","sans-serif";}
span.emailstyle17
	{mso-style-name:emailstyle17;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.EmailStyle24
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle25
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle26
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle27
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle28
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle29
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:118182839;
	mso-list-template-ids:-776844468;}
@list l0:level1
	{mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level2
	{mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level4
	{mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level7
	{mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1
	{mso-list-id:1340959368;
	mso-list-template-ids:1487684132;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>We have hosted our SCAP Content Repository at <a =
href=3D"http://www.scaprepo.com">www.scaprepo.com</a>. Feedback is =
certainly appreciated. A simple web service interface will be published =
soon.<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'>Chandra.<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
scap-dev@nist.gov [mailto:scap-dev@nist.gov] <b>On Behalf Of =
</b>Kent_Landfield@mcafee.com<br><b>Sent:</b> Friday, May 11, 2012 10:14 =
PM<br><b>To:</b> Multiple recipients of list<br><b>Subject:</b> Request =
for participants - Content Repository Specification =
Development<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><div><div><p =
class=3DMsoNormal><span style=3D'color:black'>Mike I love it when you =
tee something up like that&#8230;. ;-) &nbsp;Thank you. =
;)<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Mike =
wrote:&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>I still think that any =
specification for a repository is wishful thinking until someone builds =
one and learns the lessons it will just be another whitepaper spec. =
&nbsp;I believe the DoD needs to incorporate a metadata repository as =
part of it and other customizations that may not be useful for =
everyone.</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>We need to talk =
more&#8230;</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>If you are talking about a =
holistic, complete federated approach to a content repository, I some =
what agree. &nbsp;If you are talking about an organizational repository, =
I totally disagree. But you knew I would. ;)</span><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>Here is how I see the =
problem. &nbsp;There is an immediate need for SCAP and other related =
content to be served up inside an organization. &nbsp;Today we have =
situation where the standards allow us to provide sites the capability =
to have a single SCAP implemented policy they call official for their =
environment. Yes this is a rather simplistic since there are things such =
as targeting specific platforms, specific operational use needs, but for =
now lets agree SCAP is a massive improvement over the proprietary =
situations of the past. While we have created this standard content so =
that sites can implement their local site security once and then assure =
they are measuring all appropriately targeted devices the same way, we =
have failed to support the operational needs of the sites. &nbsp;We have =
a situation where no two vendors distribute content the same way. =
&nbsp;This causes massive problems for the administration staff when =
they need to incorporate a new SCAP enabled product into their =
architecture. &nbsp;They need to discover how the new product supports =
distributing SCAP content to it's various components. &nbsp;If they have =
one product then they do this one and they are done. &nbsp;If they have =
multiple products they will have to figure out how to minimize the =
impact by incorporating the update process for the new product into the =
existing SCAP security content processes. Now when the inevitable =
happens and the site staff needs to make a change to their security =
policy, they have to make the modifications to the benchmark or checks =
or both and then distribute those updates across their network. =
&nbsp;For each SCAP enabled product they have in place, they have =
doubled, tripled or more the work needed to make those updates =
available.&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>There is another content =
repository problem and that is the Federated Content Distribution. =
&nbsp;If you think global DNS you have a general frame of reference. =
&nbsp;The guidance authors need to be able to publish content in an =
authoritative manner so their content is updated in a timely fashion. =
&nbsp;This is a much harder problem to solve if there is no local =
organizational infrastructure to support it. ;)<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>So here is what I am =
thinking&#8230; &nbsp;We should consider addressing these as two =
separate but integrated efforts. &nbsp;I believe the Organizational =
Content Repository is the more critical piece that is actually easier to =
address. &nbsp;The Federated Content Distribution should be a subsequent =
effort integrating / augmenting the Organizational repository =
specification.&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>Mike, to your point that =
we need someone to build one first&#8230; That has happened already. =
&nbsp;I have one as do other vendors but what we don&#8217;t have is the =
access specification. &nbsp;Ours are focused on our specific product =
needs. &nbsp;Additionally there is a company that has developed a =
commercial SCAP content repository that will be announced later this =
month. I won't steal their thunder but I was recently given a sneak peek =
at it and I must admit I was very impressed. &nbsp;Again, to your point, =
it has been done. What is needed to address the initial operational =
problem is to develop a specification that provides a consistent means =
for all SCAP products to retrieve the appropriate content as configured =
and managed but the site. &nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal =
style=3D'margin-bottom:1.0pt'><span style=3D'color:black'>TO THAT =
END&#8230;.<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:black'>I am requesting =
participation from those in the community that see the need and want to =
put in the work to make this specification happen. &nbsp;I have talked =
to a couple of you but I do not want to assume your participation. =
&nbsp;If you are interested please contact me so we can get this =
started.&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:black'>Thanks!<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p></div><div><div><p =
class=3DMsoNormal><strong><span =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'>=
Kent Landfield</span></strong><span =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'>=
<br><span class=3Dapple-style-span>Director Content Strategy, =
Architecture and Standards</span><br><br><strong><span =
style=3D'font-family:"Arial","sans-serif"'>McAfee | An Intel =
Company</span></strong><br><span class=3Dapple-style-span>5000 =
Headquarters Dr.</span><br><span class=3Dapple-style-span>Plano, Texas =
75024</span><br><br><span class=3Dapple-style-span>Direct: =
+1.972.963.7096&nbsp;</span><br><span class=3Dapple-style-span>Mobile: =
+1.817.637.8026</span><br><strong><span =
style=3D'font-family:"Arial","sans-serif"'>Web:&nbsp;</span></strong><spa=
n class=3Dapple-style-span><a =
href=3D"http://www.mcafee.com/">www.mcafee.com</a></span></span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div></div></div><div>=
<p class=3DMsoNormal><span =
style=3D'color:black'><o:p>&nbsp;</o:p></span></p></div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span style=3D'color:black'>From: =
</span></b><span style=3D'color:black'>&lt;Kinney&gt;, Michael A &lt;<a =
href=3D"mailto:m.kinne@radium.ncsc.mil">m.kinne@radium.ncsc.mil</a>&gt;<b=
r><b>To: </b>David Waltermire &lt;<a =
href=3D"mailto:david.waltermire@nist.gov">david.waltermire@nist.gov</a>&g=
t;, SCAP-DEV &lt;<a =
href=3D"mailto:SCAP-DEV@nist.gov">SCAP-DEV@nist.gov</a>&gt;, &quot;<a =
href=3D"mailto:sacm@ietf.org">sacm@ietforg</a>&quot; &lt;<a =
href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a>&gt;<br><b>Subject: =
</b>Re: [sacm] [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer 2012 at MITRE in Bedford, MA<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:black'><o:p>&nbsp;</o:p></span></p></div><blockquote=
 style=3D'border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in =
0in 4.0pt;margin-left:3.75pt;margin-right:0in' =
id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE"><div><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Dave,</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>I have no problem with webinars, I do want to =
keep developer days actionable and use it to make decisions, and vote =
and accomplish things good or bad.&nbsp; I do not want this to be an =
informational briefing conference.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Thanks for the links.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>I still think that any specification for a =
repository is wishful thinking until someone builds one and learns the =
lessons it will just be another whitepaper spec. &nbsp;I believe the DoD =
needs to incorporate a metadata repository as part of it and other =
customizations that may not be useful for everyone.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>We need to talk more&#8230;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>-Mike&nbsp; </span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
 Waltermire, David A. [<a =
href=3D"mailto:david.waltermire@nist.gov">mailto:david.waltermire@nist.go=
v</a>] <br><b>Sent:</b> Tuesday, May 08, 2012 10:44 AM<br><b>To:</b> =
Kinney, Michael A; SCAP-DEV; <a =
href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br><b>Subject:</b> RE: =
[OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2012 at =
MITRE in Bedford, MA</span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Mike,</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>What about having webinars in-place of the 30 =
minute briefs?</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Regarding content management, we are building =
the prototype content repository for use in a production =
environment.&nbsp; As an open source project, it will be free for use by =
anyone interested.&nbsp; My thinking is that this project can bridge the =
gap until commercial solutions are available to augment it.&nbsp; This =
is a similar path that was followed with DNS (bind) and HTTP =
(apache).&nbsp; When it is ready for use, I am hoping to use it to host =
USGCB content.&nbsp; You would be welcome to use it for your =
needs.</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>It is good that OCIL is moving forward.&nbsp; =
This is an important piece of supporting risk management and aspects of =
continuous monitoring.&nbsp; I would also like to see some discussion on =
OCIL at Developer Days.&nbsp; With the proposals we will likely have a =
sense of what needs to be discussed and what we can achieve consensus on =
outside the meeting.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Remediation is a topic near and dear to my =
heart.&nbsp; I too would like to see it move forward.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>We just published the draft ASR specification =
for public comment.&nbsp; This specification supports enterprise =
aggregate reporting which greatly reduces the data volumes needed verses =
detailed host-based reports. This specification has been designed as a =
more robust replacement for LASR&nbsp; It can be used in continuous =
monitoring applications to support aggregate data reporting needs (e.g. =
FISMA reporting, &nbsp;CyberScope).</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Here are the links:</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><a =
href=3D"http://csrc.nist.gov/publications/PubsDrafts.html">http://csrc.ni=
st.gov/publications/PubsDrafts.html</a></span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><a =
href=3D"http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848">=
http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848</a></span=
><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>The primary reason we have suggested waiting on =
XCCDF is not the internationalization issue. Many vendors have commented =
that they are still working on implementing the XCCDF 1.2.1 =
specification. We will be in a better place in a few months once more =
development around XCCDF has occurred.&nbsp; As we consider changes to =
the SCAP stack to address OCIL and other issues, we will identify areas =
that need improvement in XCCDF.&nbsp; These are good and necessary =
discussions to have now, but we have a good deal of work to do before we =
are ready to open up XCCDF.&nbsp; My suggestion is to work on these =
related areas and then work up change proposals for XCCDF as =
needed.&nbsp; By that time we should be ready to work on a new revision =
of XCCDF.</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>I am also looking forward to the discussions at =
the conference.&nbsp; It has been too long.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Sincerely,</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Dave</span><span =
style=3D'color:black'><o:p></o:p></span></p></div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
 Kinney, Michael A [<a =
href=3D"mailto:m.kinne@radium.ncscmil">mailto:m.kinne@radium.ncsc.mil</a>=
] <br><b>Sent:</b> Tuesday, May 08, 2012 7:09 AM<br><b>To:</b> =
SCAP-DEV<br><b>Cc:</b> Waltermire, David A.<br><b>Subject:</b> RE: =
[OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2012 at =
MITRE in Bedford, MA</span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Kent,</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>It&#8217;s good to read your thoughts, and a =
realistic actionable approach is indeed needed &nbsp;Since all the =
activity hasn&#8217;t been on the lists a brief 1=AE2 hour recap may be =
in order to bring everyone up to speed since there has been a lot of =
activity on CPE/SWID, OCIl, MAEC/CybOX CEE and others.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>We could write a content repository =
specification, but without someone willing to stand one up it will be as =
valuable as the CCSS specification is today. &nbsp;I&#8217;ve been =
trying for two years to get my management to get a coordinated effort =
together for the DoD to stand up a repository, it is a tough problem and =
will require funding with a tail, I&#8217;m not sure a specification =
will solve that problem.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>We (DoD) have been putting a lot of effort into =
OCIL over the last year trying to make it useful in an enterprise =
environment and will be posting our ideas to the list before developer =
days it should have already started, we need to get consensus and a vote =
on how the community wishes to proceed.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Remediation is stalled but I&#8217;m making =
every effort to get it kick started from our perspective. I hope to =
assist in getting the draft ERI finished this year. &nbsp;We are writing =
some new STIG content and intend to used the draft CRE specification to =
insert CRE into the content so we (DoD) can do some automatic =
configuration fixes, part of a self healing network concept. It is just =
a start but the best we can do at this point.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Enterprise reporting is an interesting subject, =
since XML adds size to and content to roll up reporting, in any =
enterprise of size the problem gets greater, I look forward to your =
thoughts on that subject.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>I am concerned that the internationalization =
efforts are detracting from efforts to meet use cases, we have some =
things we would like changed in XCCDF to support our OCIl use case and I =
have been told that I need to wait. I didn&#8217;t think that a move to =
internationalization should impede efforts to move forward with use =
cases.</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>I look forward to talking with you at the =
conference.</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>v/r</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>Mike Kinney</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>Project Director</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>Computer Network Defense Research and Technology (CND R&amp;T) =
Office</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>9800 Savage Road Ste 6767<br>Ft Meade, MD 20755-6767<br></span><span =
style=3D'font-size:10.0pt;color:#1F497D'>Phone: 410-854-4422<br>NSTS: =
968-8886<br>Fax 410-854-4681</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
><a href=3D"mailto:M.kinne@radium.ncsc.mil"><span =
style=3D'color:#660000'>makinn2@nsa.gov</span></a></span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
<a href=3D"mailto:scap-dev@nist.gov">scap-dev@nist.gov</a> <a =
href=3D"mailto:[mailto:scap-dev@nist.gov]">[mailto:scap-dev@nist.gov]</a>=
 <b>On Behalf Of </b>Waltermire, David A.<br><b>Sent:</b> Monday, May =
07, 2012 7:09 PM<br><b>To:</b> Multiple recipients of =
list<br><b>Subject:</b> RE: [OVAL-DEVELOPER-LIST] Security Automation =
Developer Days: Summer 2012 at MITRE in Bedford, MA</span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Kent,</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>I like what you are saying here.&nbsp; We are =
also in support of this type of approach.&nbsp; We would like to see =
some community discussion around what are the key areas/priorities that =
the community would like to see discussed at Dev Days.&nbsp; Your topics =
below look like a good start. The SACM list might be a better venue than =
the OVAL list for this discussion.&nbsp; For each area we should focus =
the discussion around developing objectives for each session.&nbsp; The =
sessions can be time boxed based on what would be a reasonable amount of =
time to accomplish each objective.&nbsp; For example if continuous =
monitoring is a priority and collectively it takes 3 days to work =
through all the objectives, I see no problem with that.&nbsp; We can =
also keep a few sessions &#8220;on deck&#8221; if all the objectives are =
reached and we complete all the scheduled sessions early.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Thoughts?</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Sincerely,</span><span =
style=3D'color:black'><o:p></o:p></span></p></div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>David =
Waltermire</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>SCAP =
Architect</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>National Institute of =
Standards and Technology</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>(301) 975-3390</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:black'><a =
href=3D"mailto:david.waltermire@nist.gov">david.waltermire@nist.gov</a><o=
:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
<a href=3D"mailto:scap-dev@nist.gov">scap-dev@nist.gov</a> <a =
href=3D"mailto:[mailto:scap-dev@nist.gov]">[mailto:scap-dev@nist.gov]</a>=
 <b>On Behalf Of </b><a =
href=3D"mailto:Kent_Landfield@mcafee.com">Kent_Landfield@mcafee.com</a><b=
r><b>Sent:</b> Monday, May 07, 2012 4:25 PM<br><b>To:</b> =
SCAP-DEV<br><b>Subject:</b> Re: [OVAL-DEVELOPER-LIST] Security =
Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><div><div><div><div><p =
class=3DMsoNormal><span =
style=3D'color:black'>All,<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>I would like to discuss =
the format for the SCAP Developer Days that seems to be listed =
below.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>I see this appears to =
follow a path we have discussed in the past as the way not to hold a Dev =
Days event. &nbsp;We have been trying to get away from 'Death by =
Powerpoint' and back to the type of event we held years ago when we were =
highly productive. &nbsp;In the past we had a topic to be discussed and =
a time box to work within. &nbsp;That allowed us to have very active =
brainstorming sessions in a high bandwidth =
environment.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>At past Summer events we =
have got into a pattern of lots of powerpoint, lots of status of the =
efforts and very little discussion about things that need active =
discussions. &nbsp;We need to keep moving forward and making progress as =
an effort. We can get status from various places such as the lists, a =
presentation being sent out in advance, a webinar if it is felt there =
will be questions and answers from those that are new to the efforts. =
&nbsp;We have a limited amount of time and all who are attending are =
investing a great deal of time and money to be there. &nbsp;We should =
not &nbsp;be spending a great deal of time reeducating everyone when we =
could be focused on advancing needed =
efforts.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>The type of approach to a =
Dev Days event was discussed at the last Summer Dev Days. &nbsp;I have =
seen the following work quite well in other =
efforts.<o:p></o:p></span></p></div><ol start=3D1 type=3D1><li =
class=3DMsoNormal =
style=3D'color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;m=
so-list:l0 level1 lfo3'>Presentations are sent out to the attendees and =
the lists a week in advance<o:p></o:p></li><li class=3DMsoNormal =
style=3D'color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;m=
so-list:l0 level1 lfo3'>Status for any effort is limited to 30 =
minutes<o:p></o:p></li><li class=3DMsoNormal =
style=3D'color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;m=
so-list:l0 level1 lfo3'>Focused brainstorming time should be established =
for certain areas that need real work by the =
community<o:p></o:p></li><li class=3DMsoNormal =
style=3D'color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;m=
so-list:l0 level1 lfo3'>Efforts to be discussed should be based on needs =
of the security automation space to move existing efforts to =
completion.<o:p></o:p></li></ol><div><p class=3DMsoNormal><span =
style=3D'color:black'>For example:<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>Continuous monitoring is a =
major direction the efforts are becoming involved with. There are going =
to be things we need to do as a security automation community to be able =
to accomplish what is listed in the CAESARS FE. &nbsp;There are =
interfaces that need to be worked and established. &nbsp;That is one =
area that is not listed below. &nbsp;CM will have a major impact on all =
of us in the next couple years and it is being ignored. &nbsp;We can't =
keep trying to solve what has already been solved. &nbsp;We need to =
address the needed interface development now. This is an effort that =
could take nearly a whole day by =
itself.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>Operationally we have a =
real need to be able to deliver SCAP content internally within an =
organization. Today the SCAP vendors cannot share a single local site =
security policy (XCCDF + OVAL + CPE +&#8230;) without the site staff =
having to go to each of the individual products and figuring out how to =
inject that new or updated policy into that products delivery =
mechanisms. &nbsp;That is limiting sites from wanting to buy multiple =
focused SCAP products since they are such a pain to manage from a =
content perspective. &nbsp;It is easier to buy from one vendor that has =
a single means for distributing content than it is to deal with the =
management issues that having multiple SCAP products presents. &nbsp;We =
need to have at least an entire 1/2 a day on the development of a =
Content Repository specification.<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>OCIL is a positive and a =
negative at the same time. It has real value that is being underutilized =
and under implemented because of the limitations of how it addresses =
uses in an enterprise environment. &nbsp;People don't need security =
automation to do things on/for a single host. &nbsp;They need security =
automation to focus on the enterprise issues that reduce their costs and =
improve their efficiencies. &nbsp;OCIL is failing in the enterprise and =
we all understand that. &nbsp;We need to address developing a definitive =
solution for incorporating OCIL into the enterprise and that means into =
the existing specifications. Scheduling and tracking are key to it's =
success. &nbsp;We need to make that happen. &nbsp;This too needs a =
focused brainstorming time box to discuss =
options.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>I am really disappointed =
that Remediation is not on the list below&#8230; &nbsp;Yes, last Summer =
Dev Days, the time spent on Remediation was wasted time but that does =
not mean we should ignore it and not try to make some real progress. =
&nbsp;As far as I am concerned we need to reboot the remediation effort. =
&nbsp;We cannot keep being the set of specifications / tools that act as =
the little boy crying &quot;Wolf&quot; in the night. &nbsp;We need to be =
able to find and fix issues if we are going to really make a difference =
in organizational security postures. &nbsp;But today we think it is too =
hard so we don't try ? &nbsp;I think we need a couple hours to discuss =
the reboot of the effort even if that means minimizing work already =
done.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>A focused discussion on =
enterprise reporting is also critically needed. &nbsp;For the vendors =
here, we have all gone through the Cyberscope goat rope, delivering =
limited capabilities to specific data call requirements of the Federal =
Agencies. &nbsp;The initial effort was a mess, did little more than =
prove it was possible and cause the vendor community a great deal of =
thrashing to put a kludgey 'solution' in place. &nbsp;Reality is all our =
customers need roll up reporting and an infrastructure that supports it. =
&nbsp;A data call should not be special to anyone other than the =
agencies responding. The tools should be able to select the types of =
data needed and deliver that on a scheduled basis automatically. &nbsp; =
&nbsp;Enterprise Reporting pertains to commercial as well as Federal =
customers. &nbsp;We need to focus some time on what that would look like =
using the ARF and ASR as the foundational pieces. &nbsp;But there are =
missing pieces&#8230;. &nbsp;We need this =
discussed.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span style=3D'color:black'>I would hope we can make =
this summer's SCAP Dev Days useful in advancing the security automation =
efforts by addressing some of the more critical issues our customers are =
facing now or will be facing in the very short term. &nbsp;Status =
presentations are not interesting to those active in the efforts. =
&nbsp;Let's try to do those before we get to Bedford so we can real make =
some progress while we are all in the same room. &nbsp;This is always a =
big event for the 'consensus of the willing' that assemble and driven to =
see security automation make a difference. &nbsp;Let's see if we can =
have an event that, when we all walk out the last day, we all feel that =
every minute was well spent and moves us =
forward.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'color:black'>Thanks.<o:p></o:p></span></p></div><div><p =
class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><div><p =
class=3DMsoNormal><strong><span =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'>=
Kent Landfield</span></strong><span =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'>=
<br><span class=3Dapple-style-span>Director Content Strategy, =
Architecture and Standards</span><br><br><strong><span =
style=3D'font-family:"Arial","sans-serif"'>McAfee | An Intel =
Company</span></strong><br><span class=3Dapple-style-span>5000 =
Headquarters Dr.</span><br><span class=3Dapple-style-span>Plano, Texas =
75024</span><br><br><span class=3Dapple-style-span>Direct: =
+1.972.963.7096&nbsp;</span><br><span class=3Dapple-style-span>Mobile: =
+1.817.637.8026</span><br><strong><span =
style=3D'font-family:"Arial","sans-serif"'>Web:&nbsp;</span></strong><spa=
n class=3Dapple-style-span><a =
href=3D"http://www.mcafee.com/">www.mcafee.com</a></span></span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div></div></div></div=
><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span style=3D'color:black'>From: =
</span></b><span style=3D'color:black'>&lt;Boczenowski&gt;, Steve &lt;<a =
href=3D"mailto:sboczeno@MITRE.ORG">sboczeno@MITRE.ORG</a>&gt;<br><b>Reply=
-To: </b>&quot;OVAL Developer List (Closed Public Discussion)&quot; =
&lt;<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@L=
ISTS.MITRE.ORG</a>&gt;<br><b>To: </b>&quot;<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@L=
ISTS.MITRE.ORG</a>&quot; &lt;<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@L=
ISTS.MITRE.ORG</a>&gt;<br><b>Subject: </b>Re: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:black'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p></div><blockquote =
style=3D'border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in =
4.0pt;margin-left:3.75pt;margin-top:5.0pt;margin-right:0in;margin-bottom:=
5.0pt' id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE"><div><div><p =
class=3DMsoNormal><span style=3D'color:#254061'>Frank;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#254061'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#254061'>We hope to have the registration site up next =
week.&nbsp; The event will be during the week of July 9 &#8211; starting =
Monday at 10:00 AM and ending on Friday at 12:00.</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#254061'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#254061'>Meanwhile, we are working on the agenda and are =
currently considering this list of topics:</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#254061'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'text-indent:.5in'><span style=3D'color:#254061'>CCE</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>CPE/SWID</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:#254061'>CEE</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>XCCDF</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>OVAL</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:#254061'>ASR</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:#254061'>Enterprise =
OCIL</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>CybOX/MAEC</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:#254061'>Federated =
Content Repository Spec</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:#254061'>Endpoint =
Reporting for Continuous Monitoring and Compliance (ERCC)</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>MILE</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>TAXII</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:#254061'>IF-M for =
SCAP</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>IF-MAP</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:#254061'>SCAP =
Releases</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>SCAP and IETF</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:#254061'>NETCONF and =
SCAP</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#254061'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#254061'>Steve</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#254061'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal style=3D'margin-left:2.0in'><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
 Frank Lindsay Acker [<a =
href=3D"mailto:afrank@NOVA.EDU">mailto:afrank@NOVA.EDU</a>] =
<br><b>Sent:</b> Tuesday, May 01, 2012 9:32 AM<br><b>To:</b> =
oval-developer-list OVAL Developer List/Closed Public =
Discussion<br><b>Subject:</b> Re: [OVAL-DEVELOPER-LIST] Security =
Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><div><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
Steve....<br><br>Has there been any additional information regarding =
this event?<br><br>Thanks,<br>Frank Acker</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><div =
style=3D'margin-left:.5in'><div class=3DMsoNormal align=3Dcenter =
style=3D'text-align:center'><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:black'><hr size=3D2 width=3D"100%" =
align=3Dcenter></span></div></div><div id=3DdivRpF955236><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:0in;margin-bottom:12.0pt;mar=
gin-left:.5in'><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
 Boczenowski, Steve [<a =
href=3D"mailto:sboczeno@MITRE.ORG">sboczeno@MITRE.ORG</a>]<br><b>Sent:</b=
> Tuesday, March 20, 2012 16:38<br><b>To:</b> <a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@L=
ISTS.MITRE.ORG</a><br><b>Subject:</b> [OVAL-DEVELOPER-LIST] Security =
Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'color:black'><o:p></o:p></span></p></div><div><div><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'color:black'>Save the Date: week of July 9, =
2012<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:black'>This year&#8217;s =
MITRE-hosted Security Automation Developer Days event will be held =
during the week of July 9, 2012 at MITRE&#8217;s facility in Bedford, =
MA.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:black'>Details to =
follow.<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:black'>Regards,<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:black'>&nbsp;&nbsp;&nbsp; Steve<o:p></o:p></span></p><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:4.0pt;=
margin-left:.5in'><span =
style=3D'font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D'>=
______________________________________________</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:4.0pt;=
margin-left:.5in'><i><span =
style=3D'font-family:"Arial","sans-serif";color:#1F497D'>Steph</span><spa=
n style=3D'color:#1F497D'>en P. Boczenowski</span></i><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:2.0pt;=
margin-left:.5in'><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The </span><span =
style=3D'font-size:10.0pt;font-family:MITRE;color:#3366FF'>MITRE</span><s=
pan =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
> Corporation</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:0in;ma=
rgin-left:.5in;margin-bottom:.0001pt'><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Office: (781) 271-7682</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:0in;ma=
rgin-left:.5in;margin-bottom:.0001pt'><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Cell: (978) 302-3849</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:0in;ma=
rgin-left:.5in;margin-bottom:.0001pt'><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=3D"mailto:sboczeno@mitre.org" =
target=3D"_blank">sboczeno@mitre.org</a></span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:black'>To unsubscribe, send an email message to <a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG">LISTSERV@LISTS.MITRE.ORG</a> =
with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to <a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG">OVAL-DEVELOPE=
R-LIST-request@LISTS.MITRE.ORG</a>. </span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div></div><p =
class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:black'>To unsubscribe, send an email message to <a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG">LISTSERV@LISTS.MITRE.ORG</a> =
with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to <a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG">OVAL-DEVELOPE=
R-LIST-request@LISTS.MITRE.ORG</a>. </span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Times New =
Roman","serif";color:black'>To unsubscribe, send an email message to <a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG">LISTSERV@LISTS.MITRE.ORG</a> =
with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to <a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG">OVAL-DEVELOPE=
R-LIST-request@LISTS.MITRE.ORG</a>. </span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div></blockquote></di=
v></div></blockquote></div></body></html>
------=_NextPart_000_00A9_01CD4A97.C567E550--


From david.oliva@verizon.net  Thu Jun 14 16:38:53 2012
Return-Path: <david.oliva@verizon.net>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id ED87E21F8512 for <sacm@ietfa.amsl.com>; Thu, 14 Jun 2012 16:38:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 2.796
X-Spam-Level: **
X-Spam-Status: No, score=2.796 tagged_above=-999 required=5 tests=[BAYES_50=0.001, HTML_MESSAGE=0.001, HTML_MIME_NO_HTML_TAG=0.097, MIME_HTML_ONLY=1.457, SARE_LWSHORTT=1.24]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZGOEaErN0XbD for <sacm@ietfa.amsl.com>; Thu, 14 Jun 2012 16:38:51 -0700 (PDT)
Received: from vms173019pub.verizon.net (vms173019pub.verizon.net [206.46.173.19]) by ietfa.amsl.com (Postfix) with ESMTP id C39CB21F8510 for <sacm@ietf.org>; Thu, 14 Jun 2012 16:38:50 -0700 (PDT)
Received: from vznit170130pub.verizon.net ([unknown] [192.168.1.3]) by vms173019.mailsrvcs.net (Sun Java(tm) System Messaging Server 7u2-7.02 32bit (built Apr 16 2009)) with ESMTPA id <0M5M00MLKSCA44E0@vms173019.mailsrvcs.net> for sacm@ietf.org; Thu, 14 Jun 2012 18:38:35 -0500 (CDT)
Received: from 216.231.4.2 ([216.231.4.2]) by vznit170130 (Verizon Webmail) with HTTP; Thu, 14 Jun 2012 18:38:34 -0500 (CDT)
Date: Thu, 14 Jun 2012 18:38:34 -0500 (CDT)
From: david.oliva@verizon.net
To: bchandra@secpod.com, scap-dev@nist.gov, sacm@ietf.org
Message-id: <14684411.1695189.1339717114359.JavaMail.root@vznit170130>
MIME-version: 1.0
Content-type: text/html; charset=UTF-8
Content-transfer-encoding: quoted-printable
X-Mailer: Verizon Webmail
X-Originating-IP: [216.231.4.2]
Subject: Re: [sacm] Request for participants - Content Repository	Specification Development
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Jun 2012 23:38:53 -0000

<div style=3D"FONT-FAMILY: Arial; COLOR: #000000; FONT-SIZE: 12px"><div>To =
all:</div><div><br /></div><div>Perhaps NIST should write a guidance Specia=
l Publication based on SP 800-70 but as a set of requirements that reposito=
ries should have. &nbsp;For instance, that repositories display the tier le=
vel (Tier I, II, III, and IV) and the specifications used in the content.</=
div><div><br /></div><div>David Oliva (Ruben)&nbsp;</div><div>&nbsp;</div><=
div>&nbsp;</div><div style=3D"border-top:1px solid #bcbcbc;margin:5px 0px;"=
></div><span style=3D"font-size:12;font-family:arial;color:#000000;">On 06/=
14/12, <span>Chandrashekhar B&lt;bchandra@secpod.com&gt;</span> wrote:</spa=
n><div>&nbsp;</div><div style=3D"font-size:12;font-family:arial;color:#0000=
00;"><div class=3D"WordSection1"><p class=3D"MsoNormal"><span style=3D"colo=
r:#1F497D">We have hosted our SCAP Content Repository at <a href=3D"http://=
www.scaprepo.com" target=3D"_blank">www.scaprepo.com</a>. Feedback is certa=
inly appreciated. A simple web service interface will be published soon.</s=
pan></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><=
/p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">Chandra.</span></p>=
<p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span></p><div>=
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in"><p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-fam=
ily:&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=
=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"=
> <a class=3D"parsedEmail" href=3D"mailto:scap-dev@nist.gov" target=3D"_bla=
nk">scap-dev@nist.gov</a> [<a class=3D"parsedLink" href=3D"mailto:scap-dev@=
nist.gov" target=3D"_blank">mailto:scap-dev@nist.gov</a>] <b>On Behalf Of <=
/b><a class=3D"parsedEmail" href=3D"mailto:Kent_Landfield@mcafee.com" targe=
t=3D"_blank">Kent_Landfield@mcafee.com</a><br /><b>Sent:</b> Friday, May 11=
, 2012 10:14 PM<br /><b>To:</b> Multiple recipients of list<br /><b>Subject=
:</b> Request for participants - Content Repository Specification Developme=
nt</span></p></div></div><p class=3D"MsoNormal">&nbsp;</p><div><div><div><p=
 class=3D"MsoNormal"><span style=3D"color:black">Mike I love it when you te=
e something up like that=E2=80=A6. ;-) &nbsp;Thank you. ;)</span></p></div>=
<div><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span></p></=
div><div><p class=3D"MsoNormal"><span style=3D"color:#1F497D">Mike wrote:&n=
bsp;</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><s=
pan style=3D"color:#1F497D">I still think that any specification for a repo=
sitory is wishful thinking until someone builds one and learns the lessons =
it will just be another whitepaper spec. &nbsp;I believe the DoD needs to i=
ncorporate a metadata repository as part of it and other customizations tha=
t may not be useful for everyone.</span><span style=3D"color:black"></span>=
</p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">We need to talk mo=
re=E2=80=A6;</span><span style=3D"color:black"></span></p><p class=3D"MsoNo=
rmal"><span style=3D"color:black">&nbsp;</span></p><p class=3D"MsoNormal"><=
span style=3D"color:black">If you are talking about a holistic, complete fe=
derated approach to a content repository, I some what agree. &nbsp;If you a=
re talking about an organizational repository, I totally disagree. But you =
knew I would. ;)</span><span style=3D"font-size:12.0pt;font-family:&quot;Ti=
mes New Roman&quot;,&quot;serif&quot;;color:black"></span></p><p class=3D"M=
soNormal"><span style=3D"color:black">&nbsp;</span></p><p class=3D"MsoNorma=
l"><span style=3D"color:black">Here is how I see the problem. &nbsp;There i=
s an immediate need for SCAP and other related content to be served up insi=
de an organization. &nbsp;Today we have situation where the standards allow=
 us to provide sites the capability to have a single SCAP implemented polic=
y they call official for their environment. Yes this is a rather simplistic=
 since there are things such as targeting specific platforms, specific oper=
ational use needs, but for now lets agree SCAP is a massive improvement ove=
r the proprietary situations of the past. While we have created this standa=
rd content so that sites can implement their local site security once and t=
hen assure they are measuring all appropriately targeted devices the same w=
ay, we have failed to support the operational needs of the sites. &nbsp;We =
have a situation where no two vendors distribute content the same way. &nbs=
p;This causes massive problems for the administration staff when they need =
to incorporate a new SCAP enabled product into their architecture. &nbsp;Th=
ey need to discover how the new product supports distributing SCAP content =
to it's various components. &nbsp;If they have one product then they do thi=
s one and they are done. &nbsp;If they have multiple products they will hav=
e to figure out how to minimize the impact by incorporating the update proc=
ess for the new product into the existing SCAP security content processes. =
Now when the inevitable happens and the site staff needs to make a change t=
o their security policy, they have to make the modifications to the benchma=
rk or checks or both and then distribute those updates across their network=
. &nbsp;For each SCAP enabled product they have in place, they have doubled=
, tripled or more the work needed to make those updates available.&nbsp;</s=
pan></p><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span></p=
><p class=3D"MsoNormal"><span style=3D"color:black">There is another conten=
t repository problem and that is the Federated Content Distribution. &nbsp;=
If you think global DNS you have a general frame of reference. &nbsp;The gu=
idance authors need to be able to publish content in an authoritative manne=
r so their content is updated in a timely fashion. &nbsp;This is a much har=
der problem to solve if there is no local organizational infrastructure to =
support it. ;)</span></p><p class=3D"MsoNormal"><span style=3D"color:black"=
>&nbsp;</span></p><p class=3D"MsoNormal"><span style=3D"color:black">So her=
e is what I am thinking=E2=80=A6 &nbsp;We should consider addressing these =
as two separate but integrated efforts. &nbsp;I believe the Organizational =
Content Repository is the more critical piece that is actually easier to ad=
dress. &nbsp;The Federated Content Distribution should be a subsequent effo=
rt integrating / augmenting the Organizational repository specification.&nb=
sp;</span></p><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</sp=
an></p><p class=3D"MsoNormal"><span style=3D"color:black">Mike, to your poi=
nt that we need someone to build one first=E2=80=A6 That has happened alrea=
dy. &nbsp;I have one as do other vendors but what we don=E2=80=99t have is =
the access specification. &nbsp;Ours are focused on our specific product ne=
eds. &nbsp;Additionally there is a company that has developed a commercial =
SCAP content repository that will be announced later this month. I won't st=
eal their thunder but I was recently given a sneak peek at it and I must ad=
mit I was very impressed. &nbsp;Again, to your point, it has been done. Wha=
t is needed to address the initial operational problem is to develop a spec=
ification that provides a consistent means for all SCAP products to retriev=
e the appropriate content as configured and managed but the site. &nbsp;</s=
pan></p><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span></p=
><p class=3D"MsoNormal" style=3D"margin-bottom:1.0pt"><span style=3D"color:=
black">TO THAT END=E2=80=A6.</span></p><p class=3D"MsoNormal"><span style=
=3D"color:black">&nbsp;</span></p><p class=3D"MsoNormal"><span style=3D"col=
or:black">I am requesting participation from those in the community that se=
e the need and want to put in the work to make this specification happen. &=
nbsp;I have talked to a couple of you but I do not want to assume your part=
icipation. &nbsp;If you are interested please contact me so we can get this=
 started.&nbsp;</span></p><p class=3D"MsoNormal"><span style=3D"color:black=
">&nbsp;</span></p><p class=3D"MsoNormal"><span style=3D"color:black">Thank=
s!</span></p><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</spa=
n></p></div><div><div><p class=3D"MsoNormal"><strong><span style=3D"font-si=
ze:9.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#606A71=
">Kent Landfield</span></strong><span style=3D"font-size:9.0pt;font-family:=
&quot;Arial&quot;,&quot;sans-serif&quot;;color:#606A71"><br /><span class=
=3D"apple-style-span">Director Content Strategy, Architecture and Standards=
</span><br /><br /><strong><span style=3D"font-family:&quot;Arial&quot;,&qu=
ot;sans-serif&quot;">McAfee | An Intel Company</span></strong><br /><span c=
lass=3D"apple-style-span">5000 Headquarters Dr.</span><br /><span class=3D"=
apple-style-span">Plano, Texas 75024</span><br /><br /><span class=3D"apple=
-style-span">Direct: +1.972.963.7096&nbsp;</span><br /><span class=3D"apple=
-style-span">Mobile: +1.817.637.8026</span><br /><strong><span style=3D"fon=
t-family:&quot;Arial&quot;,&quot;sans-serif&quot;">Web:&nbsp;</span></stron=
g><span class=3D"apple-style-span"><a href=3D"http://www.mcafee.com/" targe=
t=3D"_blank">www.mcafee.com</a></span></span><span style=3D"color:black"></=
span></p></div></div></div></div><div><p class=3D"MsoNormal"><span style=3D=
"color:black">&nbsp;</span></p></div><div style=3D"border:none;border-top:s=
olid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in"><p class=3D"MsoNormal"><b><sp=
an style=3D"color:black">From: </span></b><span style=3D"color:black">&lt;K=
inney&gt;, Michael A &lt;<a class=3D"parsedEmail" href=3D"mailto:m.kinne@ra=
dium.ncsc.mil" target=3D"_blank">m.kinne@radium.ncsc.mil</a>&gt;<br /><b>To=
: </b>David Waltermire &lt;<a class=3D"parsedEmail" href=3D"mailto:david.wa=
ltermire@nist.gov" target=3D"_blank">david.waltermire@nist.gov</a>&gt;, SCA=
P-DEV &lt;<a class=3D"parsedEmail" href=3D"mailto:SCAP-DEV@nist.gov" target=
=3D"_blank">SCAP-DEV@nist.gov</a>&gt;, &quot;<a class=3D"parsedEmail" href=
=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@ietforg</a>&quot; &lt;<a c=
lass=3D"parsedEmail" href=3D"mailto:sacm@ietf.org" target=3D"_blank">sacm@i=
etf.org</a>&gt;<br /><b>Subject: </b>Re: [sacm] [OVAL-DEVELOPER-LIST] Secur=
ity Automation Developer Days: Summer 2012 at MITRE in Bedford, MA</span></=
p></div><div><p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;font-fa=
mily:&quot;Times New Roman&quot;,&quot;serif&quot;;color:black">&nbsp;</spa=
n></p></div><blockquote id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"=
border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in 4.0pt;margi=
n-left:3.75pt;margin-right:0in"><div><div><p class=3D"MsoNormal"><span styl=
e=3D"color:#1F497D">Dave,</span><span style=3D"color:black"></span></p><p c=
lass=3D"MsoNormal"><span style=3D"color:#1F497D">I have no problem with web=
inars, I do want to keep developer days actionable and use it to make decis=
ions, and vote and accomplish things good or bad.&nbsp; I do not want this =
to be an informational briefing conference.</span><span style=3D"color:blac=
k"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">Thanks f=
or the links.</span><span style=3D"color:black"></span></p><p class=3D"MsoN=
ormal"><span style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:blac=
k"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">I still =
think that any specification for a repository is wishful thinking until som=
eone builds one and learns the lessons it will just be another whitepaper s=
pec. &nbsp;I believe the DoD needs to incorporate a metadata repository as =
part of it and other customizations that may not be useful for everyone.</s=
pan><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span sty=
le=3D"color:#1F497D">We need to talk more=E2=80=A6;</span><span style=3D"co=
lor:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">=
&nbsp;</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal">=
<span style=3D"color:#1F497D">-Mike&nbsp; </span><span style=3D"color:black=
"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</s=
pan><span style=3D"color:black"></span></p><div><div style=3D"border:none;b=
order-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in"><p class=3D"MsoNor=
mal"><b><span style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quo=
t;sans-serif&quot;;color:black">From:</span></b><span style=3D"font-size:10=
.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:black"> Wa=
ltermire, David A. [<a class=3D"parsedEmail" href=3D"mailto:david.waltermir=
e@nist.gov" target=3D"_blank">mailto:david.waltermire@nist.gov</a>] <br /><=
b>Sent:</b> Tuesday, May 08, 2012 10:44 AM<br /><b>To:</b> Kinney, Michael =
A; SCAP-DEV; <a class=3D"parsedEmail" href=3D"mailto:sacm@ietf.org" target=
=3D"_blank">sacm@ietf.org</a><br /><b>Subject:</b> RE: [OVAL-DEVELOPER-LIST=
] Security Automation Developer Days: Summer 2012 at MITRE in Bedford, MA</=
span><span style=3D"color:black"></span></p></div></div><p class=3D"MsoNorm=
al"><span style=3D"color:black">&nbsp;</span></p><p class=3D"MsoNormal"><sp=
an style=3D"color:#1F497D">Mike,</span><span style=3D"color:black"></span><=
/p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><span =
style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"colo=
r:#1F497D">What about having webinars in-place of the 30 minute briefs?</sp=
an><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span styl=
e=3D"color:#1F497D">&nbsp;</span><span style=3D"color:black"></span></p><p =
class=3D"MsoNormal"><span style=3D"color:#1F497D">Regarding content managem=
ent, we are building the prototype content repository for use in a producti=
on environment.&nbsp; As an open source project, it will be free for use by=
 anyone interested.&nbsp; My thinking is that this project can bridge the g=
ap until commercial solutions are available to augment it.&nbsp; This is a =
similar path that was followed with DNS (bind) and HTTP (apache).&nbsp; Whe=
n it is ready for use, I am hoping to use it to host USGCB content.&nbsp; Y=
ou would be welcome to use it for your needs.</span><span style=3D"color:bl=
ack"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;=
</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span =
style=3D"color:#1F497D">It is good that OCIL is moving forward.&nbsp; This =
is an important piece of supporting risk management and aspects of continuo=
us monitoring.&nbsp; I would also like to see some discussion on OCIL at De=
veloper Days.&nbsp; With the proposals we will likely have a sense of what =
needs to be discussed and what we can achieve consensus on outside the meet=
ing.</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><s=
pan style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:black"></span=
></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">Remediation is a =
topic near and dear to my heart.&nbsp; I too would like to see it move forw=
ard.</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><s=
pan style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:black"></span=
></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">We just published=
 the draft ASR specification for public comment.&nbsp; This specification s=
upports enterprise aggregate reporting which greatly reduces the data volum=
es needed verses detailed host-based reports. This specification has been d=
esigned as a more robust replacement for LASR&nbsp; It can be used in conti=
nuous monitoring applications to support aggregate data reporting needs (e.=
g. FISMA reporting, &nbsp;CyberScope).</span><span style=3D"color:black"></=
span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span>=
<span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=
=3D"color:#1F497D">Here are the links:</span><span style=3D"color:black"></=
span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span>=
<span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=
=3D"color:#1F497D"><a href=3D"http://csrc.nist.gov/publications/PubsDrafts.=
html" target=3D"_blank">http://csrc.nist.gov/publications/PubsDrafts.html</=
a></span><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><spa=
n style=3D"color:#1F497D"><a href=3D"http://csrc.nist.gov/publications/Pubs=
NISTIRs.html#NIST-IR-7848" target=3D"_blank">http://csrc.nist.gov/publicati=
ons/PubsNISTIRs.html#NIST-IR-7848</a></span><span style=3D"color:black"></s=
pan></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><=
span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D=
"color:#1F497D">The primary reason we have suggested waiting on XCCDF is no=
t the internationalization issue. Many vendors have commented that they are=
 still working on implementing the XCCDF 1.2.1 specification. We will be in=
 a better place in a few months once more development around XCCDF has occu=
rred.&nbsp; As we consider changes to the SCAP stack to address OCIL and ot=
her issues, we will identify areas that need improvement in XCCDF.&nbsp; Th=
ese are good and necessary discussions to have now, but we have a good deal=
 of work to do before we are ready to open up XCCDF.&nbsp; My suggestion is=
 to work on these related areas and then work up change proposals for XCCDF=
 as needed.&nbsp; By that time we should be ready to work on a new revision=
 of XCCDF.</span><span style=3D"color:black"></span></p><p class=3D"MsoNorm=
al"><span style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:black">=
</span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">I am also l=
ooking forward to the discussions at the conference.&nbsp; It has been too =
long.</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><=
span style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:black"></spa=
n></p><div><p class=3D"MsoNormal"><span style=3D"color:#1F497D">Sincerely,<=
/span><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span s=
tyle=3D"color:#1F497D">Dave</span><span style=3D"color:black"></span></p></=
div><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><span=
 style=3D"color:black"></span></p><div><div style=3D"border:none;border-top=
:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in"><p class=3D"MsoNormal"><b><=
span style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-se=
rif&quot;;color:black">From:</span></b><span style=3D"font-size:10.0pt;font=
-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:black"> Kinney, Mic=
hael A [<a class=3D"parsedEmail" href=3D"mailto:m.kinne@radium.ncscmil" tar=
get=3D"_blank">mailto:m.kinne@radium.ncsc.mil</a>] <br /><b>Sent:</b> Tuesd=
ay, May 08, 2012 7:09 AM<br /><b>To:</b> SCAP-DEV<br /><b>Cc:</b> Waltermir=
e, David A.<br /><b>Subject:</b> RE: [OVAL-DEVELOPER-LIST] Security Automat=
ion Developer Days: Summer 2012 at MITRE in Bedford, MA</span><span style=
=3D"color:black"></span></p></div></div><p class=3D"MsoNormal"><span style=
=3D"color:black">&nbsp;</span></p><p class=3D"MsoNormal"><span style=3D"col=
or:#1F497D">Kent,</span><span style=3D"color:black"></span></p><p class=3D"=
MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:=
black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">It=
=E2=80=99s good to read your thoughts, and a realistic actionable approach =
is indeed needed &nbsp;Since all the activity hasn=E2=80=99t been on the li=
sts a brief 1=C5=BD2 hour recap may be in order to bring everyone up to spe=
ed since there has been a lot of activity on CPE/SWID, OCIl, MAEC/CybOX CEE=
 and others.</span><span style=3D"color:black"></span></p><p class=3D"MsoNo=
rmal"><span style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:black=
"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">We could =
write a content repository specification, but without someone willing to st=
and one up it will be as valuable as the CCSS specification is today. &nbsp=
;I=E2=80=99ve been trying for two years to get my management to get a coord=
inated effort together for the DoD to stand up a repository, it is a tough =
problem and will require funding with a tail, I=E2=80=99m not sure a specif=
ication will solve that problem.</span><span style=3D"color:black"></span><=
/p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><span =
style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"colo=
r:#1F497D">We (DoD) have been putting a lot of effort into OCIL over the la=
st year trying to make it useful in an enterprise environment and will be p=
osting our ideas to the list before developer days it should have already s=
tarted, we need to get consensus and a vote on how the community wishes to =
proceed.</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal=
"><span style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:black"></=
span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">Remediation i=
s stalled but I=E2=80=99m making every effort to get it kick started from o=
ur perspective. I hope to assist in getting the draft ERI finished this yea=
r. &nbsp;We are writing some new STIG content and intend to used the draft =
CRE specification to insert CRE into the content so we (DoD) can do some au=
tomatic configuration fixes, part of a self healing network concept. It is =
just a start but the best we can do at this point.</span><span style=3D"col=
or:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&=
nbsp;</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal"><=
span style=3D"color:#1F497D">Enterprise reporting is an interesting subject=
, since XML adds size to and content to roll up reporting, in any enterpris=
e of size the problem gets greater, I look forward to your thoughts on that=
 subject.</span><span style=3D"color:black"></span></p><p class=3D"MsoNorma=
l"><span style=3D"color:#1F497D">&nbsp;</span><span style=3D"color:black"><=
/span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">I am concern=
ed that the internationalization efforts are detracting from efforts to mee=
t use cases, we have some things we would like changed in XCCDF to support =
our OCIl use case and I have been told that I need to wait. I didn=E2=80=99=
t think that a move to internationalization should impede efforts to move f=
orward with use cases.</span><span style=3D"color:black"></span></p><p clas=
s=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><span style=3D"c=
olor:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D"=
>I look forward to talking with you at the conference.</span><span style=3D=
"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497=
D">&nbsp;</span><span style=3D"color:black"></span></p><p class=3D"MsoNorma=
l"><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans=
-serif&quot;;color:#1F497D">v/r</span><span style=3D"color:black"></span></=
p><p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;=
Arial&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><span style=
=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"font-size=
:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"=
>Mike Kinney</span><span style=3D"color:black"></span></p><p class=3D"MsoNo=
rmal"><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;s=
ans-serif&quot;;color:#1F497D">Project Director</span><span style=3D"color:=
black"></span></p><p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;fo=
nt-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D">Computer =
Network Defense Research and Technology (CND R&amp;T) Office</span><span st=
yle=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F49=
7D">9800 Savage Road Ste 6767<br />Ft Meade, MD 20755-6767<br /></span><spa=
n style=3D"font-size:10.0pt;color:#1F497D">Phone: 410-854-4422<br />NSTS: 9=
68-8886<br />Fax 410-854-4681</span><span style=3D"color:black"></span></p>=
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;color:#1F497D"><a class=3D"parsedEmail" hr=
ef=3D"mailto:M.kinne@radium.ncsc.mil" target=3D"_blank"><span style=3D"colo=
r:#660000">makinn2@nsa.gov</span></a></span><span style=3D"color:black"></s=
pan></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><=
span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D=
"color:#1F497D">&nbsp;</span><span style=3D"color:black"></span></p><p clas=
s=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><span style=3D"c=
olor:black"></span></p><div><div style=3D"border:none;border-top:solid #B5C=
4DF 1.0pt;padding:3.0pt 0in 0in 0in"><p class=3D"MsoNormal"><b><span style=
=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;=
color:black">From:</span></b><span style=3D"font-size:10.0pt;font-family:&q=
uot;Tahoma&quot;,&quot;sans-serif&quot;;color:black"><a class=3D"parsedEmai=
l" href=3D"mailto:scap-dev@nist.gov" target=3D"_blank">scap-dev@nist.gov</a=
> <a class=3D"parsedEmail" href=3D"mailto:[mailto:scap-dev@nist.gov]" targe=
t=3D"_blank">[mailto:scap-dev@nist.gov]</a> <b>On Behalf Of </b>Waltermire,=
 David A.<br /><b>Sent:</b> Monday, May 07, 2012 7:09 PM<br /><b>To:</b> Mu=
ltiple recipients of list<br /><b>Subject:</b> RE: [OVAL-DEVELOPER-LIST] Se=
curity Automation Developer Days: Summer 2012 at MITRE in Bedford, MA</span=
><span style=3D"color:black"></span></p></div></div><p class=3D"MsoNormal">=
<span style=3D"color:black">&nbsp;</span></p><p class=3D"MsoNormal"><span s=
tyle=3D"color:#1F497D">Kent,</span><span style=3D"color:black"></span></p><=
p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><span styl=
e=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1=
F497D">I like what you are saying here.&nbsp; We are also in support of thi=
s type of approach.&nbsp; We would like to see some community discussion ar=
ound what are the key areas/priorities that the community would like to see=
 discussed at Dev Days.&nbsp; Your topics below look like a good start. The=
 SACM list might be a better venue than the OVAL list for this discussion.&=
nbsp; For each area we should focus the discussion around developing object=
ives for each session.&nbsp; The sessions can be time boxed based on what w=
ould be a reasonable amount of time to accomplish each objective.&nbsp; For=
 example if continuous monitoring is a priority and collectively it takes 3=
 days to work through all the objectives, I see no problem with that.&nbsp;=
 We can also keep a few sessions =E2=80=9Con deck=E2=80=9D if all the objec=
tives are reached and we complete all the scheduled sessions early.</span><=
span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D=
"color:#1F497D">&nbsp;</span><span style=3D"color:black"></span></p><p clas=
s=3D"MsoNormal"><span style=3D"color:#1F497D">Thoughts?</span><span style=
=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F=
497D">&nbsp;</span><span style=3D"color:black"></span></p><div><p class=3D"=
MsoNormal"><span style=3D"color:#1F497D">Sincerely,</span><span style=3D"co=
lor:black"></span></p></div><p class=3D"MsoNormal"><span style=3D"color:bla=
ck">&nbsp;</span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">D=
avid Waltermire</span><span style=3D"color:black"></span></p><p class=3D"Ms=
oNormal"><span style=3D"color:#1F497D">SCAP Architect</span><span style=3D"=
color:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D=
">National Institute of Standards and Technology</span><span style=3D"color=
:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">(30=
1) 975-3390</span><span style=3D"color:black"></span></p><p class=3D"MsoNor=
mal"><span style=3D"color:black"><a class=3D"parsedEmail" href=3D"mailto:da=
vid.waltermire@nist.gov" target=3D"_blank">david.waltermire@nist.gov</a></s=
pan></p><p class=3D"MsoNormal"><span style=3D"color:#1F497D">&nbsp;</span><=
span style=3D"color:black"></span></p><div><div style=3D"border:none;border=
-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in"><p class=3D"MsoNormal">=
<b><span style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;san=
s-serif&quot;;color:black">From:</span></b><span style=3D"font-size:10.0pt;=
font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:black"><a class=
=3D"parsedEmail" href=3D"mailto:scap-dev@nist.gov" target=3D"_blank">scap-d=
ev@nist.gov</a> <a class=3D"parsedEmail" href=3D"mailto:[mailto:scap-dev@ni=
st.gov]" target=3D"_blank">[mailto:scap-dev@nist.gov]</a> <b>On Behalf Of <=
/b><a class=3D"parsedEmail" href=3D"mailto:Kent_Landfield@mcafee.com" targe=
t=3D"_blank">Kent_Landfield@mcafee.com</a><br /><b>Sent:</b> Monday, May 07=
, 2012 4:25 PM<br /><b>To:</b> SCAP-DEV<br /><b>Subject:</b> Re: [OVAL-DEVE=
LOPER-LIST] Security Automation Developer Days: Summer 2012 at MITRE in Bed=
ford, MA</span><span style=3D"color:black"></span></p></div></div><p class=
=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span></p><div><div><div>=
<div><p class=3D"MsoNormal"><span style=3D"color:black">All,</span></p></di=
v><div><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span></p>=
</div><div><p class=3D"MsoNormal"><span style=3D"color:black">I would like =
to discuss the format for the SCAP Developer Days that seems to be listed b=
elow.</span></p></div><div><p class=3D"MsoNormal"><span style=3D"color:blac=
k">&nbsp;</span></p></div><div><p class=3D"MsoNormal"><span style=3D"color:=
black">I see this appears to follow a path we have discussed in the past as=
 the way not to hold a Dev Days event. &nbsp;We have been trying to get awa=
y from 'Death by Powerpoint' and back to the type of event we held years ag=
o when we were highly productive. &nbsp;In the past we had a topic to be di=
scussed and a time box to work within. &nbsp;That allowed us to have very a=
ctive brainstorming sessions in a high bandwidth environment.</span></p></d=
iv><div><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span></p=
></div><div><p class=3D"MsoNormal"><span style=3D"color:black">At past Summ=
er events we have got into a pattern of lots of powerpoint, lots of status =
of the efforts and very little discussion about things that need active dis=
cussions. &nbsp;We need to keep moving forward and making progress as an ef=
fort. We can get status from various places such as the lists, a presentati=
on being sent out in advance, a webinar if it is felt there will be questio=
ns and answers from those that are new to the efforts. &nbsp;We have a limi=
ted amount of time and all who are attending are investing a great deal of =
time and money to be there. &nbsp;We should not &nbsp;be spending a great d=
eal of time reeducating everyone when we could be focused on advancing need=
ed efforts.</span></p></div><div><p class=3D"MsoNormal"><span style=3D"colo=
r:black">&nbsp;</span></p></div><div><p class=3D"MsoNormal"><span style=3D"=
color:black">The type of approach to a Dev Days event was discussed at the =
last Summer Dev Days. &nbsp;I have seen the following work quite well in ot=
her efforts.</span></p></div><ol start=3D"1" type=3D"1"><li class=3D"MsoNor=
mal" style=3D"color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:aut=
o;mso-list:l0 level1 lfo3">Presentations are sent out to the attendees and =
the lists a week in advance</li><li class=3D"MsoNormal" style=3D"color:blac=
k;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo=
3">Status for any effort is limited to 30 minutes</li><li class=3D"MsoNorma=
l" style=3D"color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;=
mso-list:l0 level1 lfo3">Focused brainstorming time should be established f=
or certain areas that need real work by the community</li><li class=3D"MsoN=
ormal" style=3D"color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:a=
uto;mso-list:l0 level1 lfo3">Efforts to be discussed should be based on nee=
ds of the security automation space to move existing efforts to completion.=
</li></ol><div><p class=3D"MsoNormal"><span style=3D"color:black">For examp=
le:</span></p></div><div><p class=3D"MsoNormal"><span style=3D"color:black"=
>&nbsp;</span></p></div><div><p class=3D"MsoNormal"><span style=3D"color:bl=
ack">Continuous monitoring is a major direction the efforts are becoming in=
volved with. There are going to be things we need to do as a security autom=
ation community to be able to accomplish what is listed in the CAESARS FE. =
&nbsp;There are interfaces that need to be worked and established. &nbsp;Th=
at is one area that is not listed below. &nbsp;CM will have a major impact =
on all of us in the next couple years and it is being ignored. &nbsp;We can=
't keep trying to solve what has already been solved. &nbsp;We need to addr=
ess the needed interface development now. This is an effort that could take=
 nearly a whole day by itself.</span></p></div><div><p class=3D"MsoNormal">=
<span style=3D"color:black">&nbsp;</span></p></div><div><p class=3D"MsoNorm=
al"><span style=3D"color:black">Operationally we have a real need to be abl=
e to deliver SCAP content internally within an organization. Today the SCAP=
 vendors cannot share a single local site security policy (XCCDF + OVAL + C=
PE +=E2=80=A6) without the site staff having to go to each of the individua=
l products and figuring out how to inject that new or updated policy into t=
hat products delivery mechanisms. &nbsp;That is limiting sites from wanting=
 to buy multiple focused SCAP products since they are such a pain to manage=
 from a content perspective. &nbsp;It is easier to buy from one vendor that=
 has a single means for distributing content than it is to deal with the ma=
nagement issues that having multiple SCAP products presents. &nbsp;We need =
to have at least an entire 1/2 a day on the development of a Content Reposi=
tory specification.</span></p></div><div><p class=3D"MsoNormal"><span style=
=3D"color:black">&nbsp;</span></p></div><div><p class=3D"MsoNormal"><span s=
tyle=3D"color:black">OCIL is a positive and a negative at the same time. It=
 has real value that is being underutilized and under implemented because o=
f the limitations of how it addresses uses in an enterprise environment. &n=
bsp;People don't need security automation to do things on/for a single host=
. &nbsp;They need security automation to focus on the enterprise issues tha=
t reduce their costs and improve their efficiencies. &nbsp;OCIL is failing =
in the enterprise and we all understand that. &nbsp;We need to address deve=
loping a definitive solution for incorporating OCIL into the enterprise and=
 that means into the existing specifications. Scheduling and tracking are k=
ey to it's success. &nbsp;We need to make that happen. &nbsp;This too needs=
 a focused brainstorming time box to discuss options.</span></p></div><div>=
<p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span></p></div><=
div><p class=3D"MsoNormal"><span style=3D"color:black">I am really disappoi=
nted that Remediation is not on the list below=E2=80=A6 &nbsp;Yes, last Sum=
mer Dev Days, the time spent on Remediation was wasted time but that does n=
ot mean we should ignore it and not try to make some real progress. &nbsp;A=
s far as I am concerned we need to reboot the remediation effort. &nbsp;We =
cannot keep being the set of specifications / tools that act as the little =
boy crying &quot;Wolf&quot; in the night. &nbsp;We need to be able to find =
and fix issues if we are going to really make a difference in organizationa=
l security postures. &nbsp;But today we think it is too hard so we don't tr=
y ? &nbsp;I think we need a couple hours to discuss the reboot of the effor=
t even if that means minimizing work already done.</span></p></div><div><p =
class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span></p></div><div=
><p class=3D"MsoNormal"><span style=3D"color:black">A focused discussion on=
 enterprise reporting is also critically needed. &nbsp;For the vendors here=
, we have all gone through the Cyberscope goat rope, delivering limited cap=
abilities to specific data call requirements of the Federal Agencies. &nbsp=
;The initial effort was a mess, did little more than prove it was possible =
and cause the vendor community a great deal of thrashing to put a kludgey '=
solution' in place. &nbsp;Reality is all our customers need roll up reporti=
ng and an infrastructure that supports it. &nbsp;A data call should not be =
special to anyone other than the agencies responding. The tools should be a=
ble to select the types of data needed and deliver that on a scheduled basi=
s automatically. &nbsp; &nbsp;Enterprise Reporting pertains to commercial a=
s well as Federal customers. &nbsp;We need to focus some time on what that =
would look like using the ARF and ASR as the foundational pieces. &nbsp;But=
 there are missing pieces=E2=80=A6. &nbsp;We need this discussed.</span></p=
></div><div><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span=
></p></div><div><p class=3D"MsoNormal"><span style=3D"color:black">I would =
hope we can make this summer's SCAP Dev Days useful in advancing the securi=
ty automation efforts by addressing some of the more critical issues our cu=
stomers are facing now or will be facing in the very short term. &nbsp;Stat=
us presentations are not interesting to those active in the efforts. &nbsp;=
Let's try to do those before we get to Bedford so we can real make some pro=
gress while we are all in the same room. &nbsp;This is always a big event f=
or the 'consensus of the willing' that assemble and driven to see security =
automation make a difference. &nbsp;Let's see if we can have an event that,=
 when we all walk out the last day, we all feel that every minute was well =
spent and moves us forward.</span></p></div><div><p class=3D"MsoNormal"><sp=
an style=3D"color:black">&nbsp;</span></p></div><div><p class=3D"MsoNormal"=
><span style=3D"color:black">Thanks.</span></p></div><div><p class=3D"MsoNo=
rmal"><span style=3D"color:black">&nbsp;</span></p></div><div><div><p class=
=3D"MsoNormal"><strong><span style=3D"font-size:9.0pt;font-family:&quot;Ari=
al&quot;,&quot;sans-serif&quot;;color:#606A71">Kent Landfield</span></stron=
g><span style=3D"font-size:9.0pt;font-family:&quot;Arial&quot;,&quot;sans-s=
erif&quot;;color:#606A71"><br /><span class=3D"apple-style-span">Director C=
ontent Strategy, Architecture and Standards</span><br /><br /><strong><span=
 style=3D"font-family:&quot;Arial&quot;,&quot;sans-serif&quot;">McAfee | An=
 Intel Company</span></strong><br /><span class=3D"apple-style-span">5000 H=
eadquarters Dr.</span><br /><span class=3D"apple-style-span">Plano, Texas 7=
5024</span><br /><br /><span class=3D"apple-style-span">Direct: +1.972.963.=
7096&nbsp;</span><br /><span class=3D"apple-style-span">Mobile: +1.817.637.=
8026</span><br /><strong><span style=3D"font-family:&quot;Arial&quot;,&quot=
;sans-serif&quot;">Web:&nbsp;</span></strong><span class=3D"apple-style-spa=
n"><a href=3D"http://www.mcafee.com/" target=3D"_blank">www.mcafee.com</a><=
/span></span><span style=3D"color:black"></span></p></div></div></div></div=
></div><div><p class=3D"MsoNormal"><span style=3D"color:black">&nbsp;</span=
></p></div><div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding=
:3.0pt 0in 0in 0in"><p class=3D"MsoNormal"><b><span style=3D"color:black">F=
rom: </span></b><span style=3D"color:black">&lt;Boczenowski&gt;, Steve &lt;=
<a class=3D"parsedEmail" href=3D"mailto:sboczeno@MITRE.ORG" target=3D"_blan=
k">sboczeno@MITRE.ORG</a>&gt;<br /><b>Reply-To: </b>&quot;OVAL Developer Li=
st (Closed Public Discussion)&quot; &lt;<a class=3D"parsedEmail" href=3D"ma=
ilto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG" target=3D"_blank">OVAL-DEVELOPER-=
LIST@LISTS.MITRE.ORG</a>&gt;<br /><b>To: </b>&quot;<a class=3D"parsedEmail"=
 href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG" target=3D"_blank">OVAL=
-DEVELOPER-LIST@LISTS.MITRE.ORG</a>&quot; &lt;<a class=3D"parsedEmail" href=
=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG" target=3D"_blank">OVAL-DEVE=
LOPER-LIST@LISTS.MITRE.ORG</a>&gt;<br /><b>Subject: </b>Re: [OVAL-DEVELOPER=
-LIST] Security Automation Developer Days: Summer 2012 at MITRE in Bedford,=
 MA</span></p></div><div><p class=3D"MsoNormal"><span style=3D"font-size:12=
.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:black"=
>&nbsp;</span><span style=3D"color:black"></span></p></div><blockquote id=
=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"border:none;border-left:so=
lid #B5C4DF 4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-top:5=
.0pt;margin-right:0in;margin-bottom:5.0pt"><div><div><p class=3D"MsoNormal"=
><span style=3D"color:#254061">Frank;</span><span style=3D"color:black"></s=
pan></p><p class=3D"MsoNormal"><span style=3D"color:#254061">&nbsp;</span><=
span style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D=
"color:#254061">We hope to have the registration site up next week.&nbsp; T=
he event will be during the week of July 9 =E2=80=93 starting Monday at 10:=
00 AM and ending on Friday at 12:00.</span><span style=3D"color:black"></sp=
an></p><p class=3D"MsoNormal"><span style=3D"color:#254061">&nbsp;</span><s=
pan style=3D"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"=
color:#254061">Meanwhile, we are working on the agenda and are currently co=
nsidering this list of topics:</span><span style=3D"color:black"></span></p=
><p class=3D"MsoNormal"><span style=3D"color:#254061">&nbsp;</span><span st=
yle=3D"color:black"></span></p><p class=3D"MsoNormal" style=3D"text-indent:=
.5in"><span style=3D"color:#254061">CCE</span><span style=3D"color:black"><=
/span></p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"=
color:#254061">CPE/SWID</span><span style=3D"color:black"></span></p><p cla=
ss=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"color:#254061">C=
EE</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal" styl=
e=3D"margin-left:.5in"><span style=3D"color:#254061">XCCDF</span><span styl=
e=3D"color:black"></span></p><p class=3D"MsoNormal" style=3D"margin-left:.5=
in"><span style=3D"color:#254061">OVAL</span><span style=3D"color:black"></=
span></p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"c=
olor:#254061">ASR</span><span style=3D"color:black"></span></p><p class=3D"=
MsoNormal" style=3D"margin-left:.5in"><span style=3D"color:#254061">Enterpr=
ise OCIL</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal=
" style=3D"margin-left:.5in"><span style=3D"color:#254061">CybOX/MAEC</span=
><span style=3D"color:black"></span></p><p class=3D"MsoNormal" style=3D"mar=
gin-left:.5in"><span style=3D"color:#254061">Federated Content Repository S=
pec</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal" sty=
le=3D"margin-left:.5in"><span style=3D"color:#254061">Endpoint Reporting fo=
r Continuous Monitoring and Compliance (ERCC)</span><span style=3D"color:bl=
ack"></span></p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span sty=
le=3D"color:#254061">MILE</span><span style=3D"color:black"></span></p><p c=
lass=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"color:#254061"=
>TAXII</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal" =
style=3D"margin-left:.5in"><span style=3D"color:#254061">IF-M for SCAP</spa=
n><span style=3D"color:black"></span></p><p class=3D"MsoNormal" style=3D"ma=
rgin-left:.5in"><span style=3D"color:#254061">IF-MAP</span><span style=3D"c=
olor:black"></span></p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><s=
pan style=3D"color:#254061">SCAP Releases</span><span style=3D"color:black"=
></span></p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=
=3D"color:#254061">SCAP and IETF</span><span style=3D"color:black"></span><=
/p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"color:#=
254061">NETCONF and SCAP</span><span style=3D"color:black"></span></p><p cl=
ass=3D"MsoNormal"><span style=3D"color:#254061">&nbsp;</span><span style=3D=
"color:black"></span></p><p class=3D"MsoNormal"><span style=3D"color:#25406=
1">Steve</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal=
"><span style=3D"color:#254061">&nbsp;</span><span style=3D"color:black"></=
span></p><div><div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padd=
ing:3.0pt 0in 0in 0in"><p class=3D"MsoNormal" style=3D"margin-left:2.0in"><=
b><span style=3D"font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans=
-serif&quot;;color:black">From:</span></b><span style=3D"font-size:10.0pt;f=
ont-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:black"> Frank Li=
ndsay Acker [<a class=3D"parsedEmail" href=3D"mailto:afrank@NOVA.EDU" targe=
t=3D"_blank">mailto:afrank@NOVA.EDU</a>] <br /><b>Sent:</b> Tuesday, May 01=
, 2012 9:32 AM<br /><b>To:</b> oval-developer-list OVAL Developer List/Clos=
ed Public Discussion<br /><b>Subject:</b> Re: [OVAL-DEVELOPER-LIST] Securit=
y Automation Developer Days: Summer 2012 at MITRE in Bedford, MA</span><spa=
n style=3D"color:black"></span></p></div></div><p class=3D"MsoNormal" style=
=3D"margin-left:.5in"><span style=3D"color:black">&nbsp;</span></p><div><p =
class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:10.=
0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:black">Stev=
e....<br /><br />Has there been any additional information regarding this e=
vent?<br /><br />Thanks,<br />Frank Acker</span><span style=3D"color:black"=
></span></p><div><div style=3D"margin-left:.5in"><div align=3D"center" clas=
s=3D"MsoNormal" style=3D"text-align:center"><span style=3D"font-size:12.0pt=
;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:black"><hr=
 align=3D"center" size=3D"2" width=3D"100%" /></span></div></div><div id=3D=
"divRpF955236"><p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margi=
n-right:0in;margin-bottom:12.0pt;margin-left:.5in"><b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;;color:blac=
k">From:</span></b><span style=3D"font-size:10.0pt;font-family:&quot;Tahoma=
&quot;,&quot;sans-serif&quot;;color:black"> Boczenowski, Steve [<a class=3D=
"parsedEmail" href=3D"mailto:sboczeno@MITRE.ORG" target=3D"_blank">sboczeno=
@MITRE.ORG</a>]<br /><b>Sent:</b> Tuesday, March 20, 2012 16:38<br /><b>To:=
</b> <a class=3D"parsedEmail" href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITR=
E.ORG" target=3D"_blank">OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG</a><br /><b>Su=
bject:</b> [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer=
 2012 at MITRE in Bedford, MA</span><span style=3D"color:black"></span></p>=
</div><div><div><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span sty=
le=3D"color:black">Save the Date: week of July 9, 2012</span></p><p class=
=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"color:black">&nbsp=
;</span></p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=
=3D"color:black">This year=E2=80=99s MITRE-hosted Security Automation Devel=
oper Days event will be held during the week of July 9, 2012 at MITRE=E2=80=
=99s facility in Bedford, MA.</span></p><p class=3D"MsoNormal" style=3D"mar=
gin-left:.5in"><span style=3D"color:black">&nbsp;</span></p><p class=3D"Mso=
Normal" style=3D"margin-left:.5in"><span style=3D"color:black">Details to f=
ollow.</span></p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span st=
yle=3D"color:black">&nbsp;</span></p><p class=3D"MsoNormal" style=3D"margin=
-left:.5in"><span style=3D"color:black">Regards,</span></p><p class=3D"MsoN=
ormal" style=3D"margin-left:.5in"><span style=3D"color:black">&nbsp;&nbsp;&=
nbsp; Steve</span></p><p class=3D"MsoNormal" style=3D"margin-left:.5in"><sp=
an style=3D"color:black">&nbsp;</span></p><p class=3D"MsoNormal" style=3D"m=
so-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:4.0pt;margin-left:=
.5in"><span style=3D"font-size:8.0pt;font-family:&quot;Arial&quot;,&quot;sa=
ns-serif&quot;;color:#1F497D">_____________________________________________=
_</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal" style=
=3D"mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:4.0pt;margin-=
left:.5in"><i><span style=3D"font-family:&quot;Arial&quot;,&quot;sans-serif=
&quot;;color:#1F497D">Steph</span><span style=3D"color:#1F497D">en P. Bocze=
nowski</span></i><span style=3D"color:black"></span></p><p class=3D"MsoNorm=
al" style=3D"mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:2.0p=
t;margin-left:.5in"><span style=3D"font-size:10.0pt;font-family:&quot;Arial=
&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
 The </span><span style=3D"font-size:10.0pt;font-family:MITRE;color:#3366FF=
">MITRE</span><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;=
,&quot;sans-serif&quot;;color:#1F497D"> Corporation</span><span style=3D"co=
lor:black"></span></p><p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0i=
n;margin-right:343.5pt;margin-bottom:0in;margin-left:.5in;margin-bottom:.00=
01pt"><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;s=
ans-serif&quot;;color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Office: (781)=
 271-7682</span><span style=3D"color:black"></span></p><p class=3D"MsoNorma=
l" style=3D"mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:0in;m=
argin-left:.5in;margin-bottom:.0001pt"><span style=3D"font-size:10.0pt;font=
-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp; Cell: (978) 302-3849</span><span style=3D"color:black">=
</span></p><p class=3D"MsoNormal" style=3D"mso-margin-top-alt:0in;margin-ri=
ght:343.5pt;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt"><span=
 style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&q=
uot;;color:#1F497D">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a class=3D"parsedEmail" =
href=3D"mailto:sboczeno@mitre.org" target=3D"_blank">sboczeno@mitre.org</a>=
</span><span style=3D"color:black"></span></p><p class=3D"MsoNormal" style=
=3D"margin-left:.5in"><span style=3D"color:black">&nbsp;</span></p></div><p=
 class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:12=
.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:black"=
>To unsubscribe, send an email message to <a class=3D"parsedEmail" href=3D"=
mailto:LISTSERV@LISTS.MITRE.ORG" target=3D"_blank">LISTSERV@LISTS.MITRE.ORG=
</a> with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you ha=
ve difficulties, write to <a class=3D"parsedEmail" href=3D"mailto:OVAL-DEVE=
LOPER-LIST-request@LISTS.MITRE.ORG" target=3D"_blank">OVAL-DEVELOPER-LIST-r=
equest@LISTS.MITRE.ORG</a>. </span><span style=3D"color:black"></span></p><=
/div></div></div><p class=3D"MsoNormal" style=3D"margin-left:.5in"><span st=
yle=3D"font-size:12.0pt;font-family:&quot;Times New Roman&quot;,&quot;serif=
&quot;;color:black">To unsubscribe, send an email message to <a class=3D"pa=
rsedEmail" href=3D"mailto:LISTSERV@LISTS.MITRE.ORG" target=3D"_blank">LISTS=
ERV@LISTS.MITRE.ORG</a> with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the=
 message. If you have difficulties, write to <a class=3D"parsedEmail" href=
=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG" target=3D"_blank">O=
VAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG</a>. </span><span style=3D"color=
:black"></span></p><p class=3D"MsoNormal"><span style=3D"font-size:12.0pt;f=
ont-family:&quot;Times New Roman&quot;,&quot;serif&quot;;color:black">To un=
subscribe, send an email message to <a class=3D"parsedEmail" href=3D"mailto=
:LISTSERV@LISTS.MITRE.ORG" target=3D"_blank">LISTSERV@LISTS.MITRE.ORG</a> w=
ith SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have dif=
ficulties, write to <a class=3D"parsedEmail" href=3D"mailto:OVAL-DEVELOPER-=
LIST-request@LISTS.MITRE.ORG" target=3D"_blank">OVAL-DEVELOPER-LIST-request=
@LISTS.MITRE.ORG</a>. </span><span style=3D"color:black"></span></p></div><=
/div></blockquote></div></div></blockquote></div><br /><hr size=3D"1" /><br=
 />_______________________________________________<br />sacm mailing list<b=
r /><a class=3D"parsedEmail" href=3D"mailto:sacm@ietf.org" target=3D"_blank=
">sacm@ietf.org</a><br /><a class=3D"parsedLink" href=3D"https://www.ietf.o=
rg/mailman/listinfo/sacm" target=3D"_blank">https://www.ietf.org/mailman/li=
stinfo/sacm</a><br /></div></div>

From david.waltermire@nist.gov  Fri Jun 15 12:23:21 2012
Return-Path: <david.waltermire@nist.gov>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B8B7711E80E2 for <sacm@ietfa.amsl.com>; Fri, 15 Jun 2012 12:23:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.358
X-Spam-Level: 
X-Spam-Status: No, score=-5.358 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4, SARE_LWSHORTT=1.24]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yvyjpg0m4Hph for <sacm@ietfa.amsl.com>; Fri, 15 Jun 2012 12:23:07 -0700 (PDT)
Received: from wsget1.nist.gov (wsget1.nist.gov [129.6.13.150]) by ietfa.amsl.com (Postfix) with ESMTP id 48DDB11E80CD for <sacm@ietf.org>; Fri, 15 Jun 2012 12:23:05 -0700 (PDT)
Received: from WSXGHUB2.xchange.nist.gov (129.6.18.19) by wsget1.nist.gov (129.6.13.150) with Microsoft SMTP Server (TLS) id 14.1.355.2; Fri, 15 Jun 2012 15:22:56 -0400
Received: from MBCLUSTER.xchange.nist.gov ([fe80::d479:3188:aec0:cb66]) by WSXGHUB2.xchange.nist.gov ([129.6.18.19]) with mapi; Fri, 15 Jun 2012 15:20:33 -0400
From: "Waltermire, David A." <david.waltermire@nist.gov>
To: "bchandra@secpod.com" <bchandra@secpod.com>, SCAP-DEV <SCAP-DEV@nist.gov>,  "sacm@ietf.org" <sacm@ietf.org>
Date: Fri, 15 Jun 2012 15:23:03 -0400
Thread-Topic: [sacm] Request for participants - Content Repository Specification Development
Thread-Index: AQJt5r4nvn6Xg4466qYgTE+iSkxyIpW5BFnQgAGGgJA=
Message-ID: <D7A0423E5E193F40BE6E94126930C4930B9BA83FFD@MBCLUSTER.xchange.nist.gov>
References: <15D0981C9BE53042A4C9D0F3D0B6826B2900F2@MSIS-GH1-UEA10.corp.nsa.gov> <CBD00675.32964%kent_landfield@mcafee.com> <00a801cd4a69$aba5be40$02f13ac0$@secpod.com>
In-Reply-To: <00a801cd4a69$aba5be40$02f13ac0$@secpod.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_D7A0423E5E193F40BE6E94126930C4930B9BA83FFDMBCLUSTERxcha_"
MIME-Version: 1.0
Subject: Re: [sacm] Request for participants - Content Repository	Specification Development
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Jun 2012 19:23:22 -0000

--_000_D7A0423E5E193F40BE6E94126930C4930B9BA83FFDMBCLUSTERxcha_
Content-Type: text/plain; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

I am not sure how to use the search page properly.  Would you please provid=
e some example searches?

Sincerely,
Dave

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of Cha=
ndrashekhar B
Sent: Thursday, June 14, 2012 4:10 PM
To: SCAP-DEV; sacm@ietf.org
Subject: Re: [sacm] Request for participants - Content Repository Specifica=
tion Development

We have hosted our SCAP Content Repository at www.scaprepo.com<http://www.s=
caprepo.com>. Feedback is certainly appreciated. A simple web service inter=
face will be published soon.

Chandra.

From: scap-dev@nist.gov<mailto:scap-dev@nist.gov> [mailto:scap-dev@nist.gov=
]<mailto:[mailto:scap-dev@nist.gov]> On Behalf Of Kent_Landfield@mcafee.com=
<mailto:Kent_Landfield@mcafee.com>
Sent: Friday, May 11, 2012 10:14 PM
To: Multiple recipients of list
Subject: Request for participants - Content Repository Specification Develo=
pment

Mike I love it when you tee something up like that.... ;-)  Thank you. ;)

Mike wrote:
I still think that any specification for a repository is wishful thinking u=
ntil someone builds one and learns the lessons it will just be another whit=
epaper spec.  I believe the DoD needs to incorporate a metadata repository =
as part of it and other customizations that may not be useful for everyone.
We need to talk more...

If you are talking about a holistic, complete federated approach to a conte=
nt repository, I some what agree.  If you are talking about an organization=
al repository, I totally disagree. But you knew I would. ;)

Here is how I see the problem.  There is an immediate need for SCAP and oth=
er related content to be served up inside an organization.  Today we have s=
ituation where the standards allow us to provide sites the capability to ha=
ve a single SCAP implemented policy they call official for their environmen=
t. Yes this is a rather simplistic since there are things such as targeting=
 specific platforms, specific operational use needs, but for now lets agree=
 SCAP is a massive improvement over the proprietary situations of the past.=
 While we have created this standard content so that sites can implement th=
eir local site security once and then assure they are measuring all appropr=
iately targeted devices the same way, we have failed to support the operati=
onal needs of the sites.  We have a situation where no two vendors distribu=
te content the same way.  This causes massive problems for the administrati=
on staff when they need to incorporate a new SCAP enabled product into thei=
r architecture.  They need to discover how the new product supports distrib=
uting SCAP content to it's various components.  If they have one product th=
en they do this one and they are done.  If they have multiple products they=
 will have to figure out how to minimize the impact by incorporating the up=
date process for the new product into the existing SCAP security content pr=
ocesses. Now when the inevitable happens and the site staff needs to make a=
 change to their security policy, they have to make the modifications to th=
e benchmark or checks or both and then distribute those updates across thei=
r network.  For each SCAP enabled product they have in place, they have dou=
bled, tripled or more the work needed to make those updates available.

There is another content repository problem and that is the Federated Conte=
nt Distribution.  If you think global DNS you have a general frame of refer=
ence.  The guidance authors need to be able to publish content in an author=
itative manner so their content is updated in a timely fashion.  This is a =
much harder problem to solve if there is no local organizational infrastruc=
ture to support it. ;)

So here is what I am thinking...  We should consider addressing these as tw=
o separate but integrated efforts.  I believe the Organizational Content Re=
pository is the more critical piece that is actually easier to address.  Th=
e Federated Content Distribution should be a subsequent effort integrating =
/ augmenting the Organizational repository specification.

Mike, to your point that we need someone to build one first... That has hap=
pened already.  I have one as do other vendors but what we don't have is th=
e access specification.  Ours are focused on our specific product needs.  A=
dditionally there is a company that has developed a commercial SCAP content=
 repository that will be announced later this month. I won't steal their th=
under but I was recently given a sneak peek at it and I must admit I was ve=
ry impressed.  Again, to your point, it has been done. What is needed to ad=
dress the initial operational problem is to develop a specification that pr=
ovides a consistent means for all SCAP products to retrieve the appropriate=
 content as configured and managed but the site.

TO THAT END....

I am requesting participation from those in the community that see the need=
 and want to put in the work to make this specification happen.  I have tal=
ked to a couple of you but I do not want to assume your participation.  If =
you are interested please contact me so we can get this started.

Thanks!

Kent Landfield
Director Content Strategy, Architecture and Standards

McAfee | An Intel Company
5000 Headquarters Dr.
Plano, Texas 75024

Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: <Kinney>, Michael A <m.kinne@radium.ncsc.mil<mailto:m.kinne@radium.nc=
sc.mil>>
To: David Waltermire <david.waltermire@nist.gov<mailto:david.waltermire@nis=
t.gov>>, SCAP-DEV <SCAP-DEV@nist.gov<mailto:SCAP-DEV@nist.gov>>, "sacm@ietf=
org<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.org>>
Subject: Re: [sacm] [OVAL-DEVELOPER-LIST] Security Automation Developer Day=
s: Summer 2012 at MITRE in Bedford, MA

Dave,
I have no problem with webinars, I do want to keep developer days actionabl=
e and use it to make decisions, and vote and accomplish things good or bad.=
  I do not want this to be an informational briefing conference.
Thanks for the links.

I still think that any specification for a repository is wishful thinking u=
ntil someone builds one and learns the lessons it will just be another whit=
epaper spec.  I believe the DoD needs to incorporate a metadata repository =
as part of it and other customizations that may not be useful for everyone.
We need to talk more...

-Mike

From: Waltermire, David A. [mailto:david.waltermire@nist.gov]
Sent: Tuesday, May 08, 2012 10:44 AM
To: Kinney, Michael A; SCAP-DEV; sacm@ietf.org<mailto:sacm@ietf.org>
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summ=
er 2012 at MITRE in Bedford, MA

Mike,

What about having webinars in-place of the 30 minute briefs?

Regarding content management, we are building the prototype content reposit=
ory for use in a production environment.  As an open source project, it wil=
l be free for use by anyone interested.  My thinking is that this project c=
an bridge the gap until commercial solutions are available to augment it.  =
This is a similar path that was followed with DNS (bind) and HTTP (apache).=
  When it is ready for use, I am hoping to use it to host USGCB content.  Y=
ou would be welcome to use it for your needs.

It is good that OCIL is moving forward.  This is an important piece of supp=
orting risk management and aspects of continuous monitoring.  I would also =
like to see some discussion on OCIL at Developer Days.  With the proposals =
we will likely have a sense of what needs to be discussed and what we can a=
chieve consensus on outside the meeting.

Remediation is a topic near and dear to my heart.  I too would like to see =
it move forward.

We just published the draft ASR specification for public comment.  This spe=
cification supports enterprise aggregate reporting which greatly reduces th=
e data volumes needed verses detailed host-based reports. This specificatio=
n has been designed as a more robust replacement for LASR  It can be used i=
n continuous monitoring applications to support aggregate data reporting ne=
eds (e.g. FISMA reporting,  CyberScope).

Here are the links:

http://csrc.nist.gov/publications/PubsDrafts.html
http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848

The primary reason we have suggested waiting on XCCDF is not the internatio=
nalization issue. Many vendors have commented that they are still working o=
n implementing the XCCDF 1.2.1 specification. We will be in a better place =
in a few months once more development around XCCDF has occurred.  As we con=
sider changes to the SCAP stack to address OCIL and other issues, we will i=
dentify areas that need improvement in XCCDF.  These are good and necessary=
 discussions to have now, but we have a good deal of work to do before we a=
re ready to open up XCCDF.  My suggestion is to work on these related areas=
 and then work up change proposals for XCCDF as needed.  By that time we sh=
ould be ready to work on a new revision of XCCDF.

I am also looking forward to the discussions at the conference.  It has bee=
n too long.

Sincerely,
Dave

From: Kinney, Michael A [mailto:m.kinne@radium.ncsc.mil<mailto:m.kinne@radi=
um.ncscmil>]
Sent: Tuesday, May 08, 2012 7:09 AM
To: SCAP-DEV
Cc: Waltermire, David A.
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summ=
er 2012 at MITRE in Bedford, MA

Kent,

It's good to read your thoughts, and a realistic actionable approach is ind=
eed needed  Since all the activity hasn't been on the lists a brief 1=AE2 h=
our recap may be in order to bring everyone up to speed since there has bee=
n a lot of activity on CPE/SWID, OCIl, MAEC/CybOX CEE and others.

We could write a content repository specification, but without someone will=
ing to stand one up it will be as valuable as the CCSS specification is tod=
ay.  I've been trying for two years to get my management to get a coordinat=
ed effort together for the DoD to stand up a repository, it is a tough prob=
lem and will require funding with a tail, I'm not sure a specification will=
 solve that problem.

We (DoD) have been putting a lot of effort into OCIL over the last year try=
ing to make it useful in an enterprise environment and will be posting our =
ideas to the list before developer days it should have already started, we =
need to get consensus and a vote on how the community wishes to proceed.

Remediation is stalled but I'm making every effort to get it kick started f=
rom our perspective. I hope to assist in getting the draft ERI finished thi=
s year.  We are writing some new STIG content and intend to used the draft =
CRE specification to insert CRE into the content so we (DoD) can do some au=
tomatic configuration fixes, part of a self healing network concept. It is =
just a start but the best we can do at this point.

Enterprise reporting is an interesting subject, since XML adds size to and =
content to roll up reporting, in any enterprise of size the problem gets gr=
eater, I look forward to your thoughts on that subject.

I am concerned that the internationalization efforts are detracting from ef=
forts to meet use cases, we have some things we would like changed in XCCDF=
 to support our OCIl use case and I have been told that I need to wait. I d=
idn't think that a move to internationalization should impede efforts to mo=
ve forward with use cases.

I look forward to talking with you at the conference.

v/r

Mike Kinney
Project Director
Computer Network Defense Research and Technology (CND R&T) Office
9800 Savage Road Ste 6767
Ft Meade, MD 20755-6767
Phone: 410-854-4422
NSTS: 968-8886
Fax 410-854-4681
makinn2@nsa.gov<mailto:M.kinne@radium.ncsc.mil>



From:scap-dev@nist.gov<mailto:scap-dev@nist.gov> [mailto:scap-dev@nist.gov]=
<mailto:[mailto:scap-dev@nist.gov]> On Behalf Of Waltermire, David A.
Sent: Monday, May 07, 2012 7:09 PM
To: Multiple recipients of list
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summ=
er 2012 at MITRE in Bedford, MA

Kent,

I like what you are saying here.  We are also in support of this type of ap=
proach.  We would like to see some community discussion around what are the=
 key areas/priorities that the community would like to see discussed at Dev=
 Days.  Your topics below look like a good start. The SACM list might be a =
better venue than the OVAL list for this discussion.  For each area we shou=
ld focus the discussion around developing objectives for each session.  The=
 sessions can be time boxed based on what would be a reasonable amount of t=
ime to accomplish each objective.  For example if continuous monitoring is =
a priority and collectively it takes 3 days to work through all the objecti=
ves, I see no problem with that.  We can also keep a few sessions "on deck"=
 if all the objectives are reached and we complete all the scheduled sessio=
ns early.

Thoughts?

Sincerely,

David Waltermire
SCAP Architect
National Institute of Standards and Technology
(301) 975-3390
david.waltermire@nist.gov<mailto:david.waltermire@nist.gov>

From:scap-dev@nist.gov<mailto:scap-dev@nist.gov> [mailto:scap-dev@nist.gov]=
<mailto:[mailto:scap-dev@nist.gov]> On Behalf Of Kent_Landfield@mcafee.com<=
mailto:Kent_Landfield@mcafee.com>
Sent: Monday, May 07, 2012 4:25 PM
To: SCAP-DEV
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summ=
er 2012 at MITRE in Bedford, MA

All,

I would like to discuss the format for the SCAP Developer Days that seems t=
o be listed below.

I see this appears to follow a path we have discussed in the past as the wa=
y not to hold a Dev Days event.  We have been trying to get away from 'Deat=
h by Powerpoint' and back to the type of event we held years ago when we we=
re highly productive.  In the past we had a topic to be discussed and a tim=
e box to work within.  That allowed us to have very active brainstorming se=
ssions in a high bandwidth environment.

At past Summer events we have got into a pattern of lots of powerpoint, lot=
s of status of the efforts and very little discussion about things that nee=
d active discussions.  We need to keep moving forward and making progress a=
s an effort. We can get status from various places such as the lists, a pre=
sentation being sent out in advance, a webinar if it is felt there will be =
questions and answers from those that are new to the efforts.  We have a li=
mited amount of time and all who are attending are investing a great deal o=
f time and money to be there.  We should not  be spending a great deal of t=
ime reeducating everyone when we could be focused on advancing needed effor=
ts.

The type of approach to a Dev Days event was discussed at the last Summer D=
ev Days.  I have seen the following work quite well in other efforts.

 1.  Presentations are sent out to the attendees and the lists a week in ad=
vance
 2.  Status for any effort is limited to 30 minutes
 3.  Focused brainstorming time should be established for certain areas tha=
t need real work by the community
 4.  Efforts to be discussed should be based on needs of the security autom=
ation space to move existing efforts to completion.
For example:

Continuous monitoring is a major direction the efforts are becoming involve=
d with. There are going to be things we need to do as a security automation=
 community to be able to accomplish what is listed in the CAESARS FE.  Ther=
e are interfaces that need to be worked and established.  That is one area =
that is not listed below.  CM will have a major impact on all of us in the =
next couple years and it is being ignored.  We can't keep trying to solve w=
hat has already been solved.  We need to address the needed interface devel=
opment now. This is an effort that could take nearly a whole day by itself.

Operationally we have a real need to be able to deliver SCAP content intern=
ally within an organization. Today the SCAP vendors cannot share a single l=
ocal site security policy (XCCDF + OVAL + CPE +...) without the site staff =
having to go to each of the individual products and figuring out how to inj=
ect that new or updated policy into that products delivery mechanisms.  Tha=
t is limiting sites from wanting to buy multiple focused SCAP products sinc=
e they are such a pain to manage from a content perspective.  It is easier =
to buy from one vendor that has a single means for distributing content tha=
n it is to deal with the management issues that having multiple SCAP produc=
ts presents.  We need to have at least an entire 1/2 a day on the developme=
nt of a Content Repository specification.

OCIL is a positive and a negative at the same time. It has real value that =
is being underutilized and under implemented because of the limitations of =
how it addresses uses in an enterprise environment.  People don't need secu=
rity automation to do things on/for a single host.  They need security auto=
mation to focus on the enterprise issues that reduce their costs and improv=
e their efficiencies.  OCIL is failing in the enterprise and we all underst=
and that.  We need to address developing a definitive solution for incorpor=
ating OCIL into the enterprise and that means into the existing specificati=
ons. Scheduling and tracking are key to it's success.  We need to make that=
 happen.  This too needs a focused brainstorming time box to discuss option=
s.

I am really disappointed that Remediation is not on the list below...  Yes,=
 last Summer Dev Days, the time spent on Remediation was wasted time but th=
at does not mean we should ignore it and not try to make some real progress=
.  As far as I am concerned we need to reboot the remediation effort.  We c=
annot keep being the set of specifications / tools that act as the little b=
oy crying "Wolf" in the night.  We need to be able to find and fix issues i=
f we are going to really make a difference in organizational security postu=
res.  But today we think it is too hard so we don't try ?  I think we need =
a couple hours to discuss the reboot of the effort even if that means minim=
izing work already done.

A focused discussion on enterprise reporting is also critically needed.  Fo=
r the vendors here, we have all gone through the Cyberscope goat rope, deli=
vering limited capabilities to specific data call requirements of the Feder=
al Agencies.  The initial effort was a mess, did little more than prove it =
was possible and cause the vendor community a great deal of thrashing to pu=
t a kludgey 'solution' in place.  Reality is all our customers need roll up=
 reporting and an infrastructure that supports it.  A data call should not =
be special to anyone other than the agencies responding. The tools should b=
e able to select the types of data needed and deliver that on a scheduled b=
asis automatically.    Enterprise Reporting pertains to commercial as well =
as Federal customers.  We need to focus some time on what that would look l=
ike using the ARF and ASR as the foundational pieces.  But there are missin=
g pieces....  We need this discussed.

I would hope we can make this summer's SCAP Dev Days useful in advancing th=
e security automation efforts by addressing some of the more critical issue=
s our customers are facing now or will be facing in the very short term.  S=
tatus presentations are not interesting to those active in the efforts.  Le=
t's try to do those before we get to Bedford so we can real make some progr=
ess while we are all in the same room.  This is always a big event for the =
'consensus of the willing' that assemble and driven to see security automat=
ion make a difference.  Let's see if we can have an event that, when we all=
 walk out the last day, we all feel that every minute was well spent and mo=
ves us forward.

Thanks.

Kent Landfield
Director Content Strategy, Architecture and Standards

McAfee | An Intel Company
5000 Headquarters Dr.
Plano, Texas 75024

Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: <Boczenowski>, Steve <sboczeno@MITRE.ORG<mailto:sboczeno@MITRE.ORG>>
Reply-To: "OVAL Developer List (Closed Public Discussion)" <OVAL-DEVELOPER-=
LIST@LISTS.MITRE.ORG<mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG>>
To: "OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG<mailto:OVAL-DEVELOPER-LIST@LISTS.M=
ITRE.ORG>" <OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG<mailto:OVAL-DEVELOPER-LIST@=
LISTS.MITRE.ORG>>
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summ=
er 2012 at MITRE in Bedford, MA

Frank;

We hope to have the registration site up next week.  The event will be duri=
ng the week of July 9 - starting Monday at 10:00 AM and ending on Friday at=
 12:00.

Meanwhile, we are working on the agenda and are currently considering this =
list of topics:

CCE
CPE/SWID
CEE
XCCDF
OVAL
ASR
Enterprise OCIL
CybOX/MAEC
Federated Content Repository Spec
Endpoint Reporting for Continuous Monitoring and Compliance (ERCC)
MILE
TAXII
IF-M for SCAP
IF-MAP
SCAP Releases
SCAP and IETF
NETCONF and SCAP

Steve

From: Frank Lindsay Acker [mailto:afrank@NOVA.EDU]
Sent: Tuesday, May 01, 2012 9:32 AM
To: oval-developer-list OVAL Developer List/Closed Public Discussion
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summ=
er 2012 at MITRE in Bedford, MA

Steve....

Has there been any additional information regarding this event?

Thanks,
Frank Acker
________________________________
From: Boczenowski, Steve [sboczeno@MITRE.ORG<mailto:sboczeno@MITRE.ORG>]
Sent: Tuesday, March 20, 2012 16:38
To: OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG<mailto:OVAL-DEVELOPER-LIST@LISTS.MI=
TRE.ORG>
Subject: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2=
012 at MITRE in Bedford, MA
Save the Date: week of July 9, 2012

This year's MITRE-hosted Security Automation Developer Days event will be h=
eld during the week of July 9, 2012 at MITRE's facility in Bedford, MA.

Details to follow.

Regards,
    Steve

______________________________________________
Stephen P. Boczenowski
      The MITRE Corporation
      Office: (781) 271-7682
      Cell: (978) 302-3849
     sboczeno@mitre.org<mailto:sboczeno@mitre.org>

To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG<mailto:LI=
STSERV@LISTS.MITRE.ORG> with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the=
 message. If you have difficulties, write to OVAL-DEVELOPER-LIST-request@LI=
STS.MITRE.ORG<mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG>.
To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG<mailto:LI=
STSERV@LISTS.MITRE.ORG> with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the=
 message. If you have difficulties, write to OVAL-DEVELOPER-LIST-request@LI=
STS.MITRE.ORG<mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG>.
To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG<mailto:LI=
STSERV@LISTS.MITRE.ORG> with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the=
 message. If you have difficulties, write to OVAL-DEVELOPER-LIST-request@LI=
STS.MITRE.ORG<mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG>.

--_000_D7A0423E5E193F40BE6E94126930C4930B9BA83FFDMBCLUSTERxcha_
Content-Type: text/html; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

<META HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; charset=3Diso-8859-=
2">
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40"><head><meta name=3DGenerator content=3D"Microso=
ft Word 14 (filtered medium)"><!--[if !mso]><style>v\:* {behavior:url(#defa=
ult#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:MITRE;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
p.msochpdefault, li.msochpdefault, div.msochpdefault
	{mso-style-name:msochpdefault;
	mso-style-priority:99;
	margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Calibri","sans-serif";}
span.apple-style-span
	{mso-style-name:apple-style-span;}
span.emailstyle17
	{mso-style-name:emailstyle17;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.EmailStyle23
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle24
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle25
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle26
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle27
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle28
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle30
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:118182839;
	mso-list-template-ids:-776844468;}
@list l0:level1
	{mso-level-tab-stop:.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level2
	{mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level4
	{mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level7
	{mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1
	{mso-list-id:794830398;
	mso-list-template-ids:-992022086;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue vli=
nk=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span style=3D'c=
olor:#1F497D'>I am not sure how to use the search page properly.=A0 Would y=
ou please provide some example searches?<o:p></o:p></span></p><p class=3DMs=
oNormal><span style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><p c=
lass=3DMsoNormal><span style=3D'color:#1F497D'>Sincerely,<o:p></o:p></span>=
</p><p class=3DMsoNormal><span style=3D'color:#1F497D'>Dave<o:p></o:p></spa=
n></p></div><p class=3DMsoNormal><span style=3D'color:#1F497D'><o:p>&nbsp;<=
/o:p></span></p><div><div style=3D'border:none;border-top:solid #B5C4DF 1.0=
pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span style=3D'font-s=
ize:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span style=
=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> sacm-bounces@ietf.=
org [mailto:sacm-bounces@ietf.org] <b>On Behalf Of </b>Chandrashekhar B<br>=
<b>Sent:</b> Thursday, June 14, 2012 4:10 PM<br><b>To:</b> SCAP-DEV; sacm@i=
etf.org<br><b>Subject:</b> Re: [sacm] Request for participants - Content Re=
pository Specification Development<o:p></o:p></span></p></div></div><p clas=
s=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><span style=3D'colo=
r:#1F497D'>We have hosted our SCAP Content Repository at <a href=3D"http://=
www.scaprepo.com">www.scaprepo.com</a>. Feedback is certainly appreciated. =
A simple web service interface will be published soon.<o:p></o:p></span></p=
><p class=3DMsoNormal><span style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span=
></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>Chandra.<o:p></o:p>=
</span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'><o:p>&nbsp;</=
o:p></span></p><div><div style=3D'border:none;border-top:solid #B5C4DF 1.0p=
t;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span style=3D'font-si=
ze:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></b><span style=3D=
'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> <a href=3D"mailto:sca=
p-dev@nist.gov">scap-dev@nist.gov</a> <a href=3D"mailto:[mailto:scap-dev@ni=
st.gov]">[mailto:scap-dev@nist.gov]</a> <b>On Behalf Of </b><a href=3D"mail=
to:Kent_Landfield@mcafee.com">Kent_Landfield@mcafee.com</a><br><b>Sent:</b>=
 Friday, May 11, 2012 10:14 PM<br><b>To:</b> Multiple recipients of list<br=
><b>Subject:</b> Request for participants - Content Repository Specificatio=
n Development<o:p></o:p></span></p></div></div><p class=3DMsoNormal><o:p>&n=
bsp;</o:p></p><div><div><div><p class=3DMsoNormal><span style=3D'color:blac=
k'>Mike I love it when you tee something up like that&#8230;. ;-) &nbsp;Tha=
nk you. ;)<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span style=
=3D'color:black'><o:p>&nbsp;</o:p></span></p></div><div><p class=3DMsoNorma=
l><span style=3D'color:#1F497D'>Mike wrote:&nbsp;</span><span style=3D'colo=
r:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1=
F497D'>I still think that any specification for a repository is wishful thi=
nking until someone builds one and learns the lessons it will just be anoth=
er whitepaper spec. &nbsp;I believe the DoD needs to incorporate a metadata=
 repository as part of it and other customizations that may not be useful f=
or everyone.</span><span style=3D'color:black'><o:p></o:p></span></p><p cla=
ss=3DMsoNormal><span style=3D'color:#1F497D'>We need to talk more&#8230;</s=
pan><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal>=
<span style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNorma=
l><span style=3D'color:black'>If you are talking about a holistic, complete=
 federated approach to a content repository, I some what agree. &nbsp;If yo=
u are talking about an organizational repository, I totally disagree. But y=
ou knew I would. ;)</span><span style=3D'font-size:12.0pt;font-family:"Time=
s New Roman","serif";color:black'><o:p></o:p></span></p><p class=3DMsoNorma=
l><span style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNor=
mal><span style=3D'color:black'>Here is how I see the problem. &nbsp;There =
is an immediate need for SCAP and other related content to be served up ins=
ide an organization. &nbsp;Today we have situation where the standards allo=
w us to provide sites the capability to have a single SCAP implemented poli=
cy they call official for their environment. Yes this is a rather simplisti=
c since there are things such as targeting specific platforms, specific ope=
rational use needs, but for now lets agree SCAP is a massive improvement ov=
er the proprietary situations of the past. While we have created this stand=
ard content so that sites can implement their local site security once and =
then assure they are measuring all appropriately targeted devices the same =
way, we have failed to support the operational needs of the sites. &nbsp;We=
 have a situation where no two vendors distribute content the same way. &nb=
sp;This causes massive problems for the administration staff when they need=
 to incorporate a new SCAP enabled product into their architecture. &nbsp;T=
hey need to discover how the new product supports distributing SCAP content=
 to it's various components. &nbsp;If they have one product then they do th=
is one and they are done. &nbsp;If they have multiple products they will ha=
ve to figure out how to minimize the impact by incorporating the update pro=
cess for the new product into the existing SCAP security content processes.=
 Now when the inevitable happens and the site staff needs to make a change =
to their security policy, they have to make the modifications to the benchm=
ark or checks or both and then distribute those updates across their networ=
k. &nbsp;For each SCAP enabled product they have in place, they have double=
d, tripled or more the work needed to make those updates available.&nbsp;<o=
:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:black'><o:p>&=
nbsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'color:black'>Ther=
e is another content repository problem and that is the Federated Content D=
istribution. &nbsp;If you think global DNS you have a general frame of refe=
rence. &nbsp;The guidance authors need to be able to publish content in an =
authoritative manner so their content is updated in a timely fashion. &nbsp=
;This is a much harder problem to solve if there is no local organizational=
 infrastructure to support it. ;)<o:p></o:p></span></p><p class=3DMsoNormal=
><span style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNorm=
al><span style=3D'color:black'>So here is what I am thinking&#8230; &nbsp;W=
e should consider addressing these as two separate but integrated efforts. =
&nbsp;I believe the Organizational Content Repository is the more critical =
piece that is actually easier to address. &nbsp;The Federated Content Distr=
ibution should be a subsequent effort integrating / augmenting the Organiza=
tional repository specification.&nbsp;<o:p></o:p></span></p><p class=3DMsoN=
ormal><span style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p class=3DMs=
oNormal><span style=3D'color:black'>Mike, to your point that we need someon=
e to build one first&#8230; That has happened already. &nbsp;I have one as =
do other vendors but what we don&#8217;t have is the access specification. =
&nbsp;Ours are focused on our specific product needs. &nbsp;Additionally th=
ere is a company that has developed a commercial SCAP content repository th=
at will be announced later this month. I won't steal their thunder but I wa=
s recently given a sneak peek at it and I must admit I was very impressed. =
&nbsp;Again, to your point, it has been done. What is needed to address the=
 initial operational problem is to develop a specification that provides a =
consistent means for all SCAP products to retrieve the appropriate content =
as configured and managed but the site. &nbsp;<o:p></o:p></span></p><p clas=
s=3DMsoNormal><span style=3D'color:black'><o:p>&nbsp;</o:p></span></p><p cl=
ass=3DMsoNormal style=3D'margin-bottom:1.0pt'><span style=3D'color:black'>T=
O THAT END&#8230;.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D=
'color:black'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span style=
=3D'color:black'>I am requesting participation from those in the community =
that see the need and want to put in the work to make this specification ha=
ppen. &nbsp;I have talked to a couple of you but I do not want to assume yo=
ur participation. &nbsp;If you are interested please contact me so we can g=
et this started.&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span styl=
e=3D'color:black'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span st=
yle=3D'color:black'>Thanks!<o:p></o:p></span></p><p class=3DMsoNormal><span=
 style=3D'color:black'><o:p>&nbsp;</o:p></span></p></div><div><div><p class=
=3DMsoNormal><strong><span style=3D'font-size:9.0pt;font-family:"Arial","sa=
ns-serif";color:#606A71'>Kent Landfield</span></strong><span style=3D'font-=
size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'><br><span class=
=3Dapple-style-span>Director Content Strategy, Architecture and Standards</=
span><br><br><strong><span style=3D'font-family:"Arial","sans-serif"'>McAfe=
e | An Intel Company</span></strong><br><span class=3Dapple-style-span>5000=
 Headquarters Dr.</span><br><span class=3Dapple-style-span>Plano, Texas 750=
24</span><br><br><span class=3Dapple-style-span>Direct: +1.972.963.7096&nbs=
p;</span><br><span class=3Dapple-style-span>Mobile: +1.817.637.8026</span><=
br><strong><span style=3D'font-family:"Arial","sans-serif"'>Web:&nbsp;</spa=
n></strong><span class=3Dapple-style-span><a href=3D"http://www.mcafee.com/=
">www.mcafee.com</a></span></span><span style=3D'color:black'><o:p></o:p></=
span></p></div></div></div></div><div><p class=3DMsoNormal><span style=3D'c=
olor:black'><o:p>&nbsp;</o:p></span></p></div><div style=3D'border:none;bor=
der-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal=
><b><span style=3D'color:black'>From: </span></b><span style=3D'color:black=
'>&lt;Kinney&gt;, Michael A &lt;<a href=3D"mailto:m.kinne@radium.ncsc.mil">=
m.kinne@radium.ncsc.mil</a>&gt;<br><b>To: </b>David Waltermire &lt;<a href=
=3D"mailto:david.waltermire@nist.gov">david.waltermire@nist.gov</a>&gt;, SC=
AP-DEV &lt;<a href=3D"mailto:SCAP-DEV@nist.gov">SCAP-DEV@nist.gov</a>&gt;, =
&quot;<a href=3D"mailto:sacm@ietf.org">sacm@ietforg</a>&quot; &lt;<a href=
=3D"mailto:sacm@ietf.org">sacm@ietf.org</a>&gt;<br><b>Subject: </b>Re: [sac=
m] [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2012 at=
 MITRE in Bedford, MA<o:p></o:p></span></p></div><div><p class=3DMsoNormal>=
<span style=3D'font-size:12.0pt;font-family:"Times New Roman","serif";color=
:black'><o:p>&nbsp;</o:p></span></p></div><blockquote style=3D'border:none;=
border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75p=
t;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt' id=3D"MAC_OUTLOOK_=
ATTRIBUTION_BLOCKQUOTE"><div><div><p class=3DMsoNormal><span style=3D'color=
:#1F497D'>Dave,</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>I have no problem with webi=
nars, I do want to keep developer days actionable and use it to make decisi=
ons, and vote and accomplish things good or bad.&nbsp; I do not want this t=
o be an informational briefing conference.</span><span style=3D'color:black=
'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>=
Thanks for the links.</span><span style=3D'color:black'><o:p></o:p></span><=
/p><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span st=
yle=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=
=3D'color:#1F497D'>I still think that any specification for a repository is=
 wishful thinking until someone builds one and learns the lessons it will j=
ust be another whitepaper spec. &nbsp;I believe the DoD needs to incorporat=
e a metadata repository as part of it and other customizations that may not=
 be useful for everyone.</span><span style=3D'color:black'><o:p></o:p></spa=
n></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>We need to talk mo=
re&#8230;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=
=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'colo=
r:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1=
F497D'>-Mike&nbsp; </span><span style=3D'color:black'><o:p></o:p></span></p=
><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span styl=
e=3D'color:black'><o:p></o:p></span></p><div><div style=3D'border:none;bord=
er-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal>=
<b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:=
black'>From:</span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma"=
,"sans-serif";color:black'> Waltermire, David A. [<a href=3D"mailto:david.w=
altermire@nist.gov">mailto:david.waltermire@nist.gov</a>] <br><b>Sent:</b> =
Tuesday, May 08, 2012 10:44 AM<br><b>To:</b> Kinney, Michael A; SCAP-DEV; <=
a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br><b>Subject:</b> RE: [O=
VAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2012 at MITR=
E in Bedford, MA</span><span style=3D'color:black'><o:p></o:p></span></p></=
div></div><p class=3DMsoNormal><span style=3D'color:black'>&nbsp;<o:p></o:p=
></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>Mike,</span>=
<span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><spa=
n style=3D'color:#1F497D'>&nbsp;</span><span style=3D'color:black'><o:p></o=
:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>What about=
 having webinars in-place of the 30 minute briefs?</span><span style=3D'col=
or:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#=
1F497D'>&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p c=
lass=3DMsoNormal><span style=3D'color:#1F497D'>Regarding content management=
, we are building the prototype content repository for use in a production =
environment.&nbsp; As an open source project, it will be free for use by an=
yone interested.&nbsp; My thinking is that this project can bridge the gap =
until commercial solutions are available to augment it.&nbsp; This is a sim=
ilar path that was followed with DNS (bind) and HTTP (apache).&nbsp; When i=
t is ready for use, I am hoping to use it to host USGCB content.&nbsp; You =
would be welcome to use it for your needs.</span><span style=3D'color:black=
'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>=
&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DM=
soNormal><span style=3D'color:#1F497D'>It is good that OCIL is moving forwa=
rd.&nbsp; This is an important piece of supporting risk management and aspe=
cts of continuous monitoring.&nbsp; I would also like to see some discussio=
n on OCIL at Developer Days.&nbsp; With the proposals we will likely have a=
 sense of what needs to be discussed and what we can achieve consensus on o=
utside the meeting.</span><span style=3D'color:black'><o:p></o:p></span></p=
><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span styl=
e=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D=
'color:#1F497D'>Remediation is a topic near and dear to my heart.&nbsp; I t=
oo would like to see it move forward.</span><span style=3D'color:black'><o:=
p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp=
;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNor=
mal><span style=3D'color:#1F497D'>We just published the draft ASR specifica=
tion for public comment.&nbsp; This specification supports enterprise aggre=
gate reporting which greatly reduces the data volumes needed verses detaile=
d host-based reports. This specification has been designed as a more robust=
 replacement for LASR&nbsp; It can be used in continuous monitoring applica=
tions to support aggregate data reporting needs (e.g. FISMA reporting, &nbs=
p;CyberScope).</span><span style=3D'color:black'><o:p></o:p></span></p><p c=
lass=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'=
color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'colo=
r:#1F497D'>Here are the links:</span><span style=3D'color:black'><o:p></o:p=
></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span=
><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><sp=
an style=3D'color:#1F497D'><a href=3D"http://csrc.nist.gov/publications/Pub=
sDrafts.html">http://csrc.nist.gov/publications/PubsDrafts.html</a></span><=
span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span=
 style=3D'color:#1F497D'><a href=3D"http://csrc.nist.gov/publications/PubsN=
ISTIRs.html#NIST-IR-7848">http://csrc.nist.gov/publications/PubsNISTIRs.htm=
l#NIST-IR-7848</a></span><span style=3D'color:black'><o:p></o:p></span></p>=
<p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=
=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'=
color:#1F497D'>The primary reason we have suggested waiting on XCCDF is not=
 the internationalization issue. Many vendors have commented that they are =
still working on implementing the XCCDF 1.2.1 specification. We will be in =
a better place in a few months once more development around XCCDF has occur=
red.&nbsp; As we consider changes to the SCAP stack to address OCIL and oth=
er issues, we will identify areas that need improvement in XCCDF.&nbsp; The=
se are good and necessary discussions to have now, but we have a good deal =
of work to do before we are ready to open up XCCDF.&nbsp; My suggestion is =
to work on these related areas and then work up change proposals for XCCDF =
as needed.&nbsp; By that time we should be ready to work on a new revision =
of XCCDF.</span><span style=3D'color:black'><o:p></o:p></span></p><p class=
=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'colo=
r:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1=
F497D'>I am also looking forward to the discussions at the conference.&nbsp=
; It has been too long.</span><span style=3D'color:black'><o:p></o:p></span=
></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><div><p class=3DMsoNormal><span=
 style=3D'color:#1F497D'>Sincerely,</span><span style=3D'color:black'><o:p>=
</o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>Dave</s=
pan><span style=3D'color:black'><o:p></o:p></span></p></div><p class=3DMsoN=
ormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'color:black=
'><o:p></o:p></span></p><div><div style=3D'border:none;border-top:solid #B5=
C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span style=
=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>From:</=
span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";=
color:black'> Kinney, Michael A [<a href=3D"mailto:m.kinne@radium.ncscmil">=
mailto:m.kinne@radium.ncsc.mil</a>] <br><b>Sent:</b> Tuesday, May 08, 2012 =
7:09 AM<br><b>To:</b> SCAP-DEV<br><b>Cc:</b> Waltermire, David A.<br><b>Sub=
ject:</b> RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Sum=
mer 2012 at MITRE in Bedford, MA</span><span style=3D'color:black'><o:p></o=
:p></span></p></div></div><p class=3DMsoNormal><span style=3D'color:black'>=
&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F49=
7D'>Kent,</span><span style=3D'color:black'><o:p></o:p></span></p><p class=
=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'colo=
r:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1=
F497D'>It&#8217;s good to read your thoughts, and a realistic actionable ap=
proach is indeed needed &nbsp;Since all the activity hasn&#8217;t been on t=
he lists a brief 1=AE2 hour recap may be in order to bring everyone up to s=
peed since there has been a lot of activity on CPE/SWID, OCIl, MAEC/CybOX C=
EE and others.</span><span style=3D'color:black'><o:p></o:p></span></p><p c=
lass=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'=
color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'colo=
r:#1F497D'>We could write a content repository specification, but without s=
omeone willing to stand one up it will be as valuable as the CCSS specifica=
tion is today. &nbsp;I&#8217;ve been trying for two years to get my managem=
ent to get a coordinated effort together for the DoD to stand up a reposito=
ry, it is a tough problem and will require funding with a tail, I&#8217;m n=
ot sure a specification will solve that problem.</span><span style=3D'color=
:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F=
497D'>&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p cla=
ss=3DMsoNormal><span style=3D'color:#1F497D'>We (DoD) have been putting a l=
ot of effort into OCIL over the last year trying to make it useful in an en=
terprise environment and will be posting our ideas to the list before devel=
oper days it should have already started, we need to get consensus and a vo=
te on how the community wishes to proceed.</span><span style=3D'color:black=
'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>=
&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DM=
soNormal><span style=3D'color:#1F497D'>Remediation is stalled but I&#8217;m=
 making every effort to get it kick started from our perspective. I hope to=
 assist in getting the draft ERI finished this year. &nbsp;We are writing s=
ome new STIG content and intend to used the draft CRE specification to inse=
rt CRE into the content so we (DoD) can do some automatic configuration fix=
es, part of a self healing network concept. It is just a start but the best=
 we can do at this point.</span><span style=3D'color:black'><o:p></o:p></sp=
an></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><spa=
n style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span st=
yle=3D'color:#1F497D'>Enterprise reporting is an interesting subject, since=
 XML adds size to and content to roll up reporting, in any enterprise of si=
ze the problem gets greater, I look forward to your thoughts on that subjec=
t.</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNo=
rmal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'color:black'=
><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>I=
 am concerned that the internationalization efforts are detracting from eff=
orts to meet use cases, we have some things we would like changed in XCCDF =
to support our OCIl use case and I have been told that I need to wait. I di=
dn&#8217;t think that a move to internationalization should impede efforts =
to move forward with use cases.</span><span style=3D'color:black'><o:p></o:=
p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</spa=
n><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><s=
pan style=3D'color:#1F497D'>I look forward to talking with you at the confe=
rence.</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DM=
soNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'color:bl=
ack'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:10=
.0pt;font-family:"Arial","sans-serif";color:#1F497D'>v/r</span><span style=
=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'=
font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'>&nbsp;</sp=
an><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><=
span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F49=
7D'>Mike Kinney</span><span style=3D'color:black'><o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:10.0pt;font-family:"Arial","sans=
-serif";color:#1F497D'>Project Director</span><span style=3D'color:black'><=
o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:10.0pt;f=
ont-family:"Arial","sans-serif";color:#1F497D'>Computer Network Defense Res=
earch and Technology (CND R&amp;T) Office</span><span style=3D'color:black'=
><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:10.0pt=
;font-family:"Arial","sans-serif";color:#1F497D'>9800 Savage Road Ste 6767<=
br>Ft Meade, MD 20755-6767<br></span><span style=3D'font-size:10.0pt;color:=
#1F497D'>Phone: 410-854-4422<br>NSTS: 968-8886<br>Fax 410-854-4681</span><s=
pan style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'><=
a href=3D"mailto:M.kinne@radium.ncsc.mil"><span style=3D'color:#660000'>mak=
inn2@nsa.gov</span></a></span><span style=3D'color:black'><o:p></o:p></span=
></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span =
style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span styl=
e=3D'color:#1F497D'>&nbsp;</span><span style=3D'color:black'><o:p></o:p></s=
pan></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><sp=
an style=3D'color:black'><o:p></o:p></span></p><div><div style=3D'border:no=
ne;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMso=
Normal><b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"=
;color:black'>From:</span></b><span style=3D'font-size:10.0pt;font-family:"=
Tahoma","sans-serif";color:black'><a href=3D"mailto:scap-dev@nist.gov">scap=
-dev@nist.gov</a> <a href=3D"mailto:[mailto:scap-dev@nist.gov]">[mailto:sca=
p-dev@nist.gov]</a> <b>On Behalf Of </b>Waltermire, David A.<br><b>Sent:</b=
> Monday, May 07, 2012 7:09 PM<br><b>To:</b> Multiple recipients of list<br=
><b>Subject:</b> RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Da=
ys: Summer 2012 at MITRE in Bedford, MA</span><span style=3D'color:black'><=
o:p></o:p></span></p></div></div><p class=3DMsoNormal><span style=3D'color:=
black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'colo=
r:#1F497D'>Kent,</span><span style=3D'color:black'><o:p></o:p></span></p><p=
 class=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=
=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'=
color:#1F497D'>I like what you are saying here.&nbsp; We are also in suppor=
t of this type of approach.&nbsp; We would like to see some community discu=
ssion around what are the key areas/priorities that the community would lik=
e to see discussed at Dev Days.&nbsp; Your topics below look like a good st=
art. The SACM list might be a better venue than the OVAL list for this disc=
ussion.&nbsp; For each area we should focus the discussion around developin=
g objectives for each session.&nbsp; The sessions can be time boxed based o=
n what would be a reasonable amount of time to accomplish each objective.&n=
bsp; For example if continuous monitoring is a priority and collectively it=
 takes 3 days to work through all the objectives, I see no problem with tha=
t.&nbsp; We can also keep a few sessions &#8220;on deck&#8221; if all the o=
bjectives are reached and we complete all the scheduled sessions early.</sp=
an><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><=
span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'color:black'><o:p>=
</o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'>Thought=
s?</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNo=
rmal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'color:black'=
><o:p></o:p></span></p><div><p class=3DMsoNormal><span style=3D'color:#1F49=
7D'>Sincerely,</span><span style=3D'color:black'><o:p></o:p></span></p></di=
v><p class=3DMsoNormal><span style=3D'color:black'>&nbsp;<o:p></o:p></span>=
</p><p class=3DMsoNormal><span style=3D'color:#1F497D'>David Waltermire</sp=
an><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><=
span style=3D'color:#1F497D'>SCAP Architect</span><span style=3D'color:blac=
k'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F497D'=
>National Institute of Standards and Technology</span><span style=3D'color:=
black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#1F4=
97D'>(301) 975-3390</span><span style=3D'color:black'><o:p></o:p></span></p=
><p class=3DMsoNormal><span style=3D'color:black'><a href=3D"mailto:david.w=
altermire@nist.gov">david.waltermire@nist.gov</a><o:p></o:p></span></p><p c=
lass=3DMsoNormal><span style=3D'color:#1F497D'>&nbsp;</span><span style=3D'=
color:black'><o:p></o:p></span></p><div><div style=3D'border:none;border-to=
p:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><s=
pan style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black=
'>From:</span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","san=
s-serif";color:black'><a href=3D"mailto:scap-dev@nist.gov">scap-dev@nist.go=
v</a> <a href=3D"mailto:[mailto:scap-dev@nist.gov]">[mailto:scap-dev@nist.g=
ov]</a> <b>On Behalf Of </b><a href=3D"mailto:Kent_Landfield@mcafee.com">Ke=
nt_Landfield@mcafee.com</a><br><b>Sent:</b> Monday, May 07, 2012 4:25 PM<br=
><b>To:</b> SCAP-DEV<br><b>Subject:</b> Re: [OVAL-DEVELOPER-LIST] Security =
Automation Developer Days: Summer 2012 at MITRE in Bedford, MA</span><span =
style=3D'color:black'><o:p></o:p></span></p></div></div><p class=3DMsoNorma=
l><span style=3D'color:black'>&nbsp;<o:p></o:p></span></p><div><div><div><d=
iv><p class=3DMsoNormal><span style=3D'color:black'>All,<o:p></o:p></span><=
/p></div><div><p class=3DMsoNormal><span style=3D'color:black'>&nbsp;<o:p><=
/o:p></span></p></div><div><p class=3DMsoNormal><span style=3D'color:black'=
>I would like to discuss the format for the SCAP Developer Days that seems =
to be listed below.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><s=
pan style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p class=
=3DMsoNormal><span style=3D'color:black'>I see this appears to follow a pat=
h we have discussed in the past as the way not to hold a Dev Days event. &n=
bsp;We have been trying to get away from 'Death by Powerpoint' and back to =
the type of event we held years ago when we were highly productive. &nbsp;I=
n the past we had a topic to be discussed and a time box to work within. &n=
bsp;That allowed us to have very active brainstorming sessions in a high ba=
ndwidth environment.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><=
span style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p class=
=3DMsoNormal><span style=3D'color:black'>At past Summer events we have got =
into a pattern of lots of powerpoint, lots of status of the efforts and ver=
y little discussion about things that need active discussions. &nbsp;We nee=
d to keep moving forward and making progress as an effort. We can get statu=
s from various places such as the lists, a presentation being sent out in a=
dvance, a webinar if it is felt there will be questions and answers from th=
ose that are new to the efforts. &nbsp;We have a limited amount of time and=
 all who are attending are investing a great deal of time and money to be t=
here. &nbsp;We should not &nbsp;be spending a great deal of time reeducatin=
g everyone when we could be focused on advancing needed efforts.<o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span style=3D'color:black'>&nbs=
p;<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span style=3D'colo=
r:black'>The type of approach to a Dev Days event was discussed at the last=
 Summer Dev Days. &nbsp;I have seen the following work quite well in other =
efforts.<o:p></o:p></span></p></div><ol start=3D1 type=3D1><li class=3DMsoN=
ormal style=3D'color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:au=
to;mso-list:l0 level1 lfo3'>Presentations are sent out to the attendees and=
 the lists a week in advance<o:p></o:p></li><li class=3DMsoNormal style=3D'=
color:black;mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 =
level1 lfo3'>Status for any effort is limited to 30 minutes<o:p></o:p></li>=
<li class=3DMsoNormal style=3D'color:black;mso-margin-top-alt:auto;mso-marg=
in-bottom-alt:auto;mso-list:l0 level1 lfo3'>Focused brainstorming time shou=
ld be established for certain areas that need real work by the community<o:=
p></o:p></li><li class=3DMsoNormal style=3D'color:black;mso-margin-top-alt:=
auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo3'>Efforts to be disc=
ussed should be based on needs of the security automation space to move exi=
sting efforts to completion.<o:p></o:p></li></ol><div><p class=3DMsoNormal>=
<span style=3D'color:black'>For example:<o:p></o:p></span></p></div><div><p=
 class=3DMsoNormal><span style=3D'color:black'>&nbsp;<o:p></o:p></span></p>=
</div><div><p class=3DMsoNormal><span style=3D'color:black'>Continuous moni=
toring is a major direction the efforts are becoming involved with. There a=
re going to be things we need to do as a security automation community to b=
e able to accomplish what is listed in the CAESARS FE. &nbsp;There are inte=
rfaces that need to be worked and established. &nbsp;That is one area that =
is not listed below. &nbsp;CM will have a major impact on all of us in the =
next couple years and it is being ignored. &nbsp;We can't keep trying to so=
lve what has already been solved. &nbsp;We need to address the needed inter=
face development now. This is an effort that could take nearly a whole day =
by itself.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span style=
=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p class=3DMsoNorma=
l><span style=3D'color:black'>Operationally we have a real need to be able =
to deliver SCAP content internally within an organization. Today the SCAP v=
endors cannot share a single local site security policy (XCCDF + OVAL + CPE=
 +&#8230;) without the site staff having to go to each of the individual pr=
oducts and figuring out how to inject that new or updated policy into that =
products delivery mechanisms. &nbsp;That is limiting sites from wanting to =
buy multiple focused SCAP products since they are such a pain to manage fro=
m a content perspective. &nbsp;It is easier to buy from one vendor that has=
 a single means for distributing content than it is to deal with the manage=
ment issues that having multiple SCAP products presents. &nbsp;We need to h=
ave at least an entire 1/2 a day on the development of a Content Repository=
 specification.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p class=3DMso=
Normal><span style=3D'color:black'>OCIL is a positive and a negative at the=
 same time. It has real value that is being underutilized and under impleme=
nted because of the limitations of how it addresses uses in an enterprise e=
nvironment. &nbsp;People don't need security automation to do things on/for=
 a single host. &nbsp;They need security automation to focus on the enterpr=
ise issues that reduce their costs and improve their efficiencies. &nbsp;OC=
IL is failing in the enterprise and we all understand that. &nbsp;We need t=
o address developing a definitive solution for incorporating OCIL into the =
enterprise and that means into the existing specifications. Scheduling and =
tracking are key to it's success. &nbsp;We need to make that happen. &nbsp;=
This too needs a focused brainstorming time box to discuss options.<o:p></o=
:p></span></p></div><div><p class=3DMsoNormal><span style=3D'color:black'>&=
nbsp;<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span style=3D'c=
olor:black'>I am really disappointed that Remediation is not on the list be=
low&#8230; &nbsp;Yes, last Summer Dev Days, the time spent on Remediation w=
as wasted time but that does not mean we should ignore it and not try to ma=
ke some real progress. &nbsp;As far as I am concerned we need to reboot the=
 remediation effort. &nbsp;We cannot keep being the set of specifications /=
 tools that act as the little boy crying &quot;Wolf&quot; in the night. &nb=
sp;We need to be able to find and fix issues if we are going to really make=
 a difference in organizational security postures. &nbsp;But today we think=
 it is too hard so we don't try ? &nbsp;I think we need a couple hours to d=
iscuss the reboot of the effort even if that means minimizing work already =
done.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span style=3D'c=
olor:black'>&nbsp;<o:p></o:p></span></p></div><div><p class=3DMsoNormal><sp=
an style=3D'color:black'>A focused discussion on enterprise reporting is al=
so critically needed. &nbsp;For the vendors here, we have all gone through =
the Cyberscope goat rope, delivering limited capabilities to specific data =
call requirements of the Federal Agencies. &nbsp;The initial effort was a m=
ess, did little more than prove it was possible and cause the vendor commun=
ity a great deal of thrashing to put a kludgey 'solution' in place. &nbsp;R=
eality is all our customers need roll up reporting and an infrastructure th=
at supports it. &nbsp;A data call should not be special to anyone other tha=
n the agencies responding. The tools should be able to select the types of =
data needed and deliver that on a scheduled basis automatically. &nbsp; &nb=
sp;Enterprise Reporting pertains to commercial as well as Federal customers=
. &nbsp;We need to focus some time on what that would look like using the A=
RF and ASR as the foundational pieces. &nbsp;But there are missing pieces&#=
8230;. &nbsp;We need this discussed.<o:p></o:p></span></p></div><div><p cla=
ss=3DMsoNormal><span style=3D'color:black'>&nbsp;<o:p></o:p></span></p></di=
v><div><p class=3DMsoNormal><span style=3D'color:black'>I would hope we can=
 make this summer's SCAP Dev Days useful in advancing the security automati=
on efforts by addressing some of the more critical issues our customers are=
 facing now or will be facing in the very short term. &nbsp;Status presenta=
tions are not interesting to those active in the efforts. &nbsp;Let's try t=
o do those before we get to Bedford so we can real make some progress while=
 we are all in the same room. &nbsp;This is always a big event for the 'con=
sensus of the willing' that assemble and driven to see security automation =
make a difference. &nbsp;Let's see if we can have an event that, when we al=
l walk out the last day, we all feel that every minute was well spent and m=
oves us forward.<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span=
 style=3D'color:black'>&nbsp;<o:p></o:p></span></p></div><div><p class=3DMs=
oNormal><span style=3D'color:black'>Thanks.<o:p></o:p></span></p></div><div=
><p class=3DMsoNormal><span style=3D'color:black'>&nbsp;<o:p></o:p></span><=
/p></div><div><div><p class=3DMsoNormal><strong><span style=3D'font-size:9.=
0pt;font-family:"Arial","sans-serif";color:#606A71'>Kent Landfield</span></=
strong><span style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";colo=
r:#606A71'><br><span class=3Dapple-style-span>Director Content Strategy, Ar=
chitecture and Standards</span><br><br><strong><span style=3D'font-family:"=
Arial","sans-serif"'>McAfee | An Intel Company</span></strong><br><span cla=
ss=3Dapple-style-span>5000 Headquarters Dr.</span><br><span class=3Dapple-s=
tyle-span>Plano, Texas 75024</span><br><br><span class=3Dapple-style-span>D=
irect: +1.972.963.7096&nbsp;</span><br><span class=3Dapple-style-span>Mobil=
e: +1.817.637.8026</span><br><strong><span style=3D'font-family:"Arial","sa=
ns-serif"'>Web:&nbsp;</span></strong><span class=3Dapple-style-span><a href=
=3D"http://www.mcafee.com/">www.mcafee.com</a></span></span><span style=3D'=
color:black'><o:p></o:p></span></p></div></div></div></div></div><div><p cl=
ass=3DMsoNormal><span style=3D'color:black'>&nbsp;<o:p></o:p></span></p></d=
iv><div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0=
in 0in 0in'><p class=3DMsoNormal><b><span style=3D'color:black'>From: </spa=
n></b><span style=3D'color:black'>&lt;Boczenowski&gt;, Steve &lt;<a href=3D=
"mailto:sboczeno@MITRE.ORG">sboczeno@MITRE.ORG</a>&gt;<br><b>Reply-To: </b>=
&quot;OVAL Developer List (Closed Public Discussion)&quot; &lt;<a href=3D"m=
ailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@LISTS.MITRE.=
ORG</a>&gt;<br><b>To: </b>&quot;<a href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS=
.MITRE.ORG">OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG</a>&quot; &lt;<a href=3D"ma=
ilto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@LISTS.MITRE.O=
RG</a>&gt;<br><b>Subject: </b>Re: [OVAL-DEVELOPER-LIST] Security Automation=
 Developer Days: Summer 2012 at MITRE in Bedford, MA<o:p></o:p></span></p><=
/div><div><p class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:=
"Times New Roman","serif";color:black'>&nbsp;</span><span style=3D'color:bl=
ack'><o:p></o:p></span></p></div><blockquote style=3D'border:none;border-le=
ft:solid #B5C4DF 4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-=
top:5.0pt;margin-right:0in;margin-bottom:5.0pt' id=3D"MAC_OUTLOOK_ATTRIBUTI=
ON_BLOCKQUOTE"><div><div><p class=3DMsoNormal><span style=3D'color:#254061'=
>Frank;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3D=
MsoNormal><span style=3D'color:#254061'>&nbsp;</span><span style=3D'color:b=
lack'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#2540=
61'>We hope to have the registration site up next week.&nbsp; The event wil=
l be during the week of July 9 &#8211; starting Monday at 10:00 AM and endi=
ng on Friday at 12:00.</span><span style=3D'color:black'><o:p></o:p></span>=
</p><p class=3DMsoNormal><span style=3D'color:#254061'>&nbsp;</span><span s=
tyle=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=
=3D'color:#254061'>Meanwhile, we are working on the agenda and are currentl=
y considering this list of topics:</span><span style=3D'color:black'><o:p><=
/o:p></span></p><p class=3DMsoNormal><span style=3D'color:#254061'>&nbsp;</=
span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal=
 style=3D'text-indent:.5in'><span style=3D'color:#254061'>CCE</span><span s=
tyle=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal style=3D'ma=
rgin-left:.5in'><span style=3D'color:#254061'>CPE/SWID</span><span style=3D=
'color:black'><o:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-le=
ft:.5in'><span style=3D'color:#254061'>CEE</span><span style=3D'color:black=
'><o:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-left:.5in'><sp=
an style=3D'color:#254061'>XCCDF</span><span style=3D'color:black'><o:p></o=
:p></span></p><p class=3DMsoNormal style=3D'margin-left:.5in'><span style=
=3D'color:#254061'>OVAL</span><span style=3D'color:black'><o:p></o:p></span=
></p><p class=3DMsoNormal style=3D'margin-left:.5in'><span style=3D'color:#=
254061'>ASR</span><span style=3D'color:black'><o:p></o:p></span></p><p clas=
s=3DMsoNormal style=3D'margin-left:.5in'><span style=3D'color:#254061'>Ente=
rprise OCIL</span><span style=3D'color:black'><o:p></o:p></span></p><p clas=
s=3DMsoNormal style=3D'margin-left:.5in'><span style=3D'color:#254061'>CybO=
X/MAEC</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DM=
soNormal style=3D'margin-left:.5in'><span style=3D'color:#254061'>Federated=
 Content Repository Spec</span><span style=3D'color:black'><o:p></o:p></spa=
n></p><p class=3DMsoNormal style=3D'margin-left:.5in'><span style=3D'color:=
#254061'>Endpoint Reporting for Continuous Monitoring and Compliance (ERCC)=
</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNorm=
al style=3D'margin-left:.5in'><span style=3D'color:#254061'>MILE</span><spa=
n style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal style=3D=
'margin-left:.5in'><span style=3D'color:#254061'>TAXII</span><span style=3D=
'color:black'><o:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-le=
ft:.5in'><span style=3D'color:#254061'>IF-M for SCAP</span><span style=3D'c=
olor:black'><o:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-left=
:.5in'><span style=3D'color:#254061'>IF-MAP</span><span style=3D'color:blac=
k'><o:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-left:.5in'><s=
pan style=3D'color:#254061'>SCAP Releases</span><span style=3D'color:black'=
><o:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-left:.5in'><spa=
n style=3D'color:#254061'>SCAP and IETF</span><span style=3D'color:black'><=
o:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'color:#254061'>NETCONF and SCAP</span><span style=3D'color:black'>=
<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#254061'>&n=
bsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMso=
Normal><span style=3D'color:#254061'>Steve</span><span style=3D'color:black=
'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'color:#254061'>=
&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><div><div st=
yle=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in=
'><p class=3DMsoNormal style=3D'margin-left:2.0in'><b><span style=3D'font-s=
ize:10.0pt;font-family:"Tahoma","sans-serif";color:black'>From:</span></b><=
span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:blac=
k'> Frank Lindsay Acker [<a href=3D"mailto:afrank@NOVA.EDU">mailto:afrank@N=
OVA.EDU</a>] <br><b>Sent:</b> Tuesday, May 01, 2012 9:32 AM<br><b>To:</b> o=
val-developer-list OVAL Developer List/Closed Public Discussion<br><b>Subje=
ct:</b> Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summe=
r 2012 at MITRE in Bedford, MA</span><span style=3D'color:black'><o:p></o:p=
></span></p></div></div><p class=3DMsoNormal style=3D'margin-left:.5in'><sp=
an style=3D'color:black'>&nbsp;<o:p></o:p></span></p><div><p class=3DMsoNor=
mal style=3D'margin-left:.5in'><span style=3D'font-size:10.0pt;font-family:=
"Tahoma","sans-serif";color:black'>Steve....<br><br>Has there been any addi=
tional information regarding this event?<br><br>Thanks,<br>Frank Acker</spa=
n><span style=3D'color:black'><o:p></o:p></span></p><div><div style=3D'marg=
in-left:.5in'><div class=3DMsoNormal align=3Dcenter style=3D'text-align:cen=
ter'><span style=3D'font-size:12.0pt;font-family:"Times New Roman","serif";=
color:black'><hr size=3D2 width=3D"100%" align=3Dcenter></span></div></div>=
<div id=3DdivRpF955236><p class=3DMsoNormal style=3D'mso-margin-top-alt:0in=
;margin-right:0in;margin-bottom:12.0pt;margin-left:.5in'><b><span style=3D'=
font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>From:</span=
></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";colo=
r:black'> Boczenowski, Steve [<a href=3D"mailto:sboczeno@MITRE.ORG">sboczen=
o@MITRE.ORG</a>]<br><b>Sent:</b> Tuesday, March 20, 2012 16:38<br><b>To:</b=
> <a href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIS=
T@LISTS.MITRE.ORG</a><br><b>Subject:</b> [OVAL-DEVELOPER-LIST] Security Aut=
omation Developer Days: Summer 2012 at MITRE in Bedford, MA</span><span sty=
le=3D'color:black'><o:p></o:p></span></p></div><div><div><p class=3DMsoNorm=
al style=3D'margin-left:.5in'><span style=3D'color:black'>Save the Date: we=
ek of July 9, 2012<o:p></o:p></span></p><p class=3DMsoNormal style=3D'margi=
n-left:.5in'><span style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p cla=
ss=3DMsoNormal style=3D'margin-left:.5in'><span style=3D'color:black'>This =
year&#8217;s MITRE-hosted Security Automation Developer Days event will be =
held during the week of July 9, 2012 at MITRE&#8217;s facility in Bedford, =
MA.<o:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-left:.5in'><s=
pan style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:.5in'><span style=3D'color:black'>Details to follow.<o=
:p></o:p></span></p><p class=3DMsoNormal style=3D'margin-left:.5in'><span s=
tyle=3D'color:black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal style=
=3D'margin-left:.5in'><span style=3D'color:black'>Regards,<o:p></o:p></span=
></p><p class=3DMsoNormal style=3D'margin-left:.5in'><span style=3D'color:b=
lack'>&nbsp;&nbsp;&nbsp; Steve<o:p></o:p></span></p><p class=3DMsoNormal st=
yle=3D'margin-left:.5in'><span style=3D'color:black'>&nbsp;<o:p></o:p></spa=
n></p><p class=3DMsoNormal style=3D'mso-margin-top-alt:0in;margin-right:343=
.5pt;margin-bottom:4.0pt;margin-left:.5in'><span style=3D'font-size:8.0pt;f=
ont-family:"Arial","sans-serif";color:#1F497D'>____________________________=
__________________</span><span style=3D'color:black'><o:p></o:p></span></p>=
<p class=3DMsoNormal style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;m=
argin-bottom:4.0pt;margin-left:.5in'><i><span style=3D'font-family:"Arial",=
"sans-serif";color:#1F497D'>Steph</span><span style=3D'color:#1F497D'>en P.=
 Boczenowski</span></i><span style=3D'color:black'><o:p></o:p></span></p><p=
 class=3DMsoNormal style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;mar=
gin-bottom:2.0pt;margin-left:.5in'><span style=3D'font-size:10.0pt;font-fam=
ily:"Arial","sans-serif";color:#1F497D'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The =
</span><span style=3D'font-size:10.0pt;font-family:MITRE;color:#3366FF'>MIT=
RE</span><span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";c=
olor:#1F497D'> Corporation</span><span style=3D'color:black'><o:p></o:p></s=
pan></p><p class=3DMsoNormal style=3D'mso-margin-top-alt:0in;margin-right:3=
43.5pt;margin-bottom:0in;margin-left:.5in;margin-bottom:.0001pt'><span styl=
e=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'>&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; Office: (781) 271-7682</span><span style=3D'color=
:black'><o:p></o:p></span></p><p class=3DMsoNormal style=3D'mso-margin-top-=
alt:0in;margin-right:343.5pt;margin-bottom:0in;margin-left:.5in;margin-bott=
om:.0001pt'><span style=3D'font-size:10.0pt;font-family:"Arial","sans-serif=
";color:#1F497D'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Cell: (978) 302-3849</span>=
<span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal styl=
e=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:0in;margin-l=
eft:.5in;margin-bottom:.0001pt'><span style=3D'font-size:10.0pt;font-family=
:"Arial","sans-serif";color:#1F497D'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=
=3D"mailto:sboczeno@mitre.org" target=3D"_blank">sboczeno@mitre.org</a></sp=
an><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal s=
tyle=3D'margin-left:.5in'><span style=3D'color:black'>&nbsp;<o:p></o:p></sp=
an></p></div><p class=3DMsoNormal style=3D'margin-left:.5in'><span style=3D=
'font-size:12.0pt;font-family:"Times New Roman","serif";color:black'>To uns=
ubscribe, send an email message to <a href=3D"mailto:LISTSERV@LISTS.MITRE.O=
RG">LISTSERV@LISTS.MITRE.ORG</a> with SIGNOFF OVAL-DEVELOPER-LIST in the BO=
DY of the message. If you have difficulties, write to <a href=3D"mailto:OVA=
L-DEVELOPER-LIST-request@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST-request@LISTS=
.MITRE.ORG</a>. </span><span style=3D'color:black'><o:p></o:p></span></p></=
div></div></div><p class=3DMsoNormal style=3D'margin-left:.5in'><span style=
=3D'font-size:12.0pt;font-family:"Times New Roman","serif";color:black'>To =
unsubscribe, send an email message to <a href=3D"mailto:LISTSERV@LISTS.MITR=
E.ORG">LISTSERV@LISTS.MITRE.ORG</a> with SIGNOFF OVAL-DEVELOPER-LIST in the=
 BODY of the message. If you have difficulties, write to <a href=3D"mailto:=
OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST-request@LI=
STS.MITRE.ORG</a>. </span><span style=3D'color:black'><o:p></o:p></span></p=
><p class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Times Ne=
w Roman","serif";color:black'>To unsubscribe, send an email message to <a h=
ref=3D"mailto:LISTSERV@LISTS.MITRE.ORG">LISTSERV@LISTS.MITRE.ORG</a> with S=
IGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have difficul=
ties, write to <a href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.OR=
G">OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG</a>. </span><span style=3D'c=
olor:black'><o:p></o:p></span></p></div></div></blockquote></div></div></bl=
ockquote></div></body></html>=

--_000_D7A0423E5E193F40BE6E94126930C4930B9BA83FFDMBCLUSTERxcha_--

From lnunez@c3isecurity.com  Fri Jun 15 12:33:51 2012
Return-Path: <lnunez@c3isecurity.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EB70411E80F9 for <sacm@ietfa.amsl.com>; Fri, 15 Jun 2012 12:33:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.358
X-Spam-Level: 
X-Spam-Status: No, score=-2.358 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1, SARE_LWSHORTT=1.24]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vQvSqZHm9ctE for <sacm@ietfa.amsl.com>; Fri, 15 Jun 2012 12:33:46 -0700 (PDT)
Received: from mail-yw0-f44.google.com (mail-yw0-f44.google.com [209.85.213.44]) by ietfa.amsl.com (Postfix) with ESMTP id 8969811E80F6 for <sacm@ietf.org>; Fri, 15 Jun 2012 12:33:46 -0700 (PDT)
Received: by yhq56 with SMTP id 56so3062195yhq.31 for <sacm@ietf.org>; Fri, 15 Jun 2012 12:33:46 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=subject:mime-version:content-type:from:in-reply-to:date:cc :message-id:references:to:x-mailer:x-gm-message-state; bh=NGXmN4/8kZgOag5WwnldGnCOy7cqKwsbINrIwIaHsg8=; b=C2dqeBM9We1svVpMFGQ+yUUN6MMNC9f6WyQI6wwU4TS0Qo6cZeZO3iK9iAq0AN2gQC LcTzJxXGBZujF87FtJQKhY76276Nrgk6ZxnJudJep/QM5wrOC2EdztVH4eQEQaRFBP9L Q0G5xeTIOvqT5dng/MEa27ata8Hj4zLF3cLdsblAcgKuGVi1XSRuTy+knBTBYpgdubnh pX6d0BfvMAVGXp1H3jBqNmwJDw7cMcEda5UjwZRoDnkaY1wQmZdrV5VDmExtmlatAI4T j4oIa2Bi4SrFYbSseIaFG27fu8OUZKlqQZCl6OFDLCFl6XP7Bk+UiWFNKVM1m4KiSHtF Gp7w==
Received: by 10.101.18.16 with SMTP id v16mr2924844ani.79.1339788824531; Fri, 15 Jun 2012 12:33:44 -0700 (PDT)
Received: from [192.168.1.37] (cpe-066-057-081-254.nc.res.rr.com. [66.57.81.254]) by mx.google.com with ESMTPS id i16sm17434388anm.12.2012.06.15.12.33.42 (version=TLSv1/SSLv3 cipher=OTHER); Fri, 15 Jun 2012 12:33:43 -0700 (PDT)
Mime-Version: 1.0 (Apple Message framework v1278)
Content-Type: multipart/alternative; boundary="Apple-Mail=_6240EF91-60C2-4BA3-ABE4-7EB0B936FC78"
From: Luis Nunez <lnunez@c3isecurity.com>
In-Reply-To: <D7A0423E5E193F40BE6E94126930C4930B9BA83FFD@MBCLUSTER.xchange.nist.gov>
Date: Fri, 15 Jun 2012 15:33:43 -0400
Message-Id: <34425F2D-4172-4E61-89B8-00AD6BB6462E@c3isecurity.com>
References: <15D0981C9BE53042A4C9D0F3D0B6826B2900F2@MSIS-GH1-UEA10.corp.nsa.gov> <CBD00675.32964%kent_landfield@mcafee.com> <00a801cd4a69$aba5be40$02f13ac0$@secpod.com> <D7A0423E5E193F40BE6E94126930C4930B9BA83FFD@MBCLUSTER.xchange.nist.gov>
To: "Waltermire, David A." <david.waltermire@nist.gov>
X-Mailer: Apple Mail (2.1278)
X-Gm-Message-State: ALoCoQlA9wGy68zySTC2bthP1v+SbhL1X+3ohuHjwdE7a7B3ONKRqKxW47kooD1nTEOUYMQrq/Ft
Cc: SCAP-DEV <SCAP-DEV@nist.gov>, "bchandra@secpod.com" <bchandra@secpod.com>, "sacm@ietf.org" <sacm@ietf.org>
Subject: Re: [sacm] Request for participants - Content Repository Specification Development
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 15 Jun 2012 19:33:51 -0000

--Apple-Mail=_6240EF91-60C2-4BA3-ABE4-7EB0B936FC78
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1250

here is the faq with some samples http://scaprepo.com/faq.html

cve access complexity high
all vulnerabilities from jan 2011

-ln



On Jun 15, 2012, at 3:23 PM, Waltermire, David A. wrote:

> I am not sure how to use the search page properly.  Would you please =
provide some example searches?
> =20
> Sincerely,
> Dave
> =20
> From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf =
Of Chandrashekhar B
> Sent: Thursday, June 14, 2012 4:10 PM
> To: SCAP-DEV; sacm@ietf.org
> Subject: Re: [sacm] Request for participants - Content Repository =
Specification Development
> =20
> We have hosted our SCAP Content Repository at www.scaprepo.com. =
Feedback is certainly appreciated. A simple web service interface will =
be published soon.
> =20
> Chandra.
> =20
> From: scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of =
Kent_Landfield@mcafee.com
> Sent: Friday, May 11, 2012 10:14 PM
> To: Multiple recipients of list
> Subject: Request for participants - Content Repository Specification =
Development
> =20
> Mike I love it when you tee something up like that=85. ;-)  Thank you. =
;)
> =20
> Mike wrote:=20
> I still think that any specification for a repository is wishful =
thinking until someone builds one and learns the lessons it will just be =
another whitepaper spec.  I believe the DoD needs to incorporate a =
metadata repository as part of it and other customizations that may not =
be useful for everyone.
> We need to talk more=85
> =20
> If you are talking about a holistic, complete federated approach to a =
content repository, I some what agree.  If you are talking about an =
organizational repository, I totally disagree. But you knew I would. ;)
> =20
> Here is how I see the problem.  There is an immediate need for SCAP =
and other related content to be served up inside an organization.  Today =
we have situation where the standards allow us to provide sites the =
capability to have a single SCAP implemented policy they call official =
for their environment. Yes this is a rather simplistic since there are =
things such as targeting specific platforms, specific operational use =
needs, but for now lets agree SCAP is a massive improvement over the =
proprietary situations of the past. While we have created this standard =
content so that sites can implement their local site security once and =
then assure they are measuring all appropriately targeted devices the =
same way, we have failed to support the operational needs of the sites.  =
We have a situation where no two vendors distribute content the same =
way.  This causes massive problems for the administration staff when =
they need to incorporate a new SCAP enabled product into their =
architecture.  They need to discover how the new product supports =
distributing SCAP content to it's various components.  If they have one =
product then they do this one and they are done.  If they have multiple =
products they will have to figure out how to minimize the impact by =
incorporating the update process for the new product into the existing =
SCAP security content processes. Now when the inevitable happens and the =
site staff needs to make a change to their security policy, they have to =
make the modifications to the benchmark or checks or both and then =
distribute those updates across their network.  For each SCAP enabled =
product they have in place, they have doubled, tripled or more the work =
needed to make those updates available.=20
> =20
> There is another content repository problem and that is the Federated =
Content Distribution.  If you think global DNS you have a general frame =
of reference.  The guidance authors need to be able to publish content =
in an authoritative manner so their content is updated in a timely =
fashion.  This is a much harder problem to solve if there is no local =
organizational infrastructure to support it. ;)
> =20
> So here is what I am thinking=85  We should consider addressing these =
as two separate but integrated efforts.  I believe the Organizational =
Content Repository is the more critical piece that is actually easier to =
address.  The Federated Content Distribution should be a subsequent =
effort integrating / augmenting the Organizational repository =
specification.=20
> =20
> Mike, to your point that we need someone to build one first=85 That =
has happened already.  I have one as do other vendors but what we don=92t =
have is the access specification.  Ours are focused on our specific =
product needs.  Additionally there is a company that has developed a =
commercial SCAP content repository that will be announced later this =
month. I won't steal their thunder but I was recently given a sneak peek =
at it and I must admit I was very impressed.  Again, to your point, it =
has been done. What is needed to address the initial operational problem =
is to develop a specification that provides a consistent means for all =
SCAP products to retrieve the appropriate content as configured and =
managed but the site. =20
> =20
> TO THAT END=85.
> =20
> I am requesting participation from those in the community that see the =
need and want to put in the work to make this specification happen.  I =
have talked to a couple of you but I do not want to assume your =
participation.  If you are interested please contact me so we can get =
this started.=20
> =20
> Thanks!
> =20
> Kent Landfield
> Director Content Strategy, Architecture and Standards
>=20
> McAfee | An Intel Company
> 5000 Headquarters Dr.
> Plano, Texas 75024
>=20
> Direct: +1.972.963.7096=20
> Mobile: +1.817.637.8026
> Web: www.mcafee.com
> =20
> From: <Kinney>, Michael A <m.kinne@radium.ncsc.mil>
> To: David Waltermire <david.waltermire@nist.gov>, SCAP-DEV =
<SCAP-DEV@nist.gov>, "sacm@ietforg" <sacm@ietf.org>
> Subject: Re: [sacm] [OVAL-DEVELOPER-LIST] Security Automation =
Developer Days: Summer 2012 at MITRE in Bedford, MA
> =20
> Dave,
> I have no problem with webinars, I do want to keep developer days =
actionable and use it to make decisions, and vote and accomplish things =
good or bad.  I do not want this to be an informational briefing =
conference.
> Thanks for the links.
> =20
> I still think that any specification for a repository is wishful =
thinking until someone builds one and learns the lessons it will just be =
another whitepaper spec.  I believe the DoD needs to incorporate a =
metadata repository as part of it and other customizations that may not =
be useful for everyone.
> We need to talk more=85
> =20
> -Mike=20
> =20
> From: Waltermire, David A. [mailto:david.waltermire@nist.gov]=20
> Sent: Tuesday, May 08, 2012 10:44 AM
> To: Kinney, Michael A; SCAP-DEV; sacm@ietf.org
> Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer 2012 at MITRE in Bedford, MA
> =20
> Mike,
> =20
> What about having webinars in-place of the 30 minute briefs?
> =20
> Regarding content management, we are building the prototype content =
repository for use in a production environment.  As an open source =
project, it will be free for use by anyone interested.  My thinking is =
that this project can bridge the gap until commercial solutions are =
available to augment it.  This is a similar path that was followed with =
DNS (bind) and HTTP (apache).  When it is ready for use, I am hoping to =
use it to host USGCB content.  You would be welcome to use it for your =
needs.
> =20
> It is good that OCIL is moving forward.  This is an important piece of =
supporting risk management and aspects of continuous monitoring.  I =
would also like to see some discussion on OCIL at Developer Days.  With =
the proposals we will likely have a sense of what needs to be discussed =
and what we can achieve consensus on outside the meeting.
> =20
> Remediation is a topic near and dear to my heart.  I too would like to =
see it move forward.
> =20
> We just published the draft ASR specification for public comment.  =
This specification supports enterprise aggregate reporting which greatly =
reduces the data volumes needed verses detailed host-based reports. This =
specification has been designed as a more robust replacement for LASR  =
It can be used in continuous monitoring applications to support =
aggregate data reporting needs (e.g. FISMA reporting,  CyberScope).
> =20
> Here are the links:
> =20
> http://csrc.nist.gov/publications/PubsDrafts.html
> http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848
> =20
> The primary reason we have suggested waiting on XCCDF is not the =
internationalization issue. Many vendors have commented that they are =
still working on implementing the XCCDF 1.2.1 specification. We will be =
in a better place in a few months once more development around XCCDF has =
occurred.  As we consider changes to the SCAP stack to address OCIL and =
other issues, we will identify areas that need improvement in XCCDF.  =
These are good and necessary discussions to have now, but we have a good =
deal of work to do before we are ready to open up XCCDF.  My suggestion =
is to work on these related areas and then work up change proposals for =
XCCDF as needed.  By that time we should be ready to work on a new =
revision of XCCDF.
> =20
> I am also looking forward to the discussions at the conference.  It =
has been too long.
> =20
> Sincerely,
> Dave
> =20
> From: Kinney, Michael A [mailto:m.kinne@radium.ncsc.mil]=20
> Sent: Tuesday, May 08, 2012 7:09 AM
> To: SCAP-DEV
> Cc: Waltermire, David A.
> Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer 2012 at MITRE in Bedford, MA
> =20
> Kent,
> =20
> It=92s good to read your thoughts, and a realistic actionable approach =
is indeed needed  Since all the activity hasn=92t been on the lists a =
brief 1=8E2 hour recap may be in order to bring everyone up to speed =
since there has been a lot of activity on CPE/SWID, OCIl, MAEC/CybOX CEE =
and others.
> =20
> We could write a content repository specification, but without someone =
willing to stand one up it will be as valuable as the CCSS specification =
is today.  I=92ve been trying for two years to get my management to get =
a coordinated effort together for the DoD to stand up a repository, it =
is a tough problem and will require funding with a tail, I=92m not sure =
a specification will solve that problem.
> =20
> We (DoD) have been putting a lot of effort into OCIL over the last =
year trying to make it useful in an enterprise environment and will be =
posting our ideas to the list before developer days it should have =
already started, we need to get consensus and a vote on how the =
community wishes to proceed.
> =20
> Remediation is stalled but I=92m making every effort to get it kick =
started from our perspective. I hope to assist in getting the draft ERI =
finished this year.  We are writing some new STIG content and intend to =
used the draft CRE specification to insert CRE into the content so we =
(DoD) can do some automatic configuration fixes, part of a self healing =
network concept. It is just a start but the best we can do at this =
point.
> =20
> Enterprise reporting is an interesting subject, since XML adds size to =
and content to roll up reporting, in any enterprise of size the problem =
gets greater, I look forward to your thoughts on that subject.
> =20
> I am concerned that the internationalization efforts are detracting =
from efforts to meet use cases, we have some things we would like =
changed in XCCDF to support our OCIl use case and I have been told that =
I need to wait. I didn=92t think that a move to internationalization =
should impede efforts to move forward with use cases.
> =20
> I look forward to talking with you at the conference.
> =20
> v/r
> =20
> Mike Kinney
> Project Director
> Computer Network Defense Research and Technology (CND R&T) Office
> 9800 Savage Road Ste 6767
> Ft Meade, MD 20755-6767
> Phone: 410-854-4422
> NSTS: 968-8886
> Fax 410-854-4681
> makinn2@nsa.gov
> =20
> =20
> =20
> From:scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of =
Waltermire, David A.
> Sent: Monday, May 07, 2012 7:09 PM
> To: Multiple recipients of list
> Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer 2012 at MITRE in Bedford, MA
> =20
> Kent,
> =20
> I like what you are saying here.  We are also in support of this type =
of approach.  We would like to see some community discussion around what =
are the key areas/priorities that the community would like to see =
discussed at Dev Days.  Your topics below look like a good start. The =
SACM list might be a better venue than the OVAL list for this =
discussion.  For each area we should focus the discussion around =
developing objectives for each session.  The sessions can be time boxed =
based on what would be a reasonable amount of time to accomplish each =
objective.  For example if continuous monitoring is a priority and =
collectively it takes 3 days to work through all the objectives, I see =
no problem with that.  We can also keep a few sessions =93on deck=94 if =
all the objectives are reached and we complete all the scheduled =
sessions early.
> =20
> Thoughts?
> =20
> Sincerely,
> =20
> David Waltermire
> SCAP Architect
> National Institute of Standards and Technology
> (301) 975-3390
> david.waltermire@nist.gov
> =20
> From:scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of =
Kent_Landfield@mcafee.com
> Sent: Monday, May 07, 2012 4:25 PM
> To: SCAP-DEV
> Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer 2012 at MITRE in Bedford, MA
> =20
> All,
> =20
> I would like to discuss the format for the SCAP Developer Days that =
seems to be listed below.
> =20
> I see this appears to follow a path we have discussed in the past as =
the way not to hold a Dev Days event.  We have been trying to get away =
from 'Death by Powerpoint' and back to the type of event we held years =
ago when we were highly productive.  In the past we had a topic to be =
discussed and a time box to work within.  That allowed us to have very =
active brainstorming sessions in a high bandwidth environment.
> =20
> At past Summer events we have got into a pattern of lots of =
powerpoint, lots of status of the efforts and very little discussion =
about things that need active discussions.  We need to keep moving =
forward and making progress as an effort. We can get status from various =
places such as the lists, a presentation being sent out in advance, a =
webinar if it is felt there will be questions and answers from those =
that are new to the efforts.  We have a limited amount of time and all =
who are attending are investing a great deal of time and money to be =
there.  We should not  be spending a great deal of time reeducating =
everyone when we could be focused on advancing needed efforts.
> =20
> The type of approach to a Dev Days event was discussed at the last =
Summer Dev Days.  I have seen the following work quite well in other =
efforts.
> Presentations are sent out to the attendees and the lists a week in =
advance
> Status for any effort is limited to 30 minutes
> Focused brainstorming time should be established for certain areas =
that need real work by the community
> Efforts to be discussed should be based on needs of the security =
automation space to move existing efforts to completion.
> For example:
> =20
> Continuous monitoring is a major direction the efforts are becoming =
involved with. There are going to be things we need to do as a security =
automation community to be able to accomplish what is listed in the =
CAESARS FE.  There are interfaces that need to be worked and =
established.  That is one area that is not listed below.  CM will have a =
major impact on all of us in the next couple years and it is being =
ignored.  We can't keep trying to solve what has already been solved.  =
We need to address the needed interface development now. This is an =
effort that could take nearly a whole day by itself.
> =20
> Operationally we have a real need to be able to deliver SCAP content =
internally within an organization. Today the SCAP vendors cannot share a =
single local site security policy (XCCDF + OVAL + CPE +=85) without the =
site staff having to go to each of the individual products and figuring =
out how to inject that new or updated policy into that products delivery =
mechanisms.  That is limiting sites from wanting to buy multiple focused =
SCAP products since they are such a pain to manage from a content =
perspective.  It is easier to buy from one vendor that has a single =
means for distributing content than it is to deal with the management =
issues that having multiple SCAP products presents.  We need to have at =
least an entire 1/2 a day on the development of a Content Repository =
specification.
> =20
> OCIL is a positive and a negative at the same time. It has real value =
that is being underutilized and under implemented because of the =
limitations of how it addresses uses in an enterprise environment.  =
People don't need security automation to do things on/for a single host. =
 They need security automation to focus on the enterprise issues that =
reduce their costs and improve their efficiencies.  OCIL is failing in =
the enterprise and we all understand that.  We need to address =
developing a definitive solution for incorporating OCIL into the =
enterprise and that means into the existing specifications. Scheduling =
and tracking are key to it's success.  We need to make that happen.  =
This too needs a focused brainstorming time box to discuss options.
> =20
> I am really disappointed that Remediation is not on the list below=85  =
Yes, last Summer Dev Days, the time spent on Remediation was wasted time =
but that does not mean we should ignore it and not try to make some real =
progress.  As far as I am concerned we need to reboot the remediation =
effort.  We cannot keep being the set of specifications / tools that act =
as the little boy crying "Wolf" in the night.  We need to be able to =
find and fix issues if we are going to really make a difference in =
organizational security postures.  But today we think it is too hard so =
we don't try ?  I think we need a couple hours to discuss the reboot of =
the effort even if that means minimizing work already done.
> =20
> A focused discussion on enterprise reporting is also critically =
needed.  For the vendors here, we have all gone through the Cyberscope =
goat rope, delivering limited capabilities to specific data call =
requirements of the Federal Agencies.  The initial effort was a mess, =
did little more than prove it was possible and cause the vendor =
community a great deal of thrashing to put a kludgey 'solution' in =
place.  Reality is all our customers need roll up reporting and an =
infrastructure that supports it.  A data call should not be special to =
anyone other than the agencies responding. The tools should be able to =
select the types of data needed and deliver that on a scheduled basis =
automatically.    Enterprise Reporting pertains to commercial as well as =
Federal customers.  We need to focus some time on what that would look =
like using the ARF and ASR as the foundational pieces.  But there are =
missing pieces=85.  We need this discussed.
> =20
> I would hope we can make this summer's SCAP Dev Days useful in =
advancing the security automation efforts by addressing some of the more =
critical issues our customers are facing now or will be facing in the =
very short term.  Status presentations are not interesting to those =
active in the efforts.  Let's try to do those before we get to Bedford =
so we can real make some progress while we are all in the same room.  =
This is always a big event for the 'consensus of the willing' that =
assemble and driven to see security automation make a difference.  Let's =
see if we can have an event that, when we all walk out the last day, we =
all feel that every minute was well spent and moves us forward.
> =20
> Thanks.
> =20
> Kent Landfield
> Director Content Strategy, Architecture and Standards
>=20
> McAfee | An Intel Company
> 5000 Headquarters Dr.
> Plano, Texas 75024
>=20
> Direct: +1.972.963.7096=20
> Mobile: +1.817.637.8026
> Web: www.mcafee.com
> =20
> From: <Boczenowski>, Steve <sboczeno@MITRE.ORG>
> Reply-To: "OVAL Developer List (Closed Public Discussion)" =
<OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG>
> To: "OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG" =
<OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG>
> Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer 2012 at MITRE in Bedford, MA
> =20
> Frank;
> =20
> We hope to have the registration site up next week.  The event will be =
during the week of July 9 =96 starting Monday at 10:00 AM and ending on =
Friday at 12:00.
> =20
> Meanwhile, we are working on the agenda and are currently considering =
this list of topics:
> =20
> CCE
> CPE/SWID
> CEE
> XCCDF
> OVAL
> ASR
> Enterprise OCIL
> CybOX/MAEC
> Federated Content Repository Spec
> Endpoint Reporting for Continuous Monitoring and Compliance (ERCC)
> MILE
> TAXII
> IF-M for SCAP
> IF-MAP
> SCAP Releases
> SCAP and IETF
> NETCONF and SCAP
> =20
> Steve
> =20
> From: Frank Lindsay Acker [mailto:afrank@NOVA.EDU]=20
> Sent: Tuesday, May 01, 2012 9:32 AM
> To: oval-developer-list OVAL Developer List/Closed Public Discussion
> Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer 2012 at MITRE in Bedford, MA
> =20
> Steve....
>=20
> Has there been any additional information regarding this event?
>=20
> Thanks,
> Frank Acker
> From: Boczenowski, Steve [sboczeno@MITRE.ORG]
> Sent: Tuesday, March 20, 2012 16:38
> To: OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG
> Subject: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer 2012 at MITRE in Bedford, MA
>=20
> Save the Date: week of July 9, 2012
> =20
> This year=92s MITRE-hosted Security Automation Developer Days event =
will be held during the week of July 9, 2012 at MITRE=92s facility in =
Bedford, MA.
> =20
> Details to follow.
> =20
> Regards,
>     Steve
> =20
> ______________________________________________
> Stephen P. Boczenowski
>       The MITRE Corporation
>       Office: (781) 271-7682
>       Cell: (978) 302-3849
>      sboczeno@mitre.org
> =20
> To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with =
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.
> To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with =
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.
> To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with =
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm


--Apple-Mail=_6240EF91-60C2-4BA3-ABE4-7EB0B936FC78
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=windows-1250

<html><head><base href=3D"x-msg://1380/"></head><body style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><div>here is the faq with some samples&nbsp;<a =
href=3D"http://scaprepo.com/faq.html">http://scaprepo.com/faq.html</a></di=
v><div><br></div><div><span style=3D"color: rgb(86, 86, 86); =
font-family: 'Lucida Sans Unicode', 'Lucida Grande', sans-serif; =
font-size: 12px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: 18px; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: =
inline !important; float: none; ">cve access complexity =
high</span></div><div><span style=3D"color: rgb(86, 86, 86); =
font-family: 'Lucida Sans Unicode', 'Lucida Grande', sans-serif; =
font-size: 12px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: 18px; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: =
inline !important; float: none; "><span style=3D"color: rgb(86, 86, 86); =
font-family: 'Lucida Sans Unicode', 'Lucida Grande', sans-serif; =
font-size: 12px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: 18px; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: =
inline !important; float: none; ">all vulnerabilities from jan =
2011</span></span></div><div><span style=3D"color: rgb(86, 86, 86); =
font-family: 'Lucida Sans Unicode', 'Lucida Grande', sans-serif; =
font-size: 12px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: 18px; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: =
inline !important; float: none; "><span style=3D"color: rgb(86, 86, 86); =
font-family: 'Lucida Sans Unicode', 'Lucida Grande', sans-serif; =
font-size: 12px; font-style: normal; font-variant: normal; font-weight: =
normal; letter-spacing: normal; line-height: 18px; orphans: 2; =
text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: =
inline !important; float: none; "><br></span></span></div><div><span =
style=3D"color: rgb(86, 86, 86); font-family: 'Lucida Sans Unicode', =
'Lucida Grande', sans-serif; font-size: 12px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: 18px; orphans: 2; text-align: -webkit-auto; text-indent: =
0px; text-transform: none; white-space: normal; widows: 2; word-spacing: =
0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; =
display: inline !important; float: none; "><span style=3D"color: rgb(86, =
86, 86); font-family: 'Lucida Sans Unicode', 'Lucida Grande', =
sans-serif; font-size: 12px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: =
2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: =
inline !important; float: none; =
">-ln</span></span></div><div><br></div><div><br></div><br><div><div>On =
Jun 15, 2012, at 3:23 PM, Waltermire, David A. wrote:</div><br =
class=3D"Apple-interchange-newline"><blockquote type=3D"cite"><div =
lang=3D"EN-US" link=3D"blue" vlink=3D"purple"><div class=3D"WordSection1" =
style=3D"page: WordSection1; "><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">I am not sure how to use the search page properly.&nbsp; =
Would you please provide some example =
searches?<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); "><o:p>&nbsp;</o:p></span></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(31, 73, 125); ">Sincerely,<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: rgb(31, 73, 125); =
">Dave<o:p></o:p></span></div></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); "><o:p>&nbsp;</o:p></span></div><div><div =
style=3D"border-right-style: none; border-bottom-style: none; =
border-left-style: none; border-width: initial; border-color: initial; =
border-top-style: solid; border-top-color: rgb(181, 196, 223); =
border-top-width: 1pt; padding-top: 3pt; padding-right: 0in; =
padding-bottom: 0in; padding-left: 0in; "><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><b><span style=3D"font-size: =
10pt; font-family: Tahoma, sans-serif; ">From:</span></b><span =
style=3D"font-size: 10pt; font-family: Tahoma, sans-serif; "><span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:sacm-bounces@ietf.org">sacm-bounces@ietf.org</a> =
[mailto:sacm-bounces@ietf.org]<span =
class=3D"Apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"Apple-converted-space">&nbsp;</span></b>Chandrashekhar =
B<br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Thursday, June 14, 2012 =
4:10 PM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>SCAP-DEV; <a =
href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Re: [sacm] Request for =
participants - Content Repository Specification =
Development<o:p></o:p></span></div></div></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; =
"><o:p>&nbsp;</o:p></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">We have hosted our SCAP Content Repository at<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"http://www.scaprepo.com" style=3D"color: blue; text-decoration: =
underline; ">www.scaprepo.com</a>. Feedback is certainly appreciated. A =
simple web service interface will be published =
soon.<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); "><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">Chandra.<o:p></o:p></span></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(31, 73, 125); "><o:p>&nbsp;</o:p></span></div><div><div =
style=3D"border-right-style: none; border-bottom-style: none; =
border-left-style: none; border-width: initial; border-color: initial; =
border-top-style: solid; border-top-color: rgb(181, 196, 223); =
border-top-width: 1pt; padding-top: 3pt; padding-right: 0in; =
padding-bottom: 0in; padding-left: 0in; "><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><b><span style=3D"font-size: =
10pt; font-family: Tahoma, sans-serif; ">From:</span></b><span =
style=3D"font-size: 10pt; font-family: Tahoma, sans-serif; "><span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:scap-dev@nist.gov" style=3D"color: blue; text-decoration: =
underline; ">scap-dev@nist.gov</a><span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:[mailto:scap-dev@nist.gov]" style=3D"color: blue; =
text-decoration: underline; ">[mailto:scap-dev@nist.gov]</a><span =
class=3D"Apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"Apple-converted-space">&nbsp;</span></b><a =
href=3D"mailto:Kent_Landfield@mcafee.com" style=3D"color: blue; =
text-decoration: underline; =
">Kent_Landfield@mcafee.com</a><br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Friday, May 11, 2012 10:14 =
PM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Multiple recipients of =
list<br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Request for participants - =
Content Repository Specification =
Development<o:p></o:p></span></div></div></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; =
"><o:p>&nbsp;</o:p></div><div><div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">Mike I love it when you tee something up like that=85. ;-) &nbsp;Thank =
you. ;)<o:p></o:p></span></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
"><o:p>&nbsp;</o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(31, 73, 125); ">Mike wrote:&nbsp;</span><span style=3D"color: =
black; "><o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">I still think that any specification for a repository is =
wishful thinking until someone builds one and learns the lessons it will =
just be another whitepaper spec. &nbsp;I believe the DoD needs to =
incorporate a metadata repository as part of it and other customizations =
that may not be useful for everyone.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">We need to talk more=85</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: black; =
"><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">If you are talking about a holistic, complete federated approach to a =
content repository, I some what agree. &nbsp;If you are talking about an =
organizational repository, I totally disagree. But you knew I would. =
;)</span><span style=3D"font-size: 12pt; font-family: 'Times New Roman', =
serif; color: black; "><o:p></o:p></span></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; "><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">Here is how I see the problem. &nbsp;There is an immediate need for =
SCAP and other related content to be served up inside an organization. =
&nbsp;Today we have situation where the standards allow us to provide =
sites the capability to have a single SCAP implemented policy they call =
official for their environment. Yes this is a rather simplistic since =
there are things such as targeting specific platforms, specific =
operational use needs, but for now lets agree SCAP is a massive =
improvement over the proprietary situations of the past. While we have =
created this standard content so that sites can implement their local =
site security once and then assure they are measuring all appropriately =
targeted devices the same way, we have failed to support the operational =
needs of the sites. &nbsp;We have a situation where no two vendors =
distribute content the same way. &nbsp;This causes massive problems for =
the administration staff when they need to incorporate a new SCAP =
enabled product into their architecture. &nbsp;They need to discover how =
the new product supports distributing SCAP content to it's various =
components. &nbsp;If they have one product then they do this one and =
they are done. &nbsp;If they have multiple products they will have to =
figure out how to minimize the impact by incorporating the update =
process for the new product into the existing SCAP security content =
processes. Now when the inevitable happens and the site staff needs to =
make a change to their security policy, they have to make the =
modifications to the benchmark or checks or both and then distribute =
those updates across their network. &nbsp;For each SCAP enabled product =
they have in place, they have doubled, tripled or more the work needed =
to make those updates available.&nbsp;<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
"><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">There is another content repository problem and that is the Federated =
Content Distribution. &nbsp;If you think global DNS you have a general =
frame of reference. &nbsp;The guidance authors need to be able to =
publish content in an authoritative manner so their content is updated =
in a timely fashion. &nbsp;This is a much harder problem to solve if =
there is no local organizational infrastructure to support it. =
;)<o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: black; =
"><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">So here is what I am thinking=85 &nbsp;We should consider addressing =
these as two separate but integrated efforts. &nbsp;I believe the =
Organizational Content Repository is the more critical piece that is =
actually easier to address. &nbsp;The Federated Content Distribution =
should be a subsequent effort integrating / augmenting the =
Organizational repository =
specification.&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; "><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">Mike, to your point that we need someone to build one first=85 That =
has happened already. &nbsp;I have one as do other vendors but what we =
don=92t have is the access specification. &nbsp;Ours are focused on our =
specific product needs. &nbsp;Additionally there is a company that has =
developed a commercial SCAP content repository that will be announced =
later this month. I won't steal their thunder but I was recently given a =
sneak peek at it and I must admit I was very impressed. &nbsp;Again, to =
your point, it has been done. What is needed to address the initial =
operational problem is to develop a specification that provides a =
consistent means for all SCAP products to retrieve the appropriate =
content as configured and managed but the site. =
&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
"><o:p>&nbsp;</o:p></span></div><p class=3D"MsoNormal" =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 1pt; font-size: 11pt; font-family: Calibri, sans-serif; =
"><span style=3D"color: black; ">TO THAT END=85.<o:p></o:p></span></p><div=
 style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
"><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">I am requesting participation from those in the community that see the =
need and want to put in the work to make this specification happen. =
&nbsp;I have talked to a couple of you but I do not want to assume your =
participation. &nbsp;If you are interested please contact me so we can =
get this started.&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; "><o:p>&nbsp;</o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">Thanks!<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
"><o:p>&nbsp;</o:p></span></div></div><div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><strong><span =
style=3D"font-size: 9pt; font-family: Arial, sans-serif; color: rgb(96, =
106, 113); ">Kent Landfield</span></strong><span style=3D"font-size: =
9pt; font-family: Arial, sans-serif; color: rgb(96, 106, 113); =
"><br><span class=3D"apple-style-span">Director Content Strategy, =
Architecture and Standards</span><br><br><strong><span =
style=3D"font-family: Arial, sans-serif; ">McAfee | An Intel =
Company</span></strong><br><span class=3D"apple-style-span">5000 =
Headquarters Dr.</span><br><span class=3D"apple-style-span">Plano, Texas =
75024</span><br><br><span class=3D"apple-style-span">Direct: =
+1.972.963.7096&nbsp;</span><br><span class=3D"apple-style-span">Mobile: =
+1.817.637.8026</span><br><strong><span style=3D"font-family: Arial, =
sans-serif; ">Web:&nbsp;</span></strong><span =
class=3D"apple-style-span"><a href=3D"http://www.mcafee.com/" =
style=3D"color: blue; text-decoration: underline; =
">www.mcafee.com</a></span></span><span style=3D"color: black; =
"><o:p></o:p></span></div></div></div></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
"><o:p>&nbsp;</o:p></span></div></div><div style=3D"border-right-style: =
none; border-bottom-style: none; border-left-style: none; border-width: =
initial; border-color: initial; border-top-style: solid; =
border-top-color: rgb(181, 196, 223); border-top-width: 1pt; =
padding-top: 3pt; padding-right: 0in; padding-bottom: 0in; padding-left: =
0in; "><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: =
0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><b><span style=3D"color: black; ">From:<span =
class=3D"Apple-converted-space">&nbsp;</span></span></b><span =
style=3D"color: black; ">&lt;Kinney&gt;, Michael A &lt;<a =
href=3D"mailto:m.kinne@radium.ncsc.mil" style=3D"color: blue; =
text-decoration: underline; =
">m.kinne@radium.ncsc.mil</a>&gt;<br><b>To:<span =
class=3D"Apple-converted-space">&nbsp;</span></b>David Waltermire &lt;<a =
href=3D"mailto:david.waltermire@nist.gov" style=3D"color: blue; =
text-decoration: underline; ">david.waltermire@nist.gov</a>&gt;, =
SCAP-DEV &lt;<a href=3D"mailto:SCAP-DEV@nist.gov" style=3D"color: blue; =
text-decoration: underline; ">SCAP-DEV@nist.gov</a>&gt;, "<a =
href=3D"mailto:sacm@ietf.org" style=3D"color: blue; text-decoration: =
underline; ">sacm@ietforg</a>" &lt;<a href=3D"mailto:sacm@ietf.org" =
style=3D"color: blue; text-decoration: underline; =
">sacm@ietf.org</a>&gt;<br><b>Subject:<span =
class=3D"Apple-converted-space">&nbsp;</span></b>Re: [sacm] =
[OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2012 at =
MITRE in Bedford, MA<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"font-size: 12pt; font-family: 'Times New =
Roman', serif; color: black; =
"><o:p>&nbsp;</o:p></span></div></div><blockquote =
id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"border-top-style: =
none; border-right-style: none; border-bottom-style: none; border-width: =
initial; border-color: initial; border-left-style: solid; =
border-left-color: rgb(181, 196, 223); border-left-width: 4.5pt; =
padding-top: 0in; padding-right: 0in; padding-bottom: 0in; padding-left: =
4pt; margin-left: 3.75pt; margin-top: 5pt; margin-right: 0in; =
margin-bottom: 5pt; "><div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">Dave,</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">I have no problem with webinars, I do want to keep developer =
days actionable and use it to make decisions, and vote and accomplish =
things good or bad.&nbsp; I do not want this to be an informational =
briefing conference.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">Thanks for the links.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">I still think that any specification for a repository is wishful =
thinking until someone builds one and learns the lessons it will just be =
another whitepaper spec. &nbsp;I believe the DoD needs to incorporate a =
metadata repository as part of it and other customizations that may not =
be useful for everyone.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">We need to talk more=85</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">-Mike&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div><div style=3D"border-right-style: none; =
border-bottom-style: none; border-left-style: none; border-width: =
initial; border-color: initial; border-top-style: solid; =
border-top-color: rgb(181, 196, 223); border-top-width: 1pt; =
padding-top: 3pt; padding-right: 0in; padding-bottom: 0in; padding-left: =
0in; "><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: =
0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><b><span style=3D"font-size: 10pt; font-family: Tahoma, =
sans-serif; color: black; ">From:</span></b><span style=3D"font-size: =
10pt; font-family: Tahoma, sans-serif; color: black; "><span =
class=3D"Apple-converted-space">&nbsp;</span>Waltermire, David A. [<a =
href=3D"mailto:david.waltermire@nist.gov" style=3D"color: blue; =
text-decoration: underline; ">mailto:david.waltermire@nist.gov</a>]<span =
class=3D"Apple-converted-space">&nbsp;</span><br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Tuesday, May 08, 2012 10:44 =
AM<br><b>To:</b><span class=3D"Apple-converted-space">&nbsp;</span>Kinney,=
 Michael A; SCAP-DEV;<span class=3D"Apple-converted-space">&nbsp;</span><a=
 href=3D"mailto:sacm@ietf.org" style=3D"color: blue; text-decoration: =
underline; ">sacm@ietf.org</a><br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>RE: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span style=3D"color: black; =
"><o:p></o:p></span></div></div></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">Mike,</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">What about having webinars in-place of the 30 minute =
briefs?</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">Regarding content management, we are building the prototype =
content repository for use in a production environment.&nbsp; As an open =
source project, it will be free for use by anyone interested.&nbsp; My =
thinking is that this project can bridge the gap until commercial =
solutions are available to augment it.&nbsp; This is a similar path that =
was followed with DNS (bind) and HTTP (apache).&nbsp; When it is ready =
for use, I am hoping to use it to host USGCB content.&nbsp; You would be =
welcome to use it for your needs.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">It is good that OCIL is moving forward.&nbsp; This is an =
important piece of supporting risk management and aspects of continuous =
monitoring.&nbsp; I would also like to see some discussion on OCIL at =
Developer Days.&nbsp; With the proposals we will likely have a sense of =
what needs to be discussed and what we can achieve consensus on outside =
the meeting.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">Remediation is a topic near and dear to my heart.&nbsp; I too =
would like to see it move forward.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">We just published the draft ASR specification for public =
comment.&nbsp; This specification supports enterprise aggregate =
reporting which greatly reduces the data volumes needed verses detailed =
host-based reports. This specification has been designed as a more =
robust replacement for LASR&nbsp; It can be used in continuous =
monitoring applications to support aggregate data reporting needs (e.g. =
FISMA reporting, &nbsp;CyberScope).</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">Here are the links:</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); "><a href=3D"http://csrc.nist.gov/publications/PubsDrafts.html" =
style=3D"color: blue; text-decoration: underline; =
">http://csrc.nist.gov/publications/PubsDrafts.html</a></span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(31, 73, 125); "><a =
href=3D"http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848" =
style=3D"color: blue; text-decoration: underline; =
">http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848</a></spa=
n><span style=3D"color: black; "><o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: rgb(31, 73, 125); =
">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">The primary reason we have suggested waiting on XCCDF is not the =
internationalization issue. Many vendors have commented that they are =
still working on implementing the XCCDF 1.2.1 specification. We will be =
in a better place in a few months once more development around XCCDF has =
occurred.&nbsp; As we consider changes to the SCAP stack to address OCIL =
and other issues, we will identify areas that need improvement in =
XCCDF.&nbsp; These are good and necessary discussions to have now, but =
we have a good deal of work to do before we are ready to open up =
XCCDF.&nbsp; My suggestion is to work on these related areas and then =
work up change proposals for XCCDF as needed.&nbsp; By that time we =
should be ready to work on a new revision of XCCDF.</span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(31, 73, 125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">I am also looking forward to the discussions at the =
conference.&nbsp; It has been too long.</span><span style=3D"color: =
black; "><o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">Sincerely,</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">Dave</span><span style=3D"color: black; =
"><o:p></o:p></span></div></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div><div style=3D"border-right-style: none; =
border-bottom-style: none; border-left-style: none; border-width: =
initial; border-color: initial; border-top-style: solid; =
border-top-color: rgb(181, 196, 223); border-top-width: 1pt; =
padding-top: 3pt; padding-right: 0in; padding-bottom: 0in; padding-left: =
0in; "><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: =
0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><b><span style=3D"font-size: 10pt; font-family: Tahoma, =
sans-serif; color: black; ">From:</span></b><span style=3D"font-size: =
10pt; font-family: Tahoma, sans-serif; color: black; "><span =
class=3D"Apple-converted-space">&nbsp;</span>Kinney, Michael A [<a =
href=3D"mailto:m.kinne@radium.ncscmil" style=3D"color: blue; =
text-decoration: underline; ">mailto:m.kinne@radium.ncsc.mil</a>]<span =
class=3D"Apple-converted-space">&nbsp;</span><br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Tuesday, May 08, 2012 7:09 =
AM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>SCAP-DEV<br><b>Cc:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Waltermire, David =
A.<br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>RE: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span style=3D"color: black; =
"><o:p></o:p></span></div></div></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">Kent,</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">It=92s good to read your thoughts, and a realistic actionable =
approach is indeed needed &nbsp;Since all the activity hasn=92t been on =
the lists a brief 1=8E2 hour recap may be in order to bring everyone up =
to speed since there has been a lot of activity on CPE/SWID, OCIl, =
MAEC/CybOX CEE and others.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">We could write a content repository specification, but without =
someone willing to stand one up it will be as valuable as the CCSS =
specification is today. &nbsp;I=92ve been trying for two years to get my =
management to get a coordinated effort together for the DoD to stand up =
a repository, it is a tough problem and will require funding with a =
tail, I=92m not sure a specification will solve that =
problem.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">We (DoD) have been putting a lot of effort into OCIL over the =
last year trying to make it useful in an enterprise environment and will =
be posting our ideas to the list before developer days it should have =
already started, we need to get consensus and a vote on how the =
community wishes to proceed.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">Remediation is stalled but I=92m making every effort to get it =
kick started from our perspective. I hope to assist in getting the draft =
ERI finished this year. &nbsp;We are writing some new STIG content and =
intend to used the draft CRE specification to insert CRE into the =
content so we (DoD) can do some automatic configuration fixes, part of a =
self healing network concept. It is just a start but the best we can do =
at this point.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">Enterprise reporting is an interesting subject, since XML adds =
size to and content to roll up reporting, in any enterprise of size the =
problem gets greater, I look forward to your thoughts on that =
subject.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">I am concerned that the internationalization efforts are =
detracting from efforts to meet use cases, we have some things we would =
like changed in XCCDF to support our OCIl use case and I have been told =
that I need to wait. I didn=92t think that a move to =
internationalization should impede efforts to move forward with use =
cases.</span><span style=3D"color: black; "><o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: rgb(31, 73, 125); =
">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">I look forward to talking with you at the =
conference.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"font-size: 10pt; =
font-family: Arial, sans-serif; color: rgb(31, 73, 125); =
">v/r</span><span style=3D"color: black; "><o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"font-size: 10pt; font-family: Arial, =
sans-serif; color: rgb(31, 73, 125); ">&nbsp;</span><span style=3D"color: =
black; "><o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"font-size: =
10pt; font-family: Arial, sans-serif; color: rgb(31, 73, 125); ">Mike =
Kinney</span><span style=3D"color: black; "><o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"font-size: 10pt; font-family: Arial, =
sans-serif; color: rgb(31, 73, 125); ">Project Director</span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125); ">Computer Network Defense Research and Technology (CND =
R&amp;T) Office</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"font-size: 10pt; =
font-family: Arial, sans-serif; color: rgb(31, 73, 125); ">9800 Savage =
Road Ste 6767<br>Ft Meade, MD 20755-6767<br></span><span =
style=3D"font-size: 10pt; color: rgb(31, 73, 125); ">Phone: =
410-854-4422<br>NSTS: 968-8886<br>Fax 410-854-4681</span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125); "><a href=3D"mailto:M.kinne@radium.ncsc.mil" style=3D"color: =
blue; text-decoration: underline; "><span style=3D"color: rgb(102, 0, =
0); ">makinn2@nsa.gov</span></a></span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div><div style=3D"border-right-style: none; =
border-bottom-style: none; border-left-style: none; border-width: =
initial; border-color: initial; border-top-style: solid; =
border-top-color: rgb(181, 196, 223); border-top-width: 1pt; =
padding-top: 3pt; padding-right: 0in; padding-bottom: 0in; padding-left: =
0in; "><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: =
0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><b><span style=3D"font-size: 10pt; font-family: Tahoma, =
sans-serif; color: black; ">From:</span></b><span style=3D"font-size: =
10pt; font-family: Tahoma, sans-serif; color: black; "><a =
href=3D"mailto:scap-dev@nist.gov" style=3D"color: blue; text-decoration: =
underline; ">scap-dev@nist.gov</a><span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:[mailto:scap-dev@nist.gov]" style=3D"color: blue; =
text-decoration: underline; ">[mailto:scap-dev@nist.gov]</a><span =
class=3D"Apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"Apple-converted-space">&nbsp;</span></b>Waltermire, David =
A.<br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Monday, May 07, 2012 7:09 =
PM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Multiple recipients of =
list<br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>RE: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span style=3D"color: black; =
"><o:p></o:p></span></div></div></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">Kent,</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">I like what you are saying here.&nbsp; We are also in support of =
this type of approach.&nbsp; We would like to see some community =
discussion around what are the key areas/priorities that the community =
would like to see discussed at Dev Days.&nbsp; Your topics below look =
like a good start. The SACM list might be a better venue than the OVAL =
list for this discussion.&nbsp; For each area we should focus the =
discussion around developing objectives for each session.&nbsp; The =
sessions can be time boxed based on what would be a reasonable amount of =
time to accomplish each objective.&nbsp; For example if continuous =
monitoring is a priority and collectively it takes 3 days to work =
through all the objectives, I see no problem with that.&nbsp; We can =
also keep a few sessions =93on deck=94 if all the objectives are reached =
and we complete all the scheduled sessions early.</span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(31, 73, 125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">Thoughts?</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">Sincerely,</span><span style=3D"color: black; =
"><o:p></o:p></span></div></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, =
73, 125); ">David Waltermire</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">SCAP Architect</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(31, 73, =
125); ">National Institute of Standards and Technology</span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(31, 73, 125); ">(301) 975-3390</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: black; "><a =
href=3D"mailto:david.waltermire@nist.gov" style=3D"color: blue; =
text-decoration: underline; =
">david.waltermire@nist.gov</a><o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: rgb(31, 73, 125); =
">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div><div style=3D"border-right-style: none; =
border-bottom-style: none; border-left-style: none; border-width: =
initial; border-color: initial; border-top-style: solid; =
border-top-color: rgb(181, 196, 223); border-top-width: 1pt; =
padding-top: 3pt; padding-right: 0in; padding-bottom: 0in; padding-left: =
0in; "><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: =
0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><b><span style=3D"font-size: 10pt; font-family: Tahoma, =
sans-serif; color: black; ">From:</span></b><span style=3D"font-size: =
10pt; font-family: Tahoma, sans-serif; color: black; "><a =
href=3D"mailto:scap-dev@nist.gov" style=3D"color: blue; text-decoration: =
underline; ">scap-dev@nist.gov</a><span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:[mailto:scap-dev@nist.gov]" style=3D"color: blue; =
text-decoration: underline; ">[mailto:scap-dev@nist.gov]</a><span =
class=3D"Apple-converted-space">&nbsp;</span><b>On Behalf Of<span =
class=3D"Apple-converted-space">&nbsp;</span></b><a =
href=3D"mailto:Kent_Landfield@mcafee.com" style=3D"color: blue; =
text-decoration: underline; =
">Kent_Landfield@mcafee.com</a><br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Monday, May 07, 2012 4:25 =
PM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>SCAP-DEV<br><b>Subject:</b><s=
pan class=3D"Apple-converted-space">&nbsp;</span>Re: =
[OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2012 at =
MITRE in Bedford, MA</span><span style=3D"color: black; =
"><o:p></o:p></span></div></div></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div><div><div><div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">All,<o:p></o:p></span></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">I would like to discuss the format for the SCAP Developer Days =
that seems to be listed below.<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">I see this appears to follow a path we have discussed in the =
past as the way not to hold a Dev Days event. &nbsp;We have been trying =
to get away from 'Death by Powerpoint' and back to the type of event we =
held years ago when we were highly productive. &nbsp;In the past we had =
a topic to be discussed and a time box to work within. &nbsp;That =
allowed us to have very active brainstorming sessions in a high =
bandwidth environment.<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">At past Summer events we have got into a pattern of lots of =
powerpoint, lots of status of the efforts and very little discussion =
about things that need active discussions. &nbsp;We need to keep moving =
forward and making progress as an effort. We can get status from various =
places such as the lists, a presentation being sent out in advance, a =
webinar if it is felt there will be questions and answers from those =
that are new to the efforts. &nbsp;We have a limited amount of time and =
all who are attending are investing a great deal of time and money to be =
there. &nbsp;We should not &nbsp;be spending a great deal of time =
reeducating everyone when we could be focused on advancing needed =
efforts.<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">&nbsp;<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; ">The type of approach to a =
Dev Days event was discussed at the last Summer Dev Days. &nbsp;I have =
seen the following work quite well in other =
efforts.<o:p></o:p></span></div></div><ol start=3D"1" type=3D"1" =
style=3D"margin-bottom: 0in; "><li class=3D"MsoNormal" =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; color: black; ">Presentations are sent out to the attendees =
and the lists a week in advance<o:p></o:p></li><li class=3D"MsoNormal" =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; color: black; ">Status for any effort is limited to 30 =
minutes<o:p></o:p></li><li class=3D"MsoNormal" style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; color: black; ">Focused =
brainstorming time should be established for certain areas that need =
real work by the community<o:p></o:p></li><li class=3D"MsoNormal" =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; color: black; ">Efforts to be discussed should be based on =
needs of the security automation space to move existing efforts to =
completion.<o:p></o:p></li></ol><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">For example:<o:p></o:p></span></div></div><div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">&nbsp;<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; ">Continuous monitoring is a =
major direction the efforts are becoming involved with. There are going =
to be things we need to do as a security automation community to be able =
to accomplish what is listed in the CAESARS FE. &nbsp;There are =
interfaces that need to be worked and established. &nbsp;That is one =
area that is not listed below. &nbsp;CM will have a major impact on all =
of us in the next couple years and it is being ignored. &nbsp;We can't =
keep trying to solve what has already been solved. &nbsp;We need to =
address the needed interface development now. This is an effort that =
could take nearly a whole day by =
itself.<o:p></o:p></span></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">Operationally we have a real need to be able to deliver SCAP =
content internally within an organization. Today the SCAP vendors cannot =
share a single local site security policy (XCCDF + OVAL + CPE +=85) =
without the site staff having to go to each of the individual products =
and figuring out how to inject that new or updated policy into that =
products delivery mechanisms. &nbsp;That is limiting sites from wanting =
to buy multiple focused SCAP products since they are such a pain to =
manage from a content perspective. &nbsp;It is easier to buy from one =
vendor that has a single means for distributing content than it is to =
deal with the management issues that having multiple SCAP products =
presents. &nbsp;We need to have at least an entire 1/2 a day on the =
development of a Content Repository =
specification.<o:p></o:p></span></div></div><div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">&nbsp;<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; ">OCIL is a positive and a =
negative at the same time. It has real value that is being underutilized =
and under implemented because of the limitations of how it addresses =
uses in an enterprise environment. &nbsp;People don't need security =
automation to do things on/for a single host. &nbsp;They need security =
automation to focus on the enterprise issues that reduce their costs and =
improve their efficiencies. &nbsp;OCIL is failing in the enterprise and =
we all understand that. &nbsp;We need to address developing a definitive =
solution for incorporating OCIL into the enterprise and that means into =
the existing specifications. Scheduling and tracking are key to it's =
success. &nbsp;We need to make that happen. &nbsp;This too needs a =
focused brainstorming time box to discuss =
options.<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">&nbsp;<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; ">I am really disappointed =
that Remediation is not on the list below=85 &nbsp;Yes, last Summer Dev =
Days, the time spent on Remediation was wasted time but that does not =
mean we should ignore it and not try to make some real progress. =
&nbsp;As far as I am concerned we need to reboot the remediation effort. =
&nbsp;We cannot keep being the set of specifications / tools that act as =
the little boy crying "Wolf" in the night. &nbsp;We need to be able to =
find and fix issues if we are going to really make a difference in =
organizational security postures. &nbsp;But today we think it is too =
hard so we don't try ? &nbsp;I think we need a couple hours to discuss =
the reboot of the effort even if that means minimizing work already =
done.<o:p></o:p></span></div></div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">A focused discussion on enterprise reporting is also =
critically needed. &nbsp;For the vendors here, we have all gone through =
the Cyberscope goat rope, delivering limited capabilities to specific =
data call requirements of the Federal Agencies. &nbsp;The initial effort =
was a mess, did little more than prove it was possible and cause the =
vendor community a great deal of thrashing to put a kludgey 'solution' =
in place. &nbsp;Reality is all our customers need roll up reporting and =
an infrastructure that supports it. &nbsp;A data call should not be =
special to anyone other than the agencies responding. The tools should =
be able to select the types of data needed and deliver that on a =
scheduled basis automatically. &nbsp; &nbsp;Enterprise Reporting =
pertains to commercial as well as Federal customers. &nbsp;We need to =
focus some time on what that would look like using the ARF and ASR as =
the foundational pieces. &nbsp;But there are missing pieces=85. &nbsp;We =
need this discussed.<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">I would hope we can make this summer's SCAP Dev Days useful in =
advancing the security automation efforts by addressing some of the more =
critical issues our customers are facing now or will be facing in the =
very short term. &nbsp;Status presentations are not interesting to those =
active in the efforts. &nbsp;Let's try to do those before we get to =
Bedford so we can real make some progress while we are all in the same =
room. &nbsp;This is always a big event for the 'consensus of the =
willing' that assemble and driven to see security automation make a =
difference. &nbsp;Let's see if we can have an event that, when we all =
walk out the last day, we all feel that every minute was well spent and =
moves us forward.<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">Thanks.<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><strong><span =
style=3D"font-size: 9pt; font-family: Arial, sans-serif; color: rgb(96, =
106, 113); ">Kent Landfield</span></strong><span style=3D"font-size: =
9pt; font-family: Arial, sans-serif; color: rgb(96, 106, 113); =
"><br><span class=3D"apple-style-span">Director Content Strategy, =
Architecture and Standards</span><br><br><strong><span =
style=3D"font-family: Arial, sans-serif; ">McAfee | An Intel =
Company</span></strong><br><span class=3D"apple-style-span">5000 =
Headquarters Dr.</span><br><span class=3D"apple-style-span">Plano, Texas =
75024</span><br><br><span class=3D"apple-style-span">Direct: =
+1.972.963.7096&nbsp;</span><br><span class=3D"apple-style-span">Mobile: =
+1.817.637.8026</span><br><strong><span style=3D"font-family: Arial, =
sans-serif; ">Web:&nbsp;</span></strong><span =
class=3D"apple-style-span"><a href=3D"http://www.mcafee.com/" =
style=3D"color: blue; text-decoration: underline; =
">www.mcafee.com</a></span></span><span style=3D"color: black; =
"><o:p></o:p></span></div></div></div></div></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div></div><div style=3D"border-right-style: =
none; border-bottom-style: none; border-left-style: none; border-width: =
initial; border-color: initial; border-top-style: solid; =
border-top-color: rgb(181, 196, 223); border-top-width: 1pt; =
padding-top: 3pt; padding-right: 0in; padding-bottom: 0in; padding-left: =
0in; "><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: =
0in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><b><span style=3D"color: black; ">From:<span =
class=3D"Apple-converted-space">&nbsp;</span></span></b><span =
style=3D"color: black; ">&lt;Boczenowski&gt;, Steve &lt;<a =
href=3D"mailto:sboczeno@MITRE.ORG" style=3D"color: blue; =
text-decoration: underline; =
">sboczeno@MITRE.ORG</a>&gt;<br><b>Reply-To:<span =
class=3D"Apple-converted-space">&nbsp;</span></b>"OVAL Developer List =
(Closed Public Discussion)" &lt;<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG" style=3D"color: =
blue; text-decoration: underline; =
">OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG</a>&gt;<br><b>To:<span =
class=3D"Apple-converted-space">&nbsp;</span></b>"<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG" style=3D"color: =
blue; text-decoration: underline; =
">OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG</a>" &lt;<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG" style=3D"color: =
blue; text-decoration: underline; =
">OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG</a>&gt;<br><b>Subject:<span =
class=3D"Apple-converted-space">&nbsp;</span></b>Re: =
[OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2012 at =
MITRE in Bedford, MA<o:p></o:p></span></div></div><div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"font-size: 12pt; font-family: 'Times New =
Roman', serif; color: black; ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div></div><blockquote =
id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"border-top-style: =
none; border-right-style: none; border-bottom-style: none; border-width: =
initial; border-color: initial; border-left-style: solid; =
border-left-color: rgb(181, 196, 223); border-left-width: 4.5pt; =
padding-top: 0in; padding-right: 0in; padding-bottom: 0in; padding-left: =
4pt; margin-left: 3.75pt; margin-top: 5pt; margin-right: 0in; =
margin-bottom: 5pt; "><div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, =
64, 97); ">Frank;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">We hope to have the registration site up next week.&nbsp; The =
event will be during the week of July 9 =96 starting Monday at 10:00 AM =
and ending on Friday at 12:00.</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">Meanwhile, we are working on the agenda and are currently =
considering this list of topics:</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; text-indent: 0.5in; "><span =
style=3D"color: rgb(37, 64, 97); ">CCE</span><span style=3D"color: =
black; "><o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(37, 64, 97); ">CPE/SWID</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">CEE</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">XCCDF</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">OVAL</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">ASR</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">Enterprise OCIL</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">CybOX/MAEC</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">Federated Content Repository Spec</span><span style=3D"color: =
black; "><o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 rgb(37, 64, 97); ">Endpoint Reporting for Continuous Monitoring and =
Compliance (ERCC)</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">MILE</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">TAXII</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">IF-M for SCAP</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">IF-MAP</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">SCAP Releases</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">SCAP and IETF</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">NETCONF and SCAP</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">Steve</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: rgb(37, 64, =
97); ">&nbsp;</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div><div style=3D"border-right-style: none; =
border-bottom-style: none; border-left-style: none; border-width: =
initial; border-color: initial; border-top-style: solid; =
border-top-color: rgb(181, 196, 223); border-top-width: 1pt; =
padding-top: 3pt; padding-right: 0in; padding-bottom: 0in; padding-left: =
0in; "><div style=3D"margin-top: 0in; margin-right: 0in; margin-left: =
2in; margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><b><span style=3D"font-size: 10pt; font-family: Tahoma, =
sans-serif; color: black; ">From:</span></b><span style=3D"font-size: =
10pt; font-family: Tahoma, sans-serif; color: black; "><span =
class=3D"Apple-converted-space">&nbsp;</span>Frank Lindsay Acker [<a =
href=3D"mailto:afrank@NOVA.EDU" style=3D"color: blue; text-decoration: =
underline; ">mailto:afrank@NOVA.EDU</a>]<span =
class=3D"Apple-converted-space">&nbsp;</span><br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Tuesday, May 01, 2012 9:32 =
AM<br><b>To:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>oval-developer-list OVAL =
Developer List/Closed Public Discussion<br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Re: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span style=3D"color: black; =
"><o:p></o:p></span></div></div></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">&nbsp;<o:p></o:p></span></div><div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span =
style=3D"font-size: 10pt; font-family: Tahoma, sans-serif; color: black; =
">Steve....<br><br>Has there been any additional information regarding =
this event?<br><br>Thanks,<br>Frank Acker</span><span style=3D"color: =
black; "><o:p></o:p></span></div><div><div style=3D"margin-left: 0.5in; =
"><div class=3D"MsoNormal" align=3D"center" style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif; text-align: center; "><span =
style=3D"font-size: 12pt; font-family: 'Times New Roman', serif; color: =
black; "><hr size=3D"2" width=3D"100%" =
align=3D"center"></span></div></div><div id=3D"divRpF955236"><p =
class=3D"MsoNormal" style=3D"margin-top: 0in; margin-right: 0in; =
margin-left: 0.5in; margin-bottom: 12pt; font-size: 11pt; font-family: =
Calibri, sans-serif; "><b><span style=3D"font-size: 10pt; font-family: =
Tahoma, sans-serif; color: black; ">From:</span></b><span =
style=3D"font-size: 10pt; font-family: Tahoma, sans-serif; color: black; =
"><span class=3D"Apple-converted-space">&nbsp;</span>Boczenowski, Steve =
[<a href=3D"mailto:sboczeno@MITRE.ORG" style=3D"color: blue; =
text-decoration: underline; =
">sboczeno@MITRE.ORG</a>]<br><b>Sent:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>Tuesday, March 20, 2012 =
16:38<br><b>To:</b><span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG" style=3D"color: =
blue; text-decoration: underline; =
">OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG</a><br><b>Subject:</b><span =
class=3D"Apple-converted-space">&nbsp;</span>[OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span style=3D"color: black; =
"><o:p></o:p></span></p></div><div><div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">Save the Date: week of July 9, =
2012<o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
0in; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">This year=92s MITRE-hosted Security Automation Developer Days =
event will be held during the week of July 9, 2012 at MITRE=92s facility =
in Bedford, MA.<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">Details to follow.<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0.5in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">Regards,<o:p></o:p></span></div><div style=3D"margin-top: 0in; =
margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">&nbsp;&nbsp;&nbsp; Steve<o:p></o:p></span></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0.5in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"color: black; =
">&nbsp;<o:p></o:p></span></div><p class=3D"MsoNormal" =
style=3D"margin-top: 0in; margin-right: 343.5pt; margin-left: 0.5in; =
margin-bottom: 4pt; font-size: 11pt; font-family: Calibri, sans-serif; =
"><span style=3D"font-size: 8pt; font-family: Arial, sans-serif; color: =
rgb(31, 73, 125); =
">______________________________________________</span><span =
style=3D"color: black; "><o:p></o:p></span></p><p class=3D"MsoNormal" =
style=3D"margin-top: 0in; margin-right: 343.5pt; margin-left: 0.5in; =
margin-bottom: 4pt; font-size: 11pt; font-family: Calibri, sans-serif; =
"><i><span style=3D"font-family: Arial, sans-serif; color: rgb(31, 73, =
125); ">Steph</span><span style=3D"color: rgb(31, 73, 125); ">en P. =
Boczenowski</span></i><span style=3D"color: black; =
"><o:p></o:p></span></p><p class=3D"MsoNormal" style=3D"margin-top: 0in; =
margin-right: 343.5pt; margin-left: 0.5in; margin-bottom: 2pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125); ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The<span =
class=3D"Apple-converted-space">&nbsp;</span></span><span =
style=3D"font-size: 10pt; font-family: MITRE; color: rgb(51, 102, 255); =
">MITRE</span><span style=3D"font-size: 10pt; font-family: Arial, =
sans-serif; color: rgb(31, 73, 125); "><span =
class=3D"Apple-converted-space">&nbsp;</span>Corporation</span><span =
style=3D"color: black; "><o:p></o:p></span></p><div style=3D"margin-top: =
0in; margin-right: 343.5pt; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125); ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Office: (781) =
271-7682</span><span style=3D"color: black; =
"><o:p></o:p></span></div><div style=3D"margin-top: 0in; margin-right: =
343.5pt; margin-left: 0.5in; margin-bottom: 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif; "><span style=3D"font-size: 10pt; =
font-family: Arial, sans-serif; color: rgb(31, 73, 125); =
">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Cell: (978) 302-3849</span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 343.5pt; margin-left: 0.5in; margin-bottom: =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; "><span =
style=3D"font-size: 10pt; font-family: Arial, sans-serif; color: rgb(31, =
73, 125); ">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a =
href=3D"mailto:sboczeno@mitre.org" target=3D"_blank" style=3D"color: =
blue; text-decoration: underline; ">sboczeno@mitre.org</a></span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span style=3D"color:=
 black; ">&nbsp;<o:p></o:p></span></div></div><div style=3D"margin-top: =
0in; margin-right: 0in; margin-left: 0.5in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span =
style=3D"font-size: 12pt; font-family: 'Times New Roman', serif; color: =
black; ">To unsubscribe, send an email message to<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG" style=3D"color: blue; =
text-decoration: underline; ">LISTSERV@LISTS.MITRE.ORG</a><span =
class=3D"Apple-converted-space">&nbsp;</span>with SIGNOFF =
OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG" =
style=3D"color: blue; text-decoration: underline; =
">OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG</a>.</span><span =
style=3D"color: black; "><o:p></o:p></span></div></div></div></div><div =
style=3D"margin-top: 0in; margin-right: 0in; margin-left: 0.5in; =
margin-bottom: 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif; "><span style=3D"font-size: 12pt; font-family: 'Times New =
Roman', serif; color: black; ">To unsubscribe, send an email message =
to<span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG" style=3D"color: blue; =
text-decoration: underline; ">LISTSERV@LISTS.MITRE.ORG</a><span =
class=3D"Apple-converted-space">&nbsp;</span>with SIGNOFF =
OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG" =
style=3D"color: blue; text-decoration: underline; =
">OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG</a>.</span><span =
style=3D"color: black; "><o:p></o:p></span></div><div style=3D"margin-top:=
 0in; margin-right: 0in; margin-left: 0in; margin-bottom: 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; "><span =
style=3D"font-size: 12pt; font-family: 'Times New Roman', serif; color: =
black; ">To unsubscribe, send an email message to<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG" style=3D"color: blue; =
text-decoration: underline; ">LISTSERV@LISTS.MITRE.ORG</a><span =
class=3D"Apple-converted-space">&nbsp;</span>with SIGNOFF =
OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG" =
style=3D"color: blue; text-decoration: underline; =
">OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG</a>.</span><span =
style=3D"color: black; =
"><o:p></o:p></span></div></div></div></blockquote></div></div></blockquot=
e></div>_______________________________________________<br>sacm mailing =
list<br><a =
href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>https://www.ietf.org/ma=
ilman/listinfo/sacm</div></blockquote></div><br></body></html>=

--Apple-Mail=_6240EF91-60C2-4BA3-ABE4-7EB0B936FC78--

From bchandra@secpod.com  Sat Jun 16 13:34:17 2012
Return-Path: <bchandra@secpod.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F1E4F21F850D for <sacm@ietfa.amsl.com>; Sat, 16 Jun 2012 13:34:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.058
X-Spam-Level: 
X-Spam-Status: No, score=-0.058 tagged_above=-999 required=5 tests=[AWL=1.300,  BAYES_00=-2.599, HTML_MESSAGE=0.001, SARE_LWSHORTT=1.24]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iS67hvJUOA1a for <sacm@ietfa.amsl.com>; Sat, 16 Jun 2012 13:34:04 -0700 (PDT)
Received: from cpanel23.interactivedns.com (cpanel23.interactivedns.com [184.173.122.2]) by ietfa.amsl.com (Postfix) with ESMTP id BA28E21F84EC for <sacm@ietf.org>; Sat, 16 Jun 2012 13:34:03 -0700 (PDT)
Received: from [122.172.44.175] (port=26223 helo=hpPC) by cpanel23.interactivedns.com with esmtpsa (TLSv1:AES128-SHA:128) (Exim 4.77) (envelope-from <bchandra@secpod.com>) id 1Sfzgl-0003lq-E0; Sun, 17 Jun 2012 02:03:48 +0530
From: "Chandrashekhar B" <bchandra@secpod.com>
To: "'Luis Nunez'" <lnunez@c3isecurity.com>, "'Waltermire, David A.'" <david.waltermire@nist.gov>
References: <15D0981C9BE53042A4C9D0F3D0B6826B2900F2@MSIS-GH1-UEA10.corp.nsa.gov>	<CBD00675.32964%kent_landfield@mcafee.com>	<00a801cd4a69$aba5be40$02f13ac0$@secpod.com>	<D7A0423E5E193F40BE6E94126930C4930B9BA83FFD@MBCLUSTER.xchange.nist.gov> <34425F2D-4172-4E61-89B8-00AD6BB6462E@c3isecurity.com>
In-Reply-To: <34425F2D-4172-4E61-89B8-00AD6BB6462E@c3isecurity.com>
Date: Sun, 17 Jun 2012 02:03:38 +0530
Organization: SecPod Technologies
Message-ID: <021101cd4bff$527d27d0$f7777770$@secpod.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0212_01CD4C2D.6C4394A0"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQIK+AsmsxvscjAWr3S8jTQP4mAzmQJt5r4nAhycR3IBkntfiAI5rRVflj9S9sA=
Content-Language: en-us
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - cpanel23.interactivedns.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - secpod.com
X-Source: 
X-Source-Args: 
X-Source-Dir: 
Cc: 'SCAP-DEV' <SCAP-DEV@nist.gov>, sacm@ietf.org
Subject: Re: [sacm] Request for participants - Content Repository	Specification Development
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: bchandra@secpod.com
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 16 Jun 2012 20:34:17 -0000

This is a multipart message in MIME format.

------=_NextPart_000_0212_01CD4C2D.6C4394A0
Content-Type: text/plain;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

If you type "What to search", it points to the FQA page J

=20

You can search based on all SCAP elements (Platform, product, class, =
family,
access complexity, availability, vendor.) which are identified as =
keywords.
There are additional handlers for like 'bulletin' is Microsoft security
bulletins and 'benchmark' is compliance etc. If it doesn't fall into the
above, it does text based search for queries like 'denial of service', =
for
example. I think we have covered large number of combinations that way.=20

=20

If you type in any ID, it'll directly go to the relation page. Good part =
is
it can learn new queries, please let us know if something doesn't work.

=20

Thanks,

Chandra.=20

=20

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of =
Luis
Nunez
Sent: Saturday, June 16, 2012 1:04 AM
To: Waltermire, David A.
Cc: SCAP-DEV; bchandra@secpod.com; sacm@ietf.org
Subject: Re: [sacm] Request for participants - Content Repository
Specification Development

=20

here is the faq with some samples http://scaprepo.com/faq.html

=20

cve access complexity high

all vulnerabilities from jan 2011





-ln

=20

=20

=20

On Jun 15, 2012, at 3:23 PM, Waltermire, David A. wrote:





I am not sure how to use the search page properly.  Would you please =
provide
some example searches?

=20

Sincerely,

Dave

=20

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of
Chandrashekhar B
Sent: Thursday, June 14, 2012 4:10 PM
To: SCAP-DEV; sacm@ietf.org
Subject: Re: [sacm] Request for participants - Content Repository
Specification Development

=20

We have hosted our SCAP Content Repository at www.scaprepo.com. Feedback =
is
certainly appreciated. A simple web service interface will be published
soon.

=20

Chandra.

=20

From: scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of
Kent_Landfield@mcafee.com
Sent: Friday, May 11, 2012 10:14 PM
To: Multiple recipients of list
Subject: Request for participants - Content Repository Specification
Development

=20

Mike I love it when you tee something up like that.. ;-)  Thank you. ;)

=20

Mike wrote:=20

I still think that any specification for a repository is wishful =
thinking
until someone builds one and learns the lessons it will just be another
whitepaper spec.  I believe the DoD needs to incorporate a metadata
repository as part of it and other customizations that may not be useful =
for
everyone.

We need to talk more.

=20

If you are talking about a holistic, complete federated approach to a
content repository, I some what agree.  If you are talking about an
organizational repository, I totally disagree. But you knew I would. ;)

=20

Here is how I see the problem.  There is an immediate need for SCAP and
other related content to be served up inside an organization.  Today we =
have
situation where the standards allow us to provide sites the capability =
to
have a single SCAP implemented policy they call official for their
environment. Yes this is a rather simplistic since there are things such =
as
targeting specific platforms, specific operational use needs, but for =
now
lets agree SCAP is a massive improvement over the proprietary situations =
of
the past. While we have created this standard content so that sites can
implement their local site security once and then assure they are =
measuring
all appropriately targeted devices the same way, we have failed to =
support
the operational needs of the sites.  We have a situation where no two
vendors distribute content the same way.  This causes massive problems =
for
the administration staff when they need to incorporate a new SCAP =
enabled
product into their architecture.  They need to discover how the new =
product
supports distributing SCAP content to it's various components.  If they =
have
one product then they do this one and they are done.  If they have =
multiple
products they will have to figure out how to minimize the impact by
incorporating the update process for the new product into the existing =
SCAP
security content processes. Now when the inevitable happens and the site
staff needs to make a change to their security policy, they have to make =
the
modifications to the benchmark or checks or both and then distribute =
those
updates across their network.  For each SCAP enabled product they have =
in
place, they have doubled, tripled or more the work needed to make those
updates available.=20

=20

There is another content repository problem and that is the Federated
Content Distribution.  If you think global DNS you have a general frame =
of
reference.  The guidance authors need to be able to publish content in =
an
authoritative manner so their content is updated in a timely fashion.  =
This
is a much harder problem to solve if there is no local organizational
infrastructure to support it. ;)

=20

So here is what I am thinking.  We should consider addressing these as =
two
separate but integrated efforts.  I believe the Organizational Content
Repository is the more critical piece that is actually easier to =
address.
The Federated Content Distribution should be a subsequent effort =
integrating
/ augmenting the Organizational repository specification.=20

=20

Mike, to your point that we need someone to build one first. That has
happened already.  I have one as do other vendors but what we don't have =
is
the access specification.  Ours are focused on our specific product =
needs.
Additionally there is a company that has developed a commercial SCAP =
content
repository that will be announced later this month. I won't steal their
thunder but I was recently given a sneak peek at it and I must admit I =
was
very impressed.  Again, to your point, it has been done. What is needed =
to
address the initial operational problem is to develop a specification =
that
provides a consistent means for all SCAP products to retrieve the
appropriate content as configured and managed but the site. =20

=20

TO THAT END..

=20

I am requesting participation from those in the community that see the =
need
and want to put in the work to make this specification happen.  I have
talked to a couple of you but I do not want to assume your =
participation.
If you are interested please contact me so we can get this started.=20

=20

Thanks!

=20

Kent Landfield
Director Content Strategy, Architecture and Standards

McAfee | An Intel Company
5000 Headquarters Dr.
Plano, Texas 75024

Direct: +1.972.963.7096=20
Mobile: +1.817.637.8026
Web: www.mcafee.com <http://www.mcafee.com/>=20

=20

From: <Kinney>, Michael A <m.kinne@radium.ncsc.mil>
To: David Waltermire <david.waltermire@nist.gov>, SCAP-DEV
<SCAP-DEV@nist.gov>, "sacm@ietforg <mailto:sacm@ietf.org> " =
<sacm@ietf.org>
Subject: Re: [sacm] [OVAL-DEVELOPER-LIST] Security Automation Developer
Days: Summer 2012 at MITRE in Bedford, MA

=20

Dave,

I have no problem with webinars, I do want to keep developer days =
actionable
and use it to make decisions, and vote and accomplish things good or =
bad.  I
do not want this to be an informational briefing conference.

Thanks for the links.

=20

I still think that any specification for a repository is wishful =
thinking
until someone builds one and learns the lessons it will just be another
whitepaper spec.  I believe the DoD needs to incorporate a metadata
repository as part of it and other customizations that may not be useful =
for
everyone.

We need to talk more.

=20

-Mike=20

=20

From: Waltermire, David A. [mailto:david.waltermire@nist.gov]=20
Sent: Tuesday, May 08, 2012 10:44 AM
To: Kinney, Michael A; SCAP-DEV; sacm@ietf.org
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Mike,

=20

What about having webinars in-place of the 30 minute briefs?

=20

Regarding content management, we are building the prototype content
repository for use in a production environment.  As an open source =
project,
it will be free for use by anyone interested.  My thinking is that this
project can bridge the gap until commercial solutions are available to
augment it.  This is a similar path that was followed with DNS (bind) =
and
HTTP (apache).  When it is ready for use, I am hoping to use it to host
USGCB content.  You would be welcome to use it for your needs.

=20

It is good that OCIL is moving forward.  This is an important piece of
supporting risk management and aspects of continuous monitoring.  I =
would
also like to see some discussion on OCIL at Developer Days.  With the
proposals we will likely have a sense of what needs to be discussed and =
what
we can achieve consensus on outside the meeting.

=20

Remediation is a topic near and dear to my heart.  I too would like to =
see
it move forward.

=20

We just published the draft ASR specification for public comment.  This
specification supports enterprise aggregate reporting which greatly =
reduces
the data volumes needed verses detailed host-based reports. This
specification has been designed as a more robust replacement for LASR  =
It
can be used in continuous monitoring applications to support aggregate =
data
reporting needs (e.g. FISMA reporting,  CyberScope).

=20

Here are the links:

=20

http://csrc.nist.gov/publications/PubsDrafts.html

http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848

=20

The primary reason we have suggested waiting on XCCDF is not the
internationalization issue. Many vendors have commented that they are =
still
working on implementing the XCCDF 1.2.1 specification. We will be in a
better place in a few months once more development around XCCDF has
occurred.  As we consider changes to the SCAP stack to address OCIL and
other issues, we will identify areas that need improvement in XCCDF.  =
These
are good and necessary discussions to have now, but we have a good deal =
of
work to do before we are ready to open up XCCDF.  My suggestion is to =
work
on these related areas and then work up change proposals for XCCDF as
needed.  By that time we should be ready to work on a new revision of =
XCCDF.

=20

I am also looking forward to the discussions at the conference.  It has =
been
too long.

=20

Sincerely,

Dave

=20

From: Kinney, Michael A [mailto:m.kinne@radium.ncsc.mil
<mailto:m.kinne@radium.ncscmil> ]=20
Sent: Tuesday, May 08, 2012 7:09 AM
To: SCAP-DEV
Cc: Waltermire, David A.
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Kent,

=20

It's good to read your thoughts, and a realistic actionable approach is
indeed needed  Since all the activity hasn't been on the lists a brief =
1=AE2
hour recap may be in order to bring everyone up to speed since there has
been a lot of activity on CPE/SWID, OCIl, MAEC/CybOX CEE and others.

=20

We could write a content repository specification, but without someone
willing to stand one up it will be as valuable as the CCSS specification =
is
today.  I've been trying for two years to get my management to get a
coordinated effort together for the DoD to stand up a repository, it is =
a
tough problem and will require funding with a tail, I'm not sure a
specification will solve that problem.

=20

We (DoD) have been putting a lot of effort into OCIL over the last year
trying to make it useful in an enterprise environment and will be =
posting
our ideas to the list before developer days it should have already =
started,
we need to get consensus and a vote on how the community wishes to =
proceed.

=20

Remediation is stalled but I'm making every effort to get it kick =
started
from our perspective. I hope to assist in getting the draft ERI finished
this year.  We are writing some new STIG content and intend to used the
draft CRE specification to insert CRE into the content so we (DoD) can =
do
some automatic configuration fixes, part of a self healing network =
concept.
It is just a start but the best we can do at this point.

=20

Enterprise reporting is an interesting subject, since XML adds size to =
and
content to roll up reporting, in any enterprise of size the problem gets
greater, I look forward to your thoughts on that subject.

=20

I am concerned that the internationalization efforts are detracting from
efforts to meet use cases, we have some things we would like changed in
XCCDF to support our OCIl use case and I have been told that I need to =
wait.
I didn't think that a move to internationalization should impede efforts =
to
move forward with use cases.

=20

I look forward to talking with you at the conference.

=20

v/r

=20

Mike Kinney

Project Director

Computer Network Defense Research and Technology (CND R&T) Office

9800 Savage Road Ste 6767
Ft Meade, MD 20755-6767
Phone: 410-854-4422
NSTS: 968-8886
Fax 410-854-4681

 <mailto:M.kinne@radium.ncsc.mil> makinn2@nsa.gov

=20

=20

=20

From:scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of =
Waltermire,
David A.
Sent: Monday, May 07, 2012 7:09 PM
To: Multiple recipients of list
Subject: RE: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Kent,

=20

I like what you are saying here.  We are also in support of this type of
approach.  We would like to see some community discussion around what =
are
the key areas/priorities that the community would like to see discussed =
at
Dev Days.  Your topics below look like a good start. The SACM list might =
be
a better venue than the OVAL list for this discussion.  For each area we
should focus the discussion around developing objectives for each =
session.
The sessions can be time boxed based on what would be a reasonable =
amount of
time to accomplish each objective.  For example if continuous monitoring =
is
a priority and collectively it takes 3 days to work through all the
objectives, I see no problem with that.  We can also keep a few sessions =
"on
deck" if all the objectives are reached and we complete all the =
scheduled
sessions early.

=20

Thoughts?

=20

Sincerely,

=20

David Waltermire

SCAP Architect

National Institute of Standards and Technology

(301) 975-3390

david.waltermire@nist.gov

=20

From:scap-dev@nist.gov [mailto:scap-dev@nist.gov] On Behalf Of
Kent_Landfield@mcafee.com
Sent: Monday, May 07, 2012 4:25 PM
To: SCAP-DEV
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

All,

=20

I would like to discuss the format for the SCAP Developer Days that =
seems to
be listed below.

=20

I see this appears to follow a path we have discussed in the past as the =
way
not to hold a Dev Days event.  We have been trying to get away from =
'Death
by Powerpoint' and back to the type of event we held years ago when we =
were
highly productive.  In the past we had a topic to be discussed and a =
time
box to work within.  That allowed us to have very active brainstorming
sessions in a high bandwidth environment.

=20

At past Summer events we have got into a pattern of lots of powerpoint, =
lots
of status of the efforts and very little discussion about things that =
need
active discussions.  We need to keep moving forward and making progress =
as
an effort. We can get status from various places such as the lists, a
presentation being sent out in advance, a webinar if it is felt there =
will
be questions and answers from those that are new to the efforts.  We =
have a
limited amount of time and all who are attending are investing a great =
deal
of time and money to be there.  We should not  be spending a great deal =
of
time reeducating everyone when we could be focused on advancing needed
efforts.

=20

The type of approach to a Dev Days event was discussed at the last =
Summer
Dev Days.  I have seen the following work quite well in other efforts.

1.	Presentations are sent out to the attendees and the lists a week in
advance
2.	Status for any effort is limited to 30 minutes
3.	Focused brainstorming time should be established for certain areas
that need real work by the community
4.	Efforts to be discussed should be based on needs of the security
automation space to move existing efforts to completion.

For example:

=20

Continuous monitoring is a major direction the efforts are becoming =
involved
with. There are going to be things we need to do as a security =
automation
community to be able to accomplish what is listed in the CAESARS FE.  =
There
are interfaces that need to be worked and established.  That is one area
that is not listed below.  CM will have a major impact on all of us in =
the
next couple years and it is being ignored.  We can't keep trying to =
solve
what has already been solved.  We need to address the needed interface
development now. This is an effort that could take nearly a whole day by
itself.

=20

Operationally we have a real need to be able to deliver SCAP content
internally within an organization. Today the SCAP vendors cannot share a
single local site security policy (XCCDF + OVAL + CPE +.) without the =
site
staff having to go to each of the individual products and figuring out =
how
to inject that new or updated policy into that products delivery =
mechanisms.
That is limiting sites from wanting to buy multiple focused SCAP =
products
since they are such a pain to manage from a content perspective.  It is
easier to buy from one vendor that has a single means for distributing
content than it is to deal with the management issues that having =
multiple
SCAP products presents.  We need to have at least an entire 1/2 a day on =
the
development of a Content Repository specification.

=20

OCIL is a positive and a negative at the same time. It has real value =
that
is being underutilized and under implemented because of the limitations =
of
how it addresses uses in an enterprise environment.  People don't need
security automation to do things on/for a single host.  They need =
security
automation to focus on the enterprise issues that reduce their costs and
improve their efficiencies.  OCIL is failing in the enterprise and we =
all
understand that.  We need to address developing a definitive solution =
for
incorporating OCIL into the enterprise and that means into the existing
specifications. Scheduling and tracking are key to it's success.  We =
need to
make that happen.  This too needs a focused brainstorming time box to
discuss options.

=20

I am really disappointed that Remediation is not on the list below.  =
Yes,
last Summer Dev Days, the time spent on Remediation was wasted time but =
that
does not mean we should ignore it and not try to make some real =
progress.
As far as I am concerned we need to reboot the remediation effort.  We
cannot keep being the set of specifications / tools that act as the =
little
boy crying "Wolf" in the night.  We need to be able to find and fix =
issues
if we are going to really make a difference in organizational security
postures.  But today we think it is too hard so we don't try ?  I think =
we
need a couple hours to discuss the reboot of the effort even if that =
means
minimizing work already done.

=20

A focused discussion on enterprise reporting is also critically needed.  =
For
the vendors here, we have all gone through the Cyberscope goat rope,
delivering limited capabilities to specific data call requirements of =
the
Federal Agencies.  The initial effort was a mess, did little more than =
prove
it was possible and cause the vendor community a great deal of thrashing =
to
put a kludgey 'solution' in place.  Reality is all our customers need =
roll
up reporting and an infrastructure that supports it.  A data call should =
not
be special to anyone other than the agencies responding. The tools =
should be
able to select the types of data needed and deliver that on a scheduled
basis automatically.    Enterprise Reporting pertains to commercial as =
well
as Federal customers.  We need to focus some time on what that would =
look
like using the ARF and ASR as the foundational pieces.  But there are
missing pieces..  We need this discussed.

=20

I would hope we can make this summer's SCAP Dev Days useful in advancing =
the
security automation efforts by addressing some of the more critical =
issues
our customers are facing now or will be facing in the very short term.
Status presentations are not interesting to those active in the efforts.
Let's try to do those before we get to Bedford so we can real make some
progress while we are all in the same room.  This is always a big event =
for
the 'consensus of the willing' that assemble and driven to see security
automation make a difference.  Let's see if we can have an event that, =
when
we all walk out the last day, we all feel that every minute was well =
spent
and moves us forward.

=20

Thanks.

=20

Kent Landfield
Director Content Strategy, Architecture and Standards

McAfee | An Intel Company
5000 Headquarters Dr.
Plano, Texas 75024

Direct: +1.972.963.7096=20
Mobile: +1.817.637.8026
Web: www.mcafee.com <http://www.mcafee.com/>=20

=20

From: <Boczenowski>, Steve <sboczeno@MITRE.ORG>
Reply-To: "OVAL Developer List (Closed Public Discussion)"
<OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG>
To: "OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG"
<OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG>
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Frank;

=20

We hope to have the registration site up next week.  The event will be
during the week of July 9 - starting Monday at 10:00 AM and ending on =
Friday
at 12:00.

=20

Meanwhile, we are working on the agenda and are currently considering =
this
list of topics:

=20

CCE

CPE/SWID

CEE

XCCDF

OVAL

ASR

Enterprise OCIL

CybOX/MAEC

Federated Content Repository Spec

Endpoint Reporting for Continuous Monitoring and Compliance (ERCC)

MILE

TAXII

IF-M for SCAP

IF-MAP

SCAP Releases

SCAP and IETF

NETCONF and SCAP

=20

Steve

=20

From: Frank Lindsay Acker [mailto:afrank@NOVA.EDU]=20
Sent: Tuesday, May 01, 2012 9:32 AM
To: oval-developer-list OVAL Developer List/Closed Public Discussion
Subject: Re: [OVAL-DEVELOPER-LIST] Security Automation Developer Days:
Summer 2012 at MITRE in Bedford, MA

=20

Steve....

Has there been any additional information regarding this event?

Thanks,
Frank Acker


  _____ =20


From: Boczenowski, Steve [sboczeno@MITRE.ORG]
Sent: Tuesday, March 20, 2012 16:38
To: OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG
Subject: [OVAL-DEVELOPER-LIST] Security Automation Developer Days: =
Summer
2012 at MITRE in Bedford, MA

Save the Date: week of July 9, 2012

=20

This year's MITRE-hosted Security Automation Developer Days event will =
be
held during the week of July 9, 2012 at MITRE's facility in Bedford, MA.

=20

Details to follow.

=20

Regards,

    Steve

=20

______________________________________________

Stephen P. Boczenowski

      The MITRE Corporation

      Office: (781) 271-7682

      Cell: (978) 302-3849

     sboczeno@mitre.org

=20

To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.

To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.

To unsubscribe, send an email message to LISTSERV@LISTS.MITRE.ORG with
SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have
difficulties, write to OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG.

_______________________________________________
sacm mailing list
sacm@ietf.org
https://www.ietf.org/mailman/listinfo/sacm

=20


------=_NextPart_000_0212_01CD4C2D.6C4394A0
Content-Type: text/html;
	charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><meta =
http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-2"><meta name=3DGenerator content=3D"Microsoft Word =
14 (filtered medium)"><base href=3D"x-msg://1380/"><!--[if =
!mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:MITRE;}
@font-face
	{font-family:"Lucida Sans Unicode";
	panose-1:2 11 6 2 3 5 4 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.apple-converted-space
	{mso-style-name:apple-converted-space;}
span.apple-style-span
	{mso-style-name:apple-style-span;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle22
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1673752340;
	mso-list-template-ids:1514961740;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>If you type &#8220;What to search&#8221;, it points to the FQA page =
</span><span =
style=3D'font-size:11.0pt;font-family:Wingdings;color:#1F497D'>J</span><s=
pan =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>You can search based on all SCAP elements (Platform, product, class, =
family, access complexity, availability, vendor&#8230;) which are =
identified as keywords. There are additional handlers for like =
&#8216;bulletin&#8217; is Microsoft security bulletins and =
&#8216;benchmark&#8217; is compliance etc. If it doesn&#8217;t fall into =
the above, it does text based search for queries like &#8217;denial of =
service&#8217;, for example. I think we have covered large number of =
combinations that way. <o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>If you type in any ID, it&#8217;ll directly go to the relation page. =
Good part is it can learn new queries, please let us know if something =
doesn&#8217;t work.<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Thanks,<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Chandra. <o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] <b>On Behalf Of =
</b>Luis Nunez<br><b>Sent:</b> Saturday, June 16, 2012 1:04 =
AM<br><b>To:</b> Waltermire, David A.<br><b>Cc:</b> SCAP-DEV; =
bchandra@secpod.com; sacm@ietf.org<br><b>Subject:</b> Re: [sacm] Request =
for participants - Content Repository Specification =
Development<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>here is =
the faq with some samples&nbsp;<a =
href=3D"http://scaprepo.com/faq.html">http://scaprepo.com/faq.html</a><o:=
p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal><span style=3D'font-size:9.0pt;font-family:"Lucida =
Sans Unicode","sans-serif";color:#565656'>cve access complexity =
high</span><o:p></o:p></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Lucida Sans =
Unicode","sans-serif";color:#565656'>all vulnerabilities from jan =
2011</span><o:p></o:p></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Lucida Sans =
Unicode","sans-serif";color:#565656'><br><br></span><o:p></o:p></p></div>=
<div><p class=3DMsoNormal><span =
style=3D'font-size:9.0pt;font-family:"Lucida Sans =
Unicode","sans-serif";color:#565656'>-ln</span><o:p></o:p></p></div><div>=
<p class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><div><p class=3DMsoNormal>On =
Jun 15, 2012, at 3:23 PM, Waltermire, David A. =
wrote:<o:p></o:p></p></div><p =
class=3DMsoNormal><br><br><o:p></o:p></p><div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I am not sure how to use the search page properly.&nbsp; Would you =
please provide some example searches?</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Sincerely,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Dave</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div><p =
class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span class=3Dapple-converted-space><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>&nbsp;</span=
></span><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'><a =
href=3D"mailto:sacm-bounces@ietf.org">sacm-bounces@ietf.org</a> <a =
href=3D"mailto:[mailto:sacm-bounces@ietf.org]">[mailto:sacm-bounces@ietf.=
org]</a><span class=3Dapple-converted-space>&nbsp;</span><b>On Behalf =
Of<span class=3Dapple-converted-space>&nbsp;</span></b>Chandrashekhar =
B<br><b>Sent:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Thursday, June 14, 2012 4:10 =
PM<br><b>To:</b><span =
class=3Dapple-converted-space>&nbsp;</span>SCAP-DEV; <a =
href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br><b>Subject:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Re: [sacm] Request for =
participants - Content Repository Specification Development</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>&nbsp;<o:p>=
</o:p></span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>We have hosted our SCAP Content Repository at<span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"http://www.scaprepo.com">www.scaprepo.com</a>. Feedback is =
certainly appreciated. A simple web service interface will be published =
soon.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Chandra.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div><p =
class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span class=3Dapple-converted-space><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>&nbsp;</span=
></span><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'><a =
href=3D"mailto:scap-dev@nist.gov">scap-dev@nist.gov</a><span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:[mailto:scap-dev@nist.gov]">[mailto:scap-dev@nist.gov]</a>=
<span class=3Dapple-converted-space>&nbsp;</span><b>On Behalf Of<span =
class=3Dapple-converted-space>&nbsp;</span></b><a =
href=3D"mailto:Kent_Landfield@mcafee.com">Kent_Landfield@mcafee.com</a><b=
r><b>Sent:</b><span class=3Dapple-converted-space>&nbsp;</span>Friday, =
May 11, 2012 10:14 PM<br><b>To:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Multiple recipients of =
list<br><b>Subject:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Request for participants - =
Content Repository Specification Development</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>&nbsp;<o:p>=
</o:p></span></p></div><div><div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Mike I love it when you tee something up like that&#8230;. ;-) =
&nbsp;Thank you. ;)</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Mike wrote:&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I still think that any specification for a repository is wishful =
thinking until someone builds one and learns the lessons it will just be =
another whitepaper spec. &nbsp;I believe the DoD needs to incorporate a =
metadata repository as part of it and other customizations that may not =
be useful for everyone.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>We need to talk more&#8230;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>If you are talking about a holistic, complete federated approach to a =
content repository, I some what agree. &nbsp;If you are talking about an =
organizational repository, I totally disagree. But you knew I would. =
;)</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Here is how I see the problem. &nbsp;There is an immediate need for =
SCAP and other related content to be served up inside an organization. =
&nbsp;Today we have situation where the standards allow us to provide =
sites the capability to have a single SCAP implemented policy they call =
official for their environment. Yes this is a rather simplistic since =
there are things such as targeting specific platforms, specific =
operational use needs, but for now lets agree SCAP is a massive =
improvement over the proprietary situations of the past. While we have =
created this standard content so that sites can implement their local =
site security once and then assure they are measuring all appropriately =
targeted devices the same way, we have failed to support the operational =
needs of the sites. &nbsp;We have a situation where no two vendors =
distribute content the same way. &nbsp;This causes massive problems for =
the administration staff when they need to incorporate a new SCAP =
enabled product into their architecture. &nbsp;They need to discover how =
the new product supports distributing SCAP content to it's various =
components. &nbsp;If they have one product then they do this one and =
they are done. &nbsp;If they have multiple products they will have to =
figure out how to minimize the impact by incorporating the update =
process for the new product into the existing SCAP security content =
processes. Now when the inevitable happens and the site staff needs to =
make a change to their security policy, they have to make the =
modifications to the benchmark or checks or both and then distribute =
those updates across their network. &nbsp;For each SCAP enabled product =
they have in place, they have doubled, tripled or more the work needed =
to make those updates available.&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>There is another content repository problem and that is the Federated =
Content Distribution. &nbsp;If you think global DNS you have a general =
frame of reference. &nbsp;The guidance authors need to be able to =
publish content in an authoritative manner so their content is updated =
in a timely fashion. &nbsp;This is a much harder problem to solve if =
there is no local organizational infrastructure to support it. =
;)</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>So here is what I am thinking&#8230; &nbsp;We should consider =
addressing these as two separate but integrated efforts. &nbsp;I believe =
the Organizational Content Repository is the more critical piece that is =
actually easier to address. &nbsp;The Federated Content Distribution =
should be a subsequent effort integrating / augmenting the =
Organizational repository specification.&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Mike, to your point that we need someone to build one first&#8230; That =
has happened already. &nbsp;I have one as do other vendors but what we =
don&#8217;t have is the access specification. &nbsp;Ours are focused on =
our specific product needs. &nbsp;Additionally there is a company that =
has developed a commercial SCAP content repository that will be =
announced later this month. I won't steal their thunder but I was =
recently given a sneak peek at it and I must admit I was very impressed. =
&nbsp;Again, to your point, it has been done. What is needed to address =
the initial operational problem is to develop a specification that =
provides a consistent means for all SCAP products to retrieve the =
appropriate content as configured and managed but the site. =
&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><p class=3DMsoNormal =
style=3D'margin-bottom:1.0pt'><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>TO THAT END&#8230;.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>I am requesting participation from those in the community that see the =
need and want to put in the work to make this specification happen. =
&nbsp;I have talked to a couple of you but I do not want to assume your =
participation. &nbsp;If you are interested please contact me so we can =
get this started.&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Thanks!</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><div><p class=3DMsoNormal><strong><span =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'>=
Kent Landfield</span></strong><span =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'>=
<br><span class=3Dapple-style-span>Director Content Strategy, =
Architecture and Standards</span><br><br><strong><span =
style=3D'font-family:"Arial","sans-serif"'>McAfee | An Intel =
Company</span></strong><br><span class=3Dapple-style-span>5000 =
Headquarters Dr.</span><br><span class=3Dapple-style-span>Plano, Texas =
75024</span><br><br><span class=3Dapple-style-span>Direct: =
+1.972.963.7096&nbsp;</span><br><span class=3Dapple-style-span>Mobile: =
+1.817.637.8026</span><br><strong><span =
style=3D'font-family:"Arial","sans-serif"'>Web:&nbsp;</span></strong><spa=
n class=3Dapple-style-span><a =
href=3D"http://www.mcafee.com/">www.mcafee.com</a></span></span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div></div></div><div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div style=3D'border:none;border-top:solid =
#B5C4DF 1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div><p =
class=3DMsoNormal><b><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>From:<span class=3Dapple-converted-space>&nbsp;</span></span></b><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&lt;Kinney&gt;, Michael A &lt;<a =
href=3D"mailto:m.kinne@radium.ncsc.mil">m.kinne@radium.ncsc.mil</a>&gt;<b=
r><b>To:<span class=3Dapple-converted-space>&nbsp;</span></b>David =
Waltermire &lt;<a =
href=3D"mailto:david.waltermire@nist.gov">david.waltermire@nist.gov</a>&g=
t;, SCAP-DEV &lt;<a =
href=3D"mailto:SCAP-DEV@nist.gov">SCAP-DEV@nist.gov</a>&gt;, &quot;<a =
href=3D"mailto:sacm@ietf.org">sacm@ietforg</a>&quot; &lt;<a =
href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a>&gt;<br><b>Subject:<span =
class=3Dapple-converted-space>&nbsp;</span></b>Re: [sacm] =
[OVAL-DEVELOPER-LIST] Security Automation Developer Days: Summer 2012 at =
MITRE in Bedford, MA</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><blockquote =
style=3D'border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in =
4.0pt;margin-left:3.75pt;margin-top:5.0pt;margin-right:0in;margin-bottom:=
5.0pt;border-width:initial;border-color:initial' =
id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE"><div><div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Dave,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I have no problem with webinars, I do want to keep developer days =
actionable and use it to make decisions, and vote and accomplish things =
good or bad.&nbsp; I do not want this to be an informational briefing =
conference.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Thanks for the links.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I still think that any specification for a repository is wishful =
thinking until someone builds one and learns the lessons it will just be =
another whitepaper spec. &nbsp;I believe the DoD needs to incorporate a =
metadata repository as part of it and other customizations that may not =
be useful for everyone.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>We need to talk more&#8230;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>-Mike&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div><p =
class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span class=3Dapple-converted-space><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
&nbsp;</span></span><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
Waltermire, David A. [<a =
href=3D"mailto:david.waltermire@nist.gov">mailto:david.waltermire@nist.go=
v</a>]<span =
class=3Dapple-converted-space>&nbsp;</span><br><b>Sent:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Tuesday, May 08, 2012 10:44 =
AM<br><b>To:</b><span class=3Dapple-converted-space>&nbsp;</span>Kinney, =
Michael A; SCAP-DEV;<span class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br><b>Subject:</b><span =
class=3Dapple-converted-space>&nbsp;</span>RE: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Mike,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>What about having webinars in-place of the 30 minute =
briefs?</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Regarding content management, we are building the prototype content =
repository for use in a production environment.&nbsp; As an open source =
project, it will be free for use by anyone interested.&nbsp; My thinking =
is that this project can bridge the gap until commercial solutions are =
available to augment it.&nbsp; This is a similar path that was followed =
with DNS (bind) and HTTP (apache).&nbsp; When it is ready for use, I am =
hoping to use it to host USGCB content.&nbsp; You would be welcome to =
use it for your needs.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>It is good that OCIL is moving forward.&nbsp; This is an important =
piece of supporting risk management and aspects of continuous =
monitoring.&nbsp; I would also like to see some discussion on OCIL at =
Developer Days.&nbsp; With the proposals we will likely have a sense of =
what needs to be discussed and what we can achieve consensus on outside =
the meeting.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Remediation is a topic near and dear to my heart.&nbsp; I too would =
like to see it move forward.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>We just published the draft ASR specification for public =
comment.&nbsp; This specification supports enterprise aggregate =
reporting which greatly reduces the data volumes needed verses detailed =
host-based reports. This specification has been designed as a more =
robust replacement for LASR&nbsp; It can be used in continuous =
monitoring applications to support aggregate data reporting needs (e.g. =
FISMA reporting, &nbsp;CyberScope).</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Here are the links:</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><a =
href=3D"http://csrc.nist.gov/publications/PubsDrafts.html">http://csrc.ni=
st.gov/publications/PubsDrafts.html</a></span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><a =
href=3D"http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848">=
http://csrc.nist.gov/publications/PubsNISTIRs.html#NIST-IR-7848</a></span=
><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>The primary reason we have suggested waiting on XCCDF is not the =
internationalization issue. Many vendors have commented that they are =
still working on implementing the XCCDF 1.2.1 specification. We will be =
in a better place in a few months once more development around XCCDF has =
occurred.&nbsp; As we consider changes to the SCAP stack to address OCIL =
and other issues, we will identify areas that need improvement in =
XCCDF.&nbsp; These are good and necessary discussions to have now, but =
we have a good deal of work to do before we are ready to open up =
XCCDF.&nbsp; My suggestion is to work on these related areas and then =
work up change proposals for XCCDF as needed.&nbsp; By that time we =
should be ready to work on a new revision of XCCDF.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I am also looking forward to the discussions at the conference.&nbsp; =
It has been too long.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Sincerely,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Dave</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div><p =
class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span class=3Dapple-converted-space><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
&nbsp;</span></span><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
Kinney, Michael A [<a =
href=3D"mailto:m.kinne@radium.ncscmil">mailto:m.kinne@radium.ncsc.mil</a>=
]<span class=3Dapple-converted-space>&nbsp;</span><br><b>Sent:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Tuesday, May 08, 2012 7:09 =
AM<br><b>To:</b><span =
class=3Dapple-converted-space>&nbsp;</span>SCAP-DEV<br><b>Cc:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Waltermire, David =
A.<br><b>Subject:</b><span =
class=3Dapple-converted-space>&nbsp;</span>RE: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Kent,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>It&#8217;s good to read your thoughts, and a realistic actionable =
approach is indeed needed &nbsp;Since all the activity hasn&#8217;t been =
on the lists a brief 1=AE2 hour recap may be in order to bring everyone =
up to speed since there has been a lot of activity on CPE/SWID, OCIl, =
MAEC/CybOX CEE and others.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>We could write a content repository specification, but without =
someone willing to stand one up it will be as valuable as the CCSS =
specification is today. &nbsp;I&#8217;ve been trying for two years to =
get my management to get a coordinated effort together for the DoD to =
stand up a repository, it is a tough problem and will require funding =
with a tail, I&#8217;m not sure a specification will solve that =
problem.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>We (DoD) have been putting a lot of effort into OCIL over the last =
year trying to make it useful in an enterprise environment and will be =
posting our ideas to the list before developer days it should have =
already started, we need to get consensus and a vote on how the =
community wishes to proceed.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Remediation is stalled but I&#8217;m making every effort to get it =
kick started from our perspective. I hope to assist in getting the draft =
ERI finished this year. &nbsp;We are writing some new STIG content and =
intend to used the draft CRE specification to insert CRE into the =
content so we (DoD) can do some automatic configuration fixes, part of a =
self healing network concept. It is just a start but the best we can do =
at this point.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Enterprise reporting is an interesting subject, since XML adds size =
to and content to roll up reporting, in any enterprise of size the =
problem gets greater, I look forward to your thoughts on that =
subject.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I am concerned that the internationalization efforts are detracting =
from efforts to meet use cases, we have some things we would like =
changed in XCCDF to support our OCIl use case and I have been told that =
I need to wait. I didn&#8217;t think that a move to internationalization =
should impede efforts to move forward with use cases.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I look forward to talking with you at the conference.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>v/r</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>Mike Kinney</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>Project Director</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>Computer Network Defense Research and Technology (CND R&amp;T) =
Office</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>9800 Savage Road Ste 6767<br>Ft Meade, MD 20755-6767<br></span><span =
style=3D'font-size:10.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Phone: 410-854-4422<br>NSTS: 968-8886<br>Fax 410-854-4681</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
><a href=3D"mailto:M.kinne@radium.ncsc.mil"><span =
style=3D'color:#660000'>makinn2@nsa.gov</span></a></span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div><p =
class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
<a href=3D"mailto:scap-dev@nist.gov">scap-dev@nist.gov</a><span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:[mailto:scap-dev@nist.gov]">[mailto:scap-dev@nist.gov]</a>=
<span class=3Dapple-converted-space>&nbsp;</span><b>On Behalf Of<span =
class=3Dapple-converted-space>&nbsp;</span></b>Waltermire, David =
A.<br><b>Sent:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Monday, May 07, 2012 7:09 =
PM<br><b>To:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Multiple recipients of =
list<br><b>Subject:</b><span =
class=3Dapple-converted-space>&nbsp;</span>RE: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Kent,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I like what you are saying here.&nbsp; We are also in support of this =
type of approach.&nbsp; We would like to see some community discussion =
around what are the key areas/priorities that the community would like =
to see discussed at Dev Days.&nbsp; Your topics below look like a good =
start. The SACM list might be a better venue than the OVAL list for this =
discussion.&nbsp; For each area we should focus the discussion around =
developing objectives for each session.&nbsp; The sessions can be time =
boxed based on what would be a reasonable amount of time to accomplish =
each objective.&nbsp; For example if continuous monitoring is a priority =
and collectively it takes 3 days to work through all the objectives, I =
see no problem with that.&nbsp; We can also keep a few sessions =
&#8220;on deck&#8221; if all the objectives are reached and we complete =
all the scheduled sessions early.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Thoughts?</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Sincerely,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>David Waltermire</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>SCAP Architect</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>National Institute of Standards and Technology</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>(301) 975-3390</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
><a =
href=3D"mailto:david.waltermire@nist.gov">david.waltermire@nist.gov</a></=
span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div><p =
class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
<a href=3D"mailto:scap-dev@nist.gov">scap-dev@nist.gov</a><span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:[mailto:scap-dev@nist.gov]">[mailto:scap-dev@nist.gov]</a>=
<span class=3Dapple-converted-space>&nbsp;</span><b>On Behalf Of<span =
class=3Dapple-converted-space>&nbsp;</span></b><a =
href=3D"mailto:Kent_Landfield@mcafee.com">Kent_Landfield@mcafee.com</a><b=
r><b>Sent:</b><span class=3Dapple-converted-space>&nbsp;</span>Monday, =
May 07, 2012 4:25 PM<br><b>To:</b><span =
class=3Dapple-converted-space>&nbsp;</span>SCAP-DEV<br><b>Subject:</b><sp=
an class=3Dapple-converted-space>&nbsp;</span>Re: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div><div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>All,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>I would like to discuss the format for the SCAP Developer Days that =
seems to be listed below.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>I see this appears to follow a path we have discussed in the past as =
the way not to hold a Dev Days event. &nbsp;We have been trying to get =
away from 'Death by Powerpoint' and back to the type of event we held =
years ago when we were highly productive. &nbsp;In the past we had a =
topic to be discussed and a time box to work within. &nbsp;That allowed =
us to have very active brainstorming sessions in a high bandwidth =
environment.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>At past Summer events we have got into a pattern of lots of powerpoint, =
lots of status of the efforts and very little discussion about things =
that need active discussions. &nbsp;We need to keep moving forward and =
making progress as an effort. We can get status from various places such =
as the lists, a presentation being sent out in advance, a webinar if it =
is felt there will be questions and answers from those that are new to =
the efforts. &nbsp;We have a limited amount of time and all who are =
attending are investing a great deal of time and money to be there. =
&nbsp;We should not &nbsp;be spending a great deal of time reeducating =
everyone when we could be focused on advancing needed =
efforts.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>The type of approach to a Dev Days event was discussed at the last =
Summer Dev Days. &nbsp;I have seen the following work quite well in =
other efforts.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><ol style=3D'margin-top:0in' start=3D1 =
type=3D1><li class=3DMsoNormal style=3D'color:black;mso-list:l0 level1 =
lfo1'><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>Presentatio=
ns are sent out to the attendees and the lists a week in =
advance<o:p></o:p></span></li><li class=3DMsoNormal =
style=3D'color:black;mso-list:l0 level1 lfo1'><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>Status for =
any effort is limited to 30 minutes<o:p></o:p></span></li><li =
class=3DMsoNormal style=3D'color:black;mso-list:l0 level1 lfo1'><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>Focused =
brainstorming time should be established for certain areas that need =
real work by the community<o:p></o:p></span></li><li class=3DMsoNormal =
style=3D'color:black;mso-list:l0 level1 lfo1'><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'>Efforts to =
be discussed should be based on needs of the security automation space =
to move existing efforts to =
completion.<o:p></o:p></span></li></ol><div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>For example:</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Continuous monitoring is a major direction the efforts are becoming =
involved with. There are going to be things we need to do as a security =
automation community to be able to accomplish what is listed in the =
CAESARS FE. &nbsp;There are interfaces that need to be worked and =
established. &nbsp;That is one area that is not listed below. &nbsp;CM =
will have a major impact on all of us in the next couple years and it is =
being ignored. &nbsp;We can't keep trying to solve what has already been =
solved. &nbsp;We need to address the needed interface development now. =
This is an effort that could take nearly a whole day by =
itself.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Operationally we have a real need to be able to deliver SCAP content =
internally within an organization. Today the SCAP vendors cannot share a =
single local site security policy (XCCDF + OVAL + CPE +&#8230;) without =
the site staff having to go to each of the individual products and =
figuring out how to inject that new or updated policy into that products =
delivery mechanisms. &nbsp;That is limiting sites from wanting to buy =
multiple focused SCAP products since they are such a pain to manage from =
a content perspective. &nbsp;It is easier to buy from one vendor that =
has a single means for distributing content than it is to deal with the =
management issues that having multiple SCAP products presents. &nbsp;We =
need to have at least an entire 1/2 a day on the development of a =
Content Repository specification.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>OCIL is a positive and a negative at the same time. It has real value =
that is being underutilized and under implemented because of the =
limitations of how it addresses uses in an enterprise environment. =
&nbsp;People don't need security automation to do things on/for a single =
host. &nbsp;They need security automation to focus on the enterprise =
issues that reduce their costs and improve their efficiencies. =
&nbsp;OCIL is failing in the enterprise and we all understand that. =
&nbsp;We need to address developing a definitive solution for =
incorporating OCIL into the enterprise and that means into the existing =
specifications. Scheduling and tracking are key to it's success. =
&nbsp;We need to make that happen. &nbsp;This too needs a focused =
brainstorming time box to discuss options.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>I am really disappointed that Remediation is not on the list =
below&#8230; &nbsp;Yes, last Summer Dev Days, the time spent on =
Remediation was wasted time but that does not mean we should ignore it =
and not try to make some real progress. &nbsp;As far as I am concerned =
we need to reboot the remediation effort. &nbsp;We cannot keep being the =
set of specifications / tools that act as the little boy crying =
&quot;Wolf&quot; in the night. &nbsp;We need to be able to find and fix =
issues if we are going to really make a difference in organizational =
security postures. &nbsp;But today we think it is too hard so we don't =
try ? &nbsp;I think we need a couple hours to discuss the reboot of the =
effort even if that means minimizing work already done.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>A focused discussion on enterprise reporting is also critically needed. =
&nbsp;For the vendors here, we have all gone through the Cyberscope goat =
rope, delivering limited capabilities to specific data call requirements =
of the Federal Agencies. &nbsp;The initial effort was a mess, did little =
more than prove it was possible and cause the vendor community a great =
deal of thrashing to put a kludgey 'solution' in place. &nbsp;Reality is =
all our customers need roll up reporting and an infrastructure that =
supports it. &nbsp;A data call should not be special to anyone other =
than the agencies responding. The tools should be able to select the =
types of data needed and deliver that on a scheduled basis =
automatically. &nbsp; &nbsp;Enterprise Reporting pertains to commercial =
as well as Federal customers. &nbsp;We need to focus some time on what =
that would look like using the ARF and ASR as the foundational pieces. =
&nbsp;But there are missing pieces&#8230;. &nbsp;We need this =
discussed.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>I would hope we can make this summer's SCAP Dev Days useful in =
advancing the security automation efforts by addressing some of the more =
critical issues our customers are facing now or will be facing in the =
very short term. &nbsp;Status presentations are not interesting to those =
active in the efforts. &nbsp;Let's try to do those before we get to =
Bedford so we can real make some progress while we are all in the same =
room. &nbsp;This is always a big event for the 'consensus of the =
willing' that assemble and driven to see security automation make a =
difference. &nbsp;Let's see if we can have an event that, when we all =
walk out the last day, we all feel that every minute was well spent and =
moves us forward.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Thanks.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><div><p class=3DMsoNormal><strong><span =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'>=
Kent Landfield</span></strong><span =
style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A71'>=
<br><span class=3Dapple-style-span>Director Content Strategy, =
Architecture and Standards</span><br><br><strong><span =
style=3D'font-family:"Arial","sans-serif"'>McAfee | An Intel =
Company</span></strong><br><span class=3Dapple-style-span>5000 =
Headquarters Dr.</span><br><span class=3Dapple-style-span>Plano, Texas =
75024</span><br><br><span class=3Dapple-style-span>Direct: =
+1.972.963.7096&nbsp;</span><br><span class=3Dapple-style-span>Mobile: =
+1.817.637.8026</span><br><strong><span =
style=3D'font-family:"Arial","sans-serif"'>Web:&nbsp;</span></strong><spa=
n class=3Dapple-style-span><a =
href=3D"http://www.mcafee.com/">www.mcafee.com</a></span></span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div></div></div></div><div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div style=3D'border:none;border-top:solid =
#B5C4DF 1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div><p =
class=3DMsoNormal><b><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>From:<span class=3Dapple-converted-space>&nbsp;</span></span></b><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&lt;Boczenowski&gt;, Steve &lt;<a =
href=3D"mailto:sboczeno@MITRE.ORG">sboczeno@MITRE.ORG</a>&gt;<br><b>Reply=
-To:<span class=3Dapple-converted-space>&nbsp;</span></b>&quot;OVAL =
Developer List (Closed Public Discussion)&quot; &lt;<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@L=
ISTS.MITRE.ORG</a>&gt;<br><b>To:<span =
class=3Dapple-converted-space>&nbsp;</span></b>&quot;<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@L=
ISTS.MITRE.ORG</a>&quot; &lt;<a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@L=
ISTS.MITRE.ORG</a>&gt;<br><b>Subject:<span =
class=3Dapple-converted-space>&nbsp;</span></b>Re: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div><div><p class=3DMsoNormal><span =
style=3D'color:black'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><blockquote =
style=3D'border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in =
4.0pt;margin-left:3.75pt;margin-top:5.0pt;margin-right:0in;margin-bottom:=
5.0pt;border-width:initial;border-color:initial' =
id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE"><div><div><div><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>Frank;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>We hope to have the registration site up next week.&nbsp; The event =
will be during the week of July 9 &#8211; starting Monday at 10:00 AM =
and ending on Friday at 12:00.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>Meanwhile, we are working on the agenda and are currently considering =
this list of topics:</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal =
style=3D'text-indent:.5in'><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>CCE</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>CPE/SWID</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>CEE</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>XCCDF</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>OVAL</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>ASR</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>Enterprise OCIL</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>CybOX/MAEC</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>Federated Content Repository Spec</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>Endpoint Reporting for Continuous Monitoring and Compliance =
(ERCC)</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>MILE</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>TAXII</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>IF-M for SCAP</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>IF-MAP</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>SCAP Releases</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>SCAP and IETF</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>NETCONF and SCAP</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>Steve</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#25406=
1'>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in =
0in;border-width:initial;border-color:initial'><div =
style=3D'margin-left:2.0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span class=3Dapple-converted-space><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
&nbsp;</span></span><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
Frank Lindsay Acker [<a =
href=3D"mailto:afrank@NOVA.EDU">mailto:afrank@NOVA.EDU</a>]<span =
class=3Dapple-converted-space>&nbsp;</span><br><b>Sent:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Tuesday, May 01, 2012 9:32 =
AM<br><b>To:</b><span =
class=3Dapple-converted-space>&nbsp;</span>oval-developer-list OVAL =
Developer List/Closed Public Discussion<br><b>Subject:</b><span =
class=3Dapple-converted-space>&nbsp;</span>Re: [OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
Steve....<br><br>Has there been any additional information regarding =
this event?<br><br>Thanks,<br>Frank Acker</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div style=3D'margin-left:.5in'><div =
class=3DMsoNormal align=3Dcenter style=3D'text-align:center'><span =
style=3D'color:black'><hr size=3D2 width=3D"100%" =
align=3Dcenter></span></div></div><div id=3DdivRpF955236><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:0in;margin-bottom:12.0pt;mar=
gin-left:.5in'><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
From:</span></b><span class=3Dapple-converted-space><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
&nbsp;</span></span><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'>=
Boczenowski, Steve [<a =
href=3D"mailto:sboczeno@MITRE.ORG">sboczeno@MITRE.ORG</a>]<br><b>Sent:</b=
><span class=3Dapple-converted-space>&nbsp;</span>Tuesday, March 20, =
2012 16:38<br><b>To:</b><span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:OVAL-DEVELOPER-LIST@LISTS.MITRE.ORG">OVAL-DEVELOPER-LIST@L=
ISTS.MITRE.ORG</a><br><b>Subject:</b><span =
class=3Dapple-converted-space>&nbsp;</span>[OVAL-DEVELOPER-LIST] =
Security Automation Developer Days: Summer 2012 at MITRE in Bedford, =
MA</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Save the Date: week of July 9, 2012</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>This year&#8217;s MITRE-hosted Security Automation Developer Days event =
will be held during the week of July 9, 2012 at MITRE&#8217;s facility =
in Bedford, MA.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Details to follow.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>Regards,</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;&nbsp;&nbsp; Steve</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:4.0pt;=
margin-left:.5in'><span =
style=3D'font-size:8.0pt;font-family:"Arial","sans-serif";color:#1F497D'>=
______________________________________________</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:4.0pt;=
margin-left:.5in'><i><span =
style=3D'font-size:11.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>Steph</span></i><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>en P. Boczenowski</span></i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:343.5pt;margin-bottom:2.0pt;=
margin-left:.5in'><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The<span =
class=3Dapple-converted-space>&nbsp;</span></span><span =
style=3D'font-size:10.0pt;font-family:MITRE;color:#3366FF'>MITRE</span><s=
pan class=3Dapple-converted-space><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;</span></span><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>Corporation</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p><div style=3D'margin-left:.5in;margin-right:343.5pt'><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Office: (781) 271-7682</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in;margin-right:343.5pt'><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Cell: (978) 302-3849</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in;margin-right:343.5pt'><p =
class=3DMsoNormal><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";color:#1F497D'=
>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a href=3D"mailto:sboczeno@mitre.org" =
target=3D"_blank">sboczeno@mitre.org</a></span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:black'=
>&nbsp;</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span style=3D'color:black'>To unsubscribe, send an =
email message to<span class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG">LISTSERV@LISTS.MITRE.ORG</a><spa=
n class=3Dapple-converted-space>&nbsp;</span>with SIGNOFF =
OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to<span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG">OVAL-DEVELOPE=
R-LIST-request@LISTS.MITRE.ORG</a>.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div></div><div style=3D'margin-left:.5in'><p =
class=3DMsoNormal><span style=3D'color:black'>To unsubscribe, send an =
email message to<span class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG">LISTSERV@LISTS.MITRE.ORG</a><spa=
n class=3Dapple-converted-space>&nbsp;</span>with SIGNOFF =
OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to<span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG">OVAL-DEVELOPE=
R-LIST-request@LISTS.MITRE.ORG</a>.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div><div><p class=3DMsoNormal><span =
style=3D'color:black'>To unsubscribe, send an email message to<span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:LISTSERV@LISTS.MITRE.ORG">LISTSERV@LISTS.MITRE.ORG</a><spa=
n class=3Dapple-converted-space>&nbsp;</span>with SIGNOFF =
OVAL-DEVELOPER-LIST in the BODY of the message. If you have =
difficulties, write to<span =
class=3Dapple-converted-space>&nbsp;</span><a =
href=3D"mailto:OVAL-DEVELOPER-LIST-request@LISTS.MITRE.ORG">OVAL-DEVELOPE=
R-LIST-request@LISTS.MITRE.ORG</a>.</span><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p></o:p>=
</span></p></div></div></div></blockquote></div></div></blockquote><p =
class=3DMsoNormal>_______________________________________________<br>sacm=
 mailing list<br><a =
href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br><a =
href=3D"https://www.ietf.org/mailman/listinfo/sacm">https://www.ietf.org/=
mailman/listinfo/sacm</a><o:p></o:p></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></body></html>
------=_NextPart_000_0212_01CD4C2D.6C4394A0--


From amontville@tripwire.com  Thu Jun 28 09:04:17 2012
Return-Path: <amontville@tripwire.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C3C0D21F85D8 for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:04:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level: 
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id R0I+XK7mIT4A for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:04:17 -0700 (PDT)
Received: from co1outboundpool.messaging.microsoft.com (co1ehsobe001.messaging.microsoft.com [216.32.180.184]) by ietfa.amsl.com (Postfix) with ESMTP id 436A521F84E7 for <sacm@ietf.org>; Thu, 28 Jun 2012 09:04:13 -0700 (PDT)
Received: from mail192-co1-R.bigfish.com (10.243.78.229) by CO1EHSOBE009.bigfish.com (10.243.66.72) with Microsoft SMTP Server id 14.1.225.23; Thu, 28 Jun 2012 16:02:25 +0000
Received: from mail192-co1 (localhost [127.0.0.1])	by mail192-co1-R.bigfish.com (Postfix) with ESMTP id B718148009A	for <sacm@ietf.org>; Thu, 28 Jun 2012 16:02:25 +0000 (UTC)
X-Forefront-Antispam-Report: CIP:174.47.84.216; KIP:(null); UIP:(null); IPV:NLI; H:PDXED01.tripwire.com; RD:174-47-84-216.static.twtelecom.net; EFVD:NLI
X-SpamScore: 0
X-BigFish: VPS0(zzzz1202hzzz2dh2a8h668h839h944he5bhf0ah)
Received: from mail192-co1 (localhost.localdomain [127.0.0.1]) by mail192-co1 (MessageSwitch) id 1340899343613495_22420; Thu, 28 Jun 2012 16:02:23 +0000 (UTC)
Received: from CO1EHSMHS027.bigfish.com (unknown [10.243.78.252])	by mail192-co1.bigfish.com (Postfix) with ESMTP id 8A7AE34004E	for <sacm@ietf.org>; Thu, 28 Jun 2012 16:02:23 +0000 (UTC)
Received: from PDXED01.tripwire.com (174.47.84.216) by CO1EHSMHS027.bigfish.com (10.243.66.37) with Microsoft SMTP Server (TLS) id 14.1.225.23; Thu, 28 Jun 2012 16:02:23 +0000
Received: from PDXHB01.tripwire.com (172.30.0.53) by PDXED01.tripwire.com (192.168.192.5) with Microsoft SMTP Server (TLS) id 14.1.355.2; Thu, 28 Jun 2012 09:04:14 -0700
Received: from PDXMB02.tripwire.com ([fe80::f997:7b65:8e64:438e]) by PDXHB01.tripwire.com ([fe80::d495:98d2:7df4:2154%11]) with mapi id 14.01.0355.002; Thu, 28 Jun 2012 09:03:23 -0700
From: Adam Montville <amontville@tripwire.com>
To: "sacm@ietf.org" <sacm@ietf.org>
Thread-Topic: IETF 84
Thread-Index: AQHNVUeKYUpL4z7vTUubxQ1VahOvyA==
Date: Thu, 28 Jun 2012 16:03:22 +0000
Message-ID: <CC11CE59.D81E%amontville@tripwire.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.2.2.120421
x-originating-ip: [172.30.0.234]
x-exclaimer-md-config: 79afcaa7-fdf4-4fa6-abe0-afeaa4640a4f
Content-Type: text/plain; charset="us-ascii"
Content-ID: <6B0B64F1A32AB449B3D21CC3B202A3FB@tripwire.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: tripwire.com
Subject: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 16:04:17 -0000

All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam



From karen@scarfonecybersecurity.com  Thu Jun 28 09:22:07 2012
Return-Path: <karen@scarfonecybersecurity.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 380EC21F8606 for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:22:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.976
X-Spam-Level: 
X-Spam-Status: No, score=-2.976 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3GWekcC8d5OJ for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:22:06 -0700 (PDT)
Received: from mail-yw0-f42.google.com (mail-yw0-f42.google.com [209.85.213.42]) by ietfa.amsl.com (Postfix) with ESMTP id 7642721F85E5 for <sacm@ietf.org>; Thu, 28 Jun 2012 09:22:04 -0700 (PDT)
Received: by yhfq11 with SMTP id q11so2461152yhf.15 for <sacm@ietf.org>; Thu, 28 Jun 2012 09:22:04 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type:x-gm-message-state; bh=3FYPnS1+453lD22G2BjtWE6ryPj+tZcWp+050gPaoDM=; b=CZ/Xw3dLhsTQUVxuX3Y58hP9f+OM01Qvp0I2FTOy4lxTQs2yLQOwvfDfMpV59tWBht rsGKMmt3QoeHagdFx+Su+YNPbWEZ+UQAQXHwi98fArJy27Xjg9MIuI1X9BHnojidj9jU nN/aiyJbozi8b58St6YSrBDiA71MBELSaq9WA+xLVeqqYTZZ4Od8vxdXaW5M52XgnKAF Jm1oi5DVk24JIdy20SDgxaJ17EyMEBVVxRgtxByHEKgg+ue7vxZQ+wc/eDCEYWDbXKbN N0rAlnzWVhWebCrBCYkLJmaP6E2rdJK26vZR1mjv0v3dx21nYVy7A+TXbvx/wr7Ftlc+ uYzw==
MIME-Version: 1.0
Received: by 10.50.158.229 with SMTP id wx5mr352982igb.23.1340900523660; Thu, 28 Jun 2012 09:22:03 -0700 (PDT)
Received: by 10.231.204.7 with HTTP; Thu, 28 Jun 2012 09:22:03 -0700 (PDT)
In-Reply-To: <CC11CE59.D81E%amontville@tripwire.com>
References: <CC11CE59.D81E%amontville@tripwire.com>
Date: Thu, 28 Jun 2012 12:22:03 -0400
Message-ID: <CAAfuYh_qi0DaGTtMjiYtVoJCQVGa1UpxdLuOW_=Nwng2A8YEDA@mail.gmail.com>
From: Karen Scarfone <karen@scarfonecybersecurity.com>
To: "sacm@ietf.org" <sacm@ietf.org>
Content-Type: multipart/alternative; boundary=14dae934062b64563904c38abbd5
X-Gm-Message-State: ALoCoQkf8chdHXEzrhwj0XCHBPR/9pT/BRgcx5ADamYj5O4uukcfTWBs3/rTBONgXG4OTAnopyEQ
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 16:22:07 -0000

--14dae934062b64563904c38abbd5
Content-Type: text/plain; charset=ISO-8859-1

I've gotten out of the loop on this as well. I'm still available to edit
any documents being produced by this effort.


Karen

On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com>wrote:

> All:
>
> I've been out of this loop for a while, unfortunately.  Hopefully, there
> is progress being made on the use cases and other efforts (I.e. content
> repository) that were proposed a couple of months ago.
>
> Can anyone tell me whether there is a scheduled meeting (side or
> otherwise) for SACM during IETF 84?  If so, do we have any idea when it
> will be held?
>
> Regards,
>
> Adam
>
>
> _______________________________________________
> sacm mailing list
> sacm@ietf.org
> https://www.ietf.org/mailman/listinfo/sacm
>



-- 
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com   (703)401-1018

--14dae934062b64563904c38abbd5
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

I&#39;ve gotten out of the loop on this as well. I&#39;m still available to=
 edit any documents being produced by this effort.<div><br></div><div><br><=
/div><div>Karen<br><br><div class=3D"gmail_quote">On Thu, Jun 28, 2012 at 1=
2:03 PM, Adam Montville <span dir=3D"ltr">&lt;<a href=3D"mailto:amontville@=
tripwire.com" target=3D"_blank">amontville@tripwire.com</a>&gt;</span> wrot=
e:<br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">All:<br>
<br>
I&#39;ve been out of this loop for a while, unfortunately. =A0Hopefully, th=
ere<br>
is progress being made on the use cases and other efforts (I.e. content<br>
repository) that were proposed a couple of months ago.<br>
<br>
Can anyone tell me whether there is a scheduled meeting (side or<br>
otherwise) for SACM during IETF 84? =A0If so, do we have any idea when it<b=
r>
will be held?<br>
<br>
Regards,<br>
<br>
Adam<br>
<br>
<br>
_______________________________________________<br>
sacm mailing list<br>
<a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=3D"_blank">ht=
tps://www.ietf.org/mailman/listinfo/sacm</a><br>
</blockquote></div><br><br clear=3D"all"><div><br></div>-- <br>Karen Scarfo=
ne, Principal Consultant, Scarfone Cybersecurity<br><a href=3D"mailto:karen=
@scarfonecybersecurity.com" target=3D"_blank">karen@scarfonecybersecurity.c=
om</a>=A0=A0 (703)401-1018<br>
<br>
</div>

--14dae934062b64563904c38abbd5--

From kathleen.moriarty@emc.com  Thu Jun 28 09:39:30 2012
Return-Path: <kathleen.moriarty@emc.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 764E621F850D for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:39:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.148
X-Spam-Level: 
X-Spam-Status: No, score=-2.148 tagged_above=-999 required=5 tests=[AWL=0.450,  BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WlStEsV4FSWD for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:39:29 -0700 (PDT)
Received: from mexforward.lss.emc.com (hop-nat-141.emc.com [168.159.213.141]) by ietfa.amsl.com (Postfix) with ESMTP id 784B221F8503 for <sacm@ietf.org>; Thu, 28 Jun 2012 09:39:29 -0700 (PDT)
Received: from hop04-l1d11-si02.isus.emc.com (HOP04-L1D11-SI02.isus.emc.com [10.254.111.55]) by mexforward.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id q5SGdM9s007838 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 28 Jun 2012 12:39:25 -0400
Received: from mailhub.lss.emc.com (mailhub.lss.emc.com [10.254.222.130]) by hop04-l1d11-si02.isus.emc.com (RSA Interceptor); Thu, 28 Jun 2012 12:39:10 -0400
Received: from mxhub03.corp.emc.com (mxhub03.corp.emc.com [10.254.141.105]) by mailhub.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id q5SGd9Q8020849; Thu, 28 Jun 2012 12:39:09 -0400
Received: from mx15a.corp.emc.com ([169.254.1.189]) by mxhub03.corp.emc.com ([10.254.141.105]) with mapi; Thu, 28 Jun 2012 12:39:08 -0400
From: <kathleen.moriarty@emc.com>
To: <karen@scarfonecybersecurity.com>, <sacm@ietf.org>
Date: Thu, 28 Jun 2012 12:39:08 -0400
Thread-Topic: [sacm] IETF 84
Thread-Index: Ac1VSmbzmrl6YZQWRmaJIN8++JBeCgAAbR8w
Message-ID: <F5063677821E3B4F81ACFB7905573F2403949B40@MX15A.corp.emc.com>
References: <CC11CE59.D81E%amontville@tripwire.com> <CAAfuYh_qi0DaGTtMjiYtVoJCQVGa1UpxdLuOW_=Nwng2A8YEDA@mail.gmail.com>
In-Reply-To: <CAAfuYh_qi0DaGTtMjiYtVoJCQVGa1UpxdLuOW_=Nwng2A8YEDA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_F5063677821E3B4F81ACFB7905573F2403949B40MX15Acorpemccom_"
MIME-Version: 1.0
X-EMM-MHVC: 1
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 16:39:30 -0000

--_000_F5063677821E3B4F81ACFB7905573F2403949B40MX15Acorpemccom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of Kar=
en Scarfone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018

--_000_F5063677821E3B4F81ACFB7905573F2403949B40MX15Acorpemccom_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40"><head><meta http-equiv=3DContent-Type content=
=3D"text/html; charset=3Dus-ascii"><meta name=3DGenerator content=3D"Micros=
oft Word 12 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue vli=
nk=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Thanks fo=
r starting the thread, Adam and offering to help Karen!<o:p></o:p></span></=
p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri=
","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNor=
mal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";colo=
r:#1F497D'>A few of us have been working to update the use case document th=
at David Waltermire circulated.&nbsp; We may need help here as I am not sur=
e if we have content for each of the use cases yet.&nbsp; I provided conten=
t to update use case 5.<o:p></o:p></span></p><p class=3DMsoNormal><span sty=
le=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o=
:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.=
0pt;font-family:"Calibri","sans-serif";color:#1F497D'>The hope was to revie=
w the use cases in a side meeting and start looking at a charter in support=
 of the defined use cases.&nbsp; From there, we can figure out what work is=
 needed to support the use cases and charter.&nbsp; This would be used to s=
et the milestones.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D=
'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&n=
bsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;f=
ont-family:"Calibri","sans-serif";color:#1F497D'>Should we set a meeting fo=
r the Sunday again?<o:p></o:p></span></p><p class=3DMsoNormal><span style=
=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p=
>&nbsp;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0p=
t;font-family:"Calibri","sans-serif";color:#1F497D'>Thank you,<o:p></o:p></=
span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"=
Calibri","sans-serif";color:#1F497D'>Kathleen<o:p></o:p></span></p><p class=
=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-se=
rif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><div style=3D'border:none;b=
order-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNorm=
al><b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>Fr=
om:</span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-se=
rif"'> sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] <b>On Behalf Of=
 </b>Karen Scarfone<br><b>Sent:</b> Thursday, June 28, 2012 12:22 PM<br><b>=
To:</b> sacm@ietf.org<br><b>Subject:</b> Re: [sacm] IETF 84<o:p></o:p></spa=
n></p></div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>=
I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.<o:p></o:p></p><div><p class=3DMs=
oNormal><o:p>&nbsp;</o:p></p></div><div><p class=3DMsoNormal><o:p>&nbsp;</o=
:p></p></div><div><p class=3DMsoNormal style=3D'margin-bottom:12.0pt'>Karen=
<o:p></o:p></p><div><p class=3DMsoNormal>On Thu, Jun 28, 2012 at 12:03 PM, =
Adam Montville &lt;<a href=3D"mailto:amontville@tripwire.com" target=3D"_bl=
ank">amontville@tripwire.com</a>&gt; wrote:<o:p></o:p></p><p class=3DMsoNor=
mal>All:<br><br>I've been out of this loop for a while, unfortunately. &nbs=
p;Hopefully, there<br>is progress being made on the use cases and other eff=
orts (I.e. content<br>repository) that were proposed a couple of months ago=
.<br><br>Can anyone tell me whether there is a scheduled meeting (side or<b=
r>otherwise) for SACM during IETF 84? &nbsp;If so, do we have any idea when=
 it<br>will be held?<br><br>Regards,<br><br>Adam<br><br><br>_______________=
________________________________<br>sacm mailing list<br><a href=3D"mailto:=
sacm@ietf.org">sacm@ietf.org</a><br><a href=3D"https://www.ietf.org/mailman=
/listinfo/sacm" target=3D"_blank">https://www.ietf.org/mailman/listinfo/sac=
m</a><o:p></o:p></p></div><p class=3DMsoNormal><br><br clear=3Dall><o:p></o=
:p></p><div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><p class=3DMsoN=
ormal style=3D'margin-bottom:12.0pt'>-- <br>Karen Scarfone, Principal Consu=
ltant, Scarfone Cybersecurity<br><a href=3D"mailto:karen@scarfonecybersecur=
ity.com" target=3D"_blank">karen@scarfonecybersecurity.com</a>&nbsp;&nbsp; =
(703)401-1018<o:p></o:p></p></div></div></body></html>=

--_000_F5063677821E3B4F81ACFB7905573F2403949B40MX15Acorpemccom_--

From david.waltermire@nist.gov  Thu Jun 28 09:45:27 2012
Return-Path: <david.waltermire@nist.gov>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4DDC521F850D for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:45:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.102
X-Spam-Level: 
X-Spam-Status: No, score=-5.102 tagged_above=-999 required=5 tests=[AWL=-0.256, BAYES_00=-2.599, HTML_MESSAGE=0.001, MIME_BASE64_TEXT=1.753, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DpZTPLYyX7pa for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:45:26 -0700 (PDT)
Received: from wsget2.nist.gov (wsget2.nist.gov [129.6.13.151]) by ietfa.amsl.com (Postfix) with ESMTP id 11B5121F8503 for <sacm@ietf.org>; Thu, 28 Jun 2012 09:45:25 -0700 (PDT)
Received: from WSXGHUB1.xchange.nist.gov (129.6.18.96) by wsget2.nist.gov (129.6.13.151) with Microsoft SMTP Server (TLS) id 14.1.355.2; Thu, 28 Jun 2012 12:44:39 -0400
Received: from MBCLUSTER.xchange.nist.gov ([fe80::d479:3188:aec0:cb66]) by WSXGHUB1.xchange.nist.gov ([129.6.18.96]) with mapi; Thu, 28 Jun 2012 12:44:57 -0400
From: "Waltermire, David A." <david.waltermire@nist.gov>
To: "kathleen.moriarty@emc.com" <kathleen.moriarty@emc.com>, "karen@scarfonecybersecurity.com" <karen@scarfonecybersecurity.com>, "sacm@ietf.org" <sacm@ietf.org>
Date: Thu, 28 Jun 2012 12:44:55 -0400
Thread-Topic: [sacm] IETF 84
Thread-Index: Ac1VSmbzmrl6YZQWRmaJIN8++JBeCgAAbR8wAABF5aA=
Message-ID: <D7A0423E5E193F40BE6E94126930C4930B9D8CA073@MBCLUSTER.xchange.nist.gov>
References: <CC11CE59.D81E%amontville@tripwire.com> <CAAfuYh_qi0DaGTtMjiYtVoJCQVGa1UpxdLuOW_=Nwng2A8YEDA@mail.gmail.com> <F5063677821E3B4F81ACFB7905573F2403949B40@MX15A.corp.emc.com>
In-Reply-To: <F5063677821E3B4F81ACFB7905573F2403949B40@MX15A.corp.emc.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_D7A0423E5E193F40BE6E94126930C4930B9D8CA073MBCLUSTERxcha_"
MIME-Version: 1.0
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 16:45:27 -0000

--_000_D7A0423E5E193F40BE6E94126930C4930B9D8CA073MBCLUSTERxcha_
Content-Type: text/plain; charset="us-ascii"

I think it would be valuable to have some discussion around the use cases and some initial concepts for the charter.  Sunday would work for me.

Sincerely,
Dave

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of kathleen.moriarty@emc.com
Sent: Thursday, June 28, 2012 12:39 PM
To: karen@scarfonecybersecurity.com; sacm@ietf.org
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Waltermire circulated.  We may need help here as I am not sure if we have content for each of the use cases yet.  I provided content to update use case 5.

The hope was to review the use cases in a side meeting and start looking at a charter in support of the defined use cases.  From there, we can figure out what work is needed to support the use cases and charter.  This would be used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From: sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-bounces@ietf.org]<mailto:[mailto:sacm-bounces@ietf.org]> On Behalf Of Karen Scarfone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit any documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<mailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (703)401-1018

--_000_D7A0423E5E193F40BE6E94126930C4930B9D8CA073MBCLUSTERxcha_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+PGhlYWQ+PE1FVEEgSFRUUC1FUVVJVj0iQ29udGVudC1UeXBlIiBDT05U
RU5UPSJ0ZXh0L2h0bWw7IGNoYXJzZXQ9dXMtYXNjaWkiPjxtZXRhIG5hbWU9R2VuZXJhdG9yIGNv
bnRlbnQ9Ik1pY3Jvc29mdCBXb3JkIDE0IChmaWx0ZXJlZCBtZWRpdW0pIj48c3R5bGU+PCEtLQ0K
LyogRm9udCBEZWZpbml0aW9ucyAqLw0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseTpDYWxpYnJp
Ow0KCXBhbm9zZS0xOjIgMTUgNSAyIDIgMiA0IDMgMiA0O30NCkBmb250LWZhY2UNCgl7Zm9udC1m
YW1pbHk6VGFob21hOw0KCXBhbm9zZS0xOjIgMTEgNiA0IDMgNSA0IDQgMiA0O30NCi8qIFN0eWxl
IERlZmluaXRpb25zICovDQpwLk1zb05vcm1hbCwgbGkuTXNvTm9ybWFsLCBkaXYuTXNvTm9ybWFs
DQoJe21hcmdpbjowaW47DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0Ow0KCWZvbnQtc2l6ZToxMi4w
cHQ7DQoJZm9udC1mYW1pbHk6IlRpbWVzIE5ldyBSb21hbiIsInNlcmlmIjt9DQphOmxpbmssIHNw
YW4uTXNvSHlwZXJsaW5rDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpibHVlOw0K
CXRleHQtZGVjb3JhdGlvbjp1bmRlcmxpbmU7fQ0KYTp2aXNpdGVkLCBzcGFuLk1zb0h5cGVybGlu
a0ZvbGxvd2VkDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgljb2xvcjpwdXJwbGU7DQoJdGV4
dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQpwLk1zb0FjZXRhdGUsIGxpLk1zb0FjZXRhdGUsIGRp
di5Nc29BY2V0YXRlDQoJe21zby1zdHlsZS1wcmlvcml0eTo5OTsNCgltc28tc3R5bGUtbGluazoi
QmFsbG9vbiBUZXh0IENoYXIiOw0KCW1hcmdpbjowaW47DQoJbWFyZ2luLWJvdHRvbTouMDAwMXB0
Ow0KCWZvbnQtc2l6ZTo4LjBwdDsNCglmb250LWZhbWlseToiVGFob21hIiwic2Fucy1zZXJpZiI7
fQ0Kc3Bhbi5FbWFpbFN0eWxlMTcNCgl7bXNvLXN0eWxlLXR5cGU6cGVyc29uYWw7DQoJZm9udC1m
YW1pbHk6IkNhbGlicmkiLCJzYW5zLXNlcmlmIjsNCgljb2xvcjojMUY0OTdEO30NCnNwYW4uRW1h
aWxTdHlsZTE4DQoJe21zby1zdHlsZS10eXBlOnBlcnNvbmFsLXJlcGx5Ow0KCWZvbnQtZmFtaWx5
OiJDYWxpYnJpIiwic2Fucy1zZXJpZiI7DQoJY29sb3I6IzFGNDk3RDt9DQpzcGFuLkJhbGxvb25U
ZXh0Q2hhcg0KCXttc28tc3R5bGUtbmFtZToiQmFsbG9vbiBUZXh0IENoYXIiOw0KCW1zby1zdHls
ZS1wcmlvcml0eTo5OTsNCgltc28tc3R5bGUtbGluazoiQmFsbG9vbiBUZXh0IjsNCglmb250LWZh
bWlseToiVGFob21hIiwic2Fucy1zZXJpZiI7fQ0KLk1zb0NocERlZmF1bHQNCgl7bXNvLXN0eWxl
LXR5cGU6ZXhwb3J0LW9ubHk7DQoJZm9udC1zaXplOjEwLjBwdDt9DQpAcGFnZSBXb3JkU2VjdGlv
bjENCgl7c2l6ZTo4LjVpbiAxMS4waW47DQoJbWFyZ2luOjEuMGluIDEuMGluIDEuMGluIDEuMGlu
O30NCmRpdi5Xb3JkU2VjdGlvbjENCgl7cGFnZTpXb3JkU2VjdGlvbjE7fQ0KLS0+PC9zdHlsZT48
IS0tW2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlZGVmYXVsdHMgdjpleHQ9ImVkaXQiIHNw
aWRtYXg9IjEwMjYiIC8+DQo8L3htbD48IVtlbmRpZl0tLT48IS0tW2lmIGd0ZSBtc28gOV0+PHht
bD4NCjxvOnNoYXBlbGF5b3V0IHY6ZXh0PSJlZGl0Ij4NCjxvOmlkbWFwIHY6ZXh0PSJlZGl0IiBk
YXRhPSIxIiAvPg0KPC9vOnNoYXBlbGF5b3V0PjwveG1sPjwhW2VuZGlmXS0tPjwvaGVhZD48Ym9k
eSBsYW5nPUVOLVVTIGxpbms9Ymx1ZSB2bGluaz1wdXJwbGU+PGRpdiBjbGFzcz1Xb3JkU2VjdGlv
bjE+PHAgY2xhc3M9TXNvTm9ybWFsPjxzcGFuIHN0eWxlPSdmb250LXNpemU6MTEuMHB0O2ZvbnQt
ZmFtaWx5OiJDYWxpYnJpIiwic2Fucy1zZXJpZiI7Y29sb3I6IzFGNDk3RCc+SSB0aGluayBpdCB3
b3VsZCBiZSB2YWx1YWJsZSB0byBoYXZlIHNvbWUgZGlzY3Vzc2lvbiBhcm91bmQgdGhlIHVzZSBj
YXNlcyBhbmQgc29tZSBpbml0aWFsIGNvbmNlcHRzIGZvciB0aGUgY2hhcnRlci4mbmJzcDsgU3Vu
ZGF5IHdvdWxkIHdvcmsgZm9yIG1lLjxvOnA+PC9vOnA+PC9zcGFuPjwvcD48cCBjbGFzcz1Nc29O
b3JtYWw+PHNwYW4gc3R5bGU9J2ZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6IkNhbGlicmki
LCJzYW5zLXNlcmlmIjtjb2xvcjojMUY0OTdEJz48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+
PGRpdj48cCBjbGFzcz1Nc29Ob3JtYWw+PHNwYW4gc3R5bGU9J2ZvbnQtc2l6ZToxMS4wcHQ7Zm9u
dC1mYW1pbHk6IkNhbGlicmkiLCJzYW5zLXNlcmlmIjtjb2xvcjojMUY0OTdEJz5TaW5jZXJlbHks
PG86cD48L286cD48L3NwYW4+PC9wPjxwIGNsYXNzPU1zb05vcm1hbD48c3BhbiBzdHlsZT0nZm9u
dC1zaXplOjExLjBwdDtmb250LWZhbWlseToiQ2FsaWJyaSIsInNhbnMtc2VyaWYiO2NvbG9yOiMx
RjQ5N0QnPkRhdmU8bzpwPjwvbzpwPjwvc3Bhbj48L3A+PC9kaXY+PHAgY2xhc3M9TXNvTm9ybWFs
PjxzcGFuIHN0eWxlPSdmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiJDYWxpYnJpIiwic2Fu
cy1zZXJpZiI7Y29sb3I6IzFGNDk3RCc+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPjxkaXY+
PGRpdiBzdHlsZT0nYm9yZGVyOm5vbmU7Ym9yZGVyLXRvcDpzb2xpZCAjQjVDNERGIDEuMHB0O3Bh
ZGRpbmc6My4wcHQgMGluIDBpbiAwaW4nPjxwIGNsYXNzPU1zb05vcm1hbD48Yj48c3BhbiBzdHls
ZT0nZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseToiVGFob21hIiwic2Fucy1zZXJpZiInPkZy
b206PC9zcGFuPjwvYj48c3BhbiBzdHlsZT0nZm9udC1zaXplOjEwLjBwdDtmb250LWZhbWlseToi
VGFob21hIiwic2Fucy1zZXJpZiInPiBzYWNtLWJvdW5jZXNAaWV0Zi5vcmcgW21haWx0bzpzYWNt
LWJvdW5jZXNAaWV0Zi5vcmddIDxiPk9uIEJlaGFsZiBPZiA8L2I+a2F0aGxlZW4ubW9yaWFydHlA
ZW1jLmNvbTxicj48Yj5TZW50OjwvYj4gVGh1cnNkYXksIEp1bmUgMjgsIDIwMTIgMTI6MzkgUE08
YnI+PGI+VG86PC9iPiBrYXJlbkBzY2FyZm9uZWN5YmVyc2VjdXJpdHkuY29tOyBzYWNtQGlldGYu
b3JnPGJyPjxiPlN1YmplY3Q6PC9iPiBSZTogW3NhY21dIElFVEYgODQ8bzpwPjwvbzpwPjwvc3Bh
bj48L3A+PC9kaXY+PC9kaXY+PHAgY2xhc3M9TXNvTm9ybWFsPjxvOnA+Jm5ic3A7PC9vOnA+PC9w
PjxwIGNsYXNzPU1zb05vcm1hbD48c3BhbiBzdHlsZT0nZm9udC1zaXplOjExLjBwdDtmb250LWZh
bWlseToiQ2FsaWJyaSIsInNhbnMtc2VyaWYiO2NvbG9yOiMxRjQ5N0QnPlRoYW5rcyBmb3Igc3Rh
cnRpbmcgdGhlIHRocmVhZCwgQWRhbSBhbmQgb2ZmZXJpbmcgdG8gaGVscCBLYXJlbiE8bzpwPjwv
bzpwPjwvc3Bhbj48L3A+PHAgY2xhc3M9TXNvTm9ybWFsPjxzcGFuIHN0eWxlPSdmb250LXNpemU6
MTEuMHB0O2ZvbnQtZmFtaWx5OiJDYWxpYnJpIiwic2Fucy1zZXJpZiI7Y29sb3I6IzFGNDk3RCc+
PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPjxwIGNsYXNzPU1zb05vcm1hbD48c3BhbiBzdHls
ZT0nZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseToiQ2FsaWJyaSIsInNhbnMtc2VyaWYiO2Nv
bG9yOiMxRjQ5N0QnPkEgZmV3IG9mIHVzIGhhdmUgYmVlbiB3b3JraW5nIHRvIHVwZGF0ZSB0aGUg
dXNlIGNhc2UgZG9jdW1lbnQgdGhhdCBEYXZpZCBXYWx0ZXJtaXJlIGNpcmN1bGF0ZWQuJm5ic3A7
IFdlIG1heSBuZWVkIGhlbHAgaGVyZSBhcyBJIGFtIG5vdCBzdXJlIGlmIHdlIGhhdmUgY29udGVu
dCBmb3IgZWFjaCBvZiB0aGUgdXNlIGNhc2VzIHlldC4mbmJzcDsgSSBwcm92aWRlZCBjb250ZW50
IHRvIHVwZGF0ZSB1c2UgY2FzZSA1LjxvOnA+PC9vOnA+PC9zcGFuPjwvcD48cCBjbGFzcz1Nc29O
b3JtYWw+PHNwYW4gc3R5bGU9J2ZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1pbHk6IkNhbGlicmki
LCJzYW5zLXNlcmlmIjtjb2xvcjojMUY0OTdEJz48bzpwPiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+
PHAgY2xhc3M9TXNvTm9ybWFsPjxzcGFuIHN0eWxlPSdmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFt
aWx5OiJDYWxpYnJpIiwic2Fucy1zZXJpZiI7Y29sb3I6IzFGNDk3RCc+VGhlIGhvcGUgd2FzIHRv
IHJldmlldyB0aGUgdXNlIGNhc2VzIGluIGEgc2lkZSBtZWV0aW5nIGFuZCBzdGFydCBsb29raW5n
IGF0IGEgY2hhcnRlciBpbiBzdXBwb3J0IG9mIHRoZSBkZWZpbmVkIHVzZSBjYXNlcy4mbmJzcDsg
RnJvbSB0aGVyZSwgd2UgY2FuIGZpZ3VyZSBvdXQgd2hhdCB3b3JrIGlzIG5lZWRlZCB0byBzdXBw
b3J0IHRoZSB1c2UgY2FzZXMgYW5kIGNoYXJ0ZXIuJm5ic3A7IFRoaXMgd291bGQgYmUgdXNlZCB0
byBzZXQgdGhlIG1pbGVzdG9uZXMuPG86cD48L286cD48L3NwYW4+PC9wPjxwIGNsYXNzPU1zb05v
cm1hbD48c3BhbiBzdHlsZT0nZm9udC1zaXplOjExLjBwdDtmb250LWZhbWlseToiQ2FsaWJyaSIs
InNhbnMtc2VyaWYiO2NvbG9yOiMxRjQ5N0QnPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD48
cCBjbGFzcz1Nc29Ob3JtYWw+PHNwYW4gc3R5bGU9J2ZvbnQtc2l6ZToxMS4wcHQ7Zm9udC1mYW1p
bHk6IkNhbGlicmkiLCJzYW5zLXNlcmlmIjtjb2xvcjojMUY0OTdEJz5TaG91bGQgd2Ugc2V0IGEg
bWVldGluZyBmb3IgdGhlIFN1bmRheSBhZ2Fpbj88bzpwPjwvbzpwPjwvc3Bhbj48L3A+PHAgY2xh
c3M9TXNvTm9ybWFsPjxzcGFuIHN0eWxlPSdmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiJD
YWxpYnJpIiwic2Fucy1zZXJpZiI7Y29sb3I6IzFGNDk3RCc+PG86cD4mbmJzcDs8L286cD48L3Nw
YW4+PC9wPjxwIGNsYXNzPU1zb05vcm1hbD48c3BhbiBzdHlsZT0nZm9udC1zaXplOjExLjBwdDtm
b250LWZhbWlseToiQ2FsaWJyaSIsInNhbnMtc2VyaWYiO2NvbG9yOiMxRjQ5N0QnPlRoYW5rIHlv
dSw8bzpwPjwvbzpwPjwvc3Bhbj48L3A+PHAgY2xhc3M9TXNvTm9ybWFsPjxzcGFuIHN0eWxlPSdm
b250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiJDYWxpYnJpIiwic2Fucy1zZXJpZiI7Y29sb3I6
IzFGNDk3RCc+S2F0aGxlZW48bzpwPjwvbzpwPjwvc3Bhbj48L3A+PHAgY2xhc3M9TXNvTm9ybWFs
PjxzcGFuIHN0eWxlPSdmb250LXNpemU6MTEuMHB0O2ZvbnQtZmFtaWx5OiJDYWxpYnJpIiwic2Fu
cy1zZXJpZiI7Y29sb3I6IzFGNDk3RCc+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPjxkaXYg
c3R5bGU9J2JvcmRlcjpub25lO2JvcmRlci10b3A6c29saWQgI0I1QzRERiAxLjBwdDtwYWRkaW5n
OjMuMHB0IDBpbiAwaW4gMGluJz48cCBjbGFzcz1Nc29Ob3JtYWw+PGI+PHNwYW4gc3R5bGU9J2Zv
bnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6IlRhaG9tYSIsInNhbnMtc2VyaWYiJz5Gcm9tOjwv
c3Bhbj48L2I+PHNwYW4gc3R5bGU9J2ZvbnQtc2l6ZToxMC4wcHQ7Zm9udC1mYW1pbHk6IlRhaG9t
YSIsInNhbnMtc2VyaWYiJz4gPGEgaHJlZj0ibWFpbHRvOnNhY20tYm91bmNlc0BpZXRmLm9yZyI+
c2FjbS1ib3VuY2VzQGlldGYub3JnPC9hPiA8YSBocmVmPSJtYWlsdG86W21haWx0bzpzYWNtLWJv
dW5jZXNAaWV0Zi5vcmddIj5bbWFpbHRvOnNhY20tYm91bmNlc0BpZXRmLm9yZ108L2E+IDxiPk9u
IEJlaGFsZiBPZiA8L2I+S2FyZW4gU2NhcmZvbmU8YnI+PGI+U2VudDo8L2I+IFRodXJzZGF5LCBK
dW5lIDI4LCAyMDEyIDEyOjIyIFBNPGJyPjxiPlRvOjwvYj4gPGEgaHJlZj0ibWFpbHRvOnNhY21A
aWV0Zi5vcmciPnNhY21AaWV0Zi5vcmc8L2E+PGJyPjxiPlN1YmplY3Q6PC9iPiBSZTogW3NhY21d
IElFVEYgODQ8bzpwPjwvbzpwPjwvc3Bhbj48L3A+PC9kaXY+PHAgY2xhc3M9TXNvTm9ybWFsPjxv
OnA+Jm5ic3A7PC9vOnA+PC9wPjxwIGNsYXNzPU1zb05vcm1hbD5JJ3ZlIGdvdHRlbiBvdXQgb2Yg
dGhlIGxvb3Agb24gdGhpcyBhcyB3ZWxsLiBJJ20gc3RpbGwgYXZhaWxhYmxlIHRvIGVkaXQgYW55
IGRvY3VtZW50cyBiZWluZyBwcm9kdWNlZCBieSB0aGlzIGVmZm9ydC48bzpwPjwvbzpwPjwvcD48
ZGl2PjxwIGNsYXNzPU1zb05vcm1hbD48bzpwPiZuYnNwOzwvbzpwPjwvcD48L2Rpdj48ZGl2Pjxw
IGNsYXNzPU1zb05vcm1hbD48bzpwPiZuYnNwOzwvbzpwPjwvcD48L2Rpdj48ZGl2PjxwIGNsYXNz
PU1zb05vcm1hbCBzdHlsZT0nbWFyZ2luLWJvdHRvbToxMi4wcHQnPkthcmVuPG86cD48L286cD48
L3A+PGRpdj48cCBjbGFzcz1Nc29Ob3JtYWw+T24gVGh1LCBKdW4gMjgsIDIwMTIgYXQgMTI6MDMg
UE0sIEFkYW0gTW9udHZpbGxlICZsdDs8YSBocmVmPSJtYWlsdG86YW1vbnR2aWxsZUB0cmlwd2ly
ZS5jb20iIHRhcmdldD0iX2JsYW5rIj5hbW9udHZpbGxlQHRyaXB3aXJlLmNvbTwvYT4mZ3Q7IHdy
b3RlOjxvOnA+PC9vOnA+PC9wPjxwIGNsYXNzPU1zb05vcm1hbD5BbGw6PGJyPjxicj5JJ3ZlIGJl
ZW4gb3V0IG9mIHRoaXMgbG9vcCBmb3IgYSB3aGlsZSwgdW5mb3J0dW5hdGVseS4gJm5ic3A7SG9w
ZWZ1bGx5LCB0aGVyZTxicj5pcyBwcm9ncmVzcyBiZWluZyBtYWRlIG9uIHRoZSB1c2UgY2FzZXMg
YW5kIG90aGVyIGVmZm9ydHMgKEkuZS4gY29udGVudDxicj5yZXBvc2l0b3J5KSB0aGF0IHdlcmUg
cHJvcG9zZWQgYSBjb3VwbGUgb2YgbW9udGhzIGFnby48YnI+PGJyPkNhbiBhbnlvbmUgdGVsbCBt
ZSB3aGV0aGVyIHRoZXJlIGlzIGEgc2NoZWR1bGVkIG1lZXRpbmcgKHNpZGUgb3I8YnI+b3RoZXJ3
aXNlKSBmb3IgU0FDTSBkdXJpbmcgSUVURiA4ND8gJm5ic3A7SWYgc28sIGRvIHdlIGhhdmUgYW55
IGlkZWEgd2hlbiBpdDxicj53aWxsIGJlIGhlbGQ/PGJyPjxicj5SZWdhcmRzLDxicj48YnI+QWRh
bTxicj48YnI+PGJyPl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19f
X19fPGJyPnNhY20gbWFpbGluZyBsaXN0PGJyPjxhIGhyZWY9Im1haWx0bzpzYWNtQGlldGYub3Jn
Ij5zYWNtQGlldGYub3JnPC9hPjxicj48YSBocmVmPSJodHRwczovL3d3dy5pZXRmLm9yZy9tYWls
bWFuL2xpc3RpbmZvL3NhY20iIHRhcmdldD0iX2JsYW5rIj5odHRwczovL3d3dy5pZXRmLm9yZy9t
YWlsbWFuL2xpc3RpbmZvL3NhY208L2E+PG86cD48L286cD48L3A+PC9kaXY+PHAgY2xhc3M9TXNv
Tm9ybWFsPjxicj48YnIgY2xlYXI9YWxsPjxvOnA+PC9vOnA+PC9wPjxkaXY+PHAgY2xhc3M9TXNv
Tm9ybWFsPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPjwvZGl2PjxwIGNsYXNzPU1zb05vcm1hbCBzdHls
ZT0nbWFyZ2luLWJvdHRvbToxMi4wcHQnPi0tIDxicj5LYXJlbiBTY2FyZm9uZSwgUHJpbmNpcGFs
IENvbnN1bHRhbnQsIFNjYXJmb25lIEN5YmVyc2VjdXJpdHk8YnI+PGEgaHJlZj0ibWFpbHRvOmth
cmVuQHNjYXJmb25lY3liZXJzZWN1cml0eS5jb20iIHRhcmdldD0iX2JsYW5rIj5rYXJlbkBzY2Fy
Zm9uZWN5YmVyc2VjdXJpdHkuY29tPC9hPiZuYnNwOyZuYnNwOyAoNzAzKTQwMS0xMDE4PG86cD48
L286cD48L3A+PC9kaXY+PC9kaXY+PC9ib2R5PjwvaHRtbD4=

--_000_D7A0423E5E193F40BE6E94126930C4930B9D8CA073MBCLUSTERxcha_--

From Kent_Landfield@mcafee.com  Thu Jun 28 09:50:27 2012
Return-Path: <Kent_Landfield@mcafee.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E3F5321F850D for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:50:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.598
X-Spam-Level: 
X-Spam-Status: No, score=-6.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 11rlM2nUcVDX for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:50:26 -0700 (PDT)
Received: from dalsmrelay2.nai.com (dalsmrelay2.nai.com [205.227.136.216]) by ietfa.amsl.com (Postfix) with ESMTP id 7AB3421F84FE for <sacm@ietf.org>; Thu, 28 Jun 2012 09:50:26 -0700 (PDT)
Received: from DALEXHT2.corp.nai.org (unknown [10.64.5.52]) by dalsmrelay2.nai.com with smtp id 04f1_5aff_5e57bd0b_4ff6_472f_bb82_99d2b1308ede; Thu, 28 Jun 2012 11:50:20 -0500
Received: from AMERDALEXMB1.corp.nai.org ([fe80::b534:4a0d:1289:2d2d]) by DALEXHT2.corp.nai.org ([::1]) with mapi; Thu, 28 Jun 2012 11:48:11 -0500
From: <Kent_Landfield@McAfee.com>
To: <kathleen.moriarty@emc.com>, <karen@scarfonecybersecurity.com>, <sacm@ietf.org>
Date: Thu, 28 Jun 2012 11:48:59 -0500
Thread-Topic: [sacm] IETF 84
Thread-Index: Ac1VTcz198HzCJ3pTVKH8N9bbnxMmg==
Message-ID: <CC11F4A4.36422%kent_landfield@mcafee.com>
In-Reply-To: <F5063677821E3B4F81ACFB7905573F2403949B40@MX15A.corp.emc.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.2.2.120421
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_CC11F4A436422kentlandfieldmcafeecom_"
MIME-Version: 1.0
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 16:50:28 -0000

--_000_CC11F4A436422kentlandfieldmcafeecom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Personally I'd rather not do Sunday if we can. It worked but we had a coupl=
e people that wanted to be there that did not arrive until after the meetin=
g and could not listen in as they were in transit at the time.

Kent Landfield

McAfee | An Intel Company
Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: Kathleen Moriarty <kathleen.moriarty@emc.com<mailto:kathleen.moriarty=
@emc.com>>
To: "karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com=
>" <karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>=
>, "sacm@ietf.org<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.or=
g>>
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From: sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-boun=
ces@ietf.org] On Behalf Of Karen Scarfone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018

--_000_CC11F4A436422kentlandfieldmcafeecom_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html><head></head><body style=3D"word-wrap: break-word; -webkit-nbsp-mode:=
 space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-si=
ze: 16px; font-family: 'Times New Roman', sans-serif; "><div><div><div>Pers=
onally I'd rather not do Sunday if we can. It worked but we had a couple pe=
ople that wanted to be there that did not arrive until after the meeting an=
d could not listen in as they were in transit at the time.</div><div><br></=
div><div><div><span class=3D"Apple-style-span" style=3D"color: rgb(96, 106,=
 113); font-size: 12px; -webkit-border-horizontal-spacing: 1px; -webkit-bor=
der-vertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif; "><st=
rong>Kent Landfield</strong></span><span class=3D"Apple-style-span" style=
=3D"color: rgb(96, 106, 113); font-size: 12px; -webkit-border-horizontal-sp=
acing: 1px; -webkit-border-vertical-spacing: 1px; font-family: Arial, Helve=
tica, sans-serif; "><br></span><span class=3D"Apple-style-span" style=3D"co=
lor: rgb(96, 106, 113); font-size: 12px; -webkit-border-horizontal-spacing:=
 1px; -webkit-border-vertical-spacing: 1px; font-family: Arial, Helvetica, =
sans-serif; "><br></span><span class=3D"Apple-style-span" style=3D"color: r=
gb(96, 106, 113); font-size: 12px; -webkit-border-horizontal-spacing: 1px; =
-webkit-border-vertical-spacing: 1px; font-family: Arial, Helvetica, sans-s=
erif; "><strong>McAfee | An Intel Company</strong></span><span class=3D"App=
le-style-span" style=3D"color: rgb(96, 106, 113); font-size: 12px; -webkit-=
border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px; font-=
family: Arial, Helvetica, sans-serif; "><br></span><span class=3D"Apple-sty=
le-span" style=3D"color: rgb(96, 106, 113); font-size: 12px; -webkit-border=
-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px; font-family=
: Arial, Helvetica, sans-serif; ">Direct: +1.972.963.7096&nbsp;</span><span=
 class=3D"Apple-style-span" style=3D"color: rgb(96, 106, 113); font-size: 1=
2px; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacin=
g: 1px; font-family: Arial, Helvetica, sans-serif; "><br></span><span class=
=3D"Apple-style-span" style=3D"color: rgb(96, 106, 113); font-size: 12px; -=
webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px=
; font-family: Arial, Helvetica, sans-serif; ">Mobile: +1.817.637.8026</spa=
n><span class=3D"Apple-style-span" style=3D"color: rgb(96, 106, 113); font-=
size: 12px; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical=
-spacing: 1px; font-family: Arial, Helvetica, sans-serif; "><br></span><spa=
n class=3D"Apple-style-span" style=3D"color: rgb(96, 106, 113); font-size: =
12px; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spaci=
ng: 1px; font-family: Arial, Helvetica, sans-serif; "><strong>Web:&nbsp;</s=
trong></span><span class=3D"Apple-style-span" style=3D"color: rgb(96, 106, =
113); font-size: 12px; -webkit-border-horizontal-spacing: 1px; -webkit-bord=
er-vertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif; "><a h=
ref=3D"http://www.mcafee.com/" style=3D"color: rgb(96, 106, 113) !important=
; ">www.mcafee.com</a></span></div></div></div></div><div><br></div><span i=
d=3D"OLK_SRC_BODY_SECTION"><div style=3D"font-family:Calibri; font-size:11p=
t; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: m=
edium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BOR=
DER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt"><s=
pan style=3D"font-weight:bold">From: </span> Kathleen Moriarty &lt;<a href=
=3D"mailto:kathleen.moriarty@emc.com">kathleen.moriarty@emc.com</a>&gt;<br>=
<span style=3D"font-weight:bold">To: </span> "<a href=3D"mailto:karen@scarf=
onecybersecurity.com">karen@scarfonecybersecurity.com</a>" &lt;<a href=3D"m=
ailto:karen@scarfonecybersecurity.com">karen@scarfonecybersecurity.com</a>&=
gt;, "<a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a>" &lt;<a href=3D"ma=
ilto:sacm@ietf.org">sacm@ietf.org</a>&gt;<br><span style=3D"font-weight:bol=
d">Subject: </span> Re: [sacm] IETF 84<br></div><div><br></div><blockquote =
id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"BORDER-LEFT: #b5c4df 5 s=
olid; PADDING:0 0 0 5; MARGIN:0 0 0 5;"><div xmlns:v=3D"urn:schemas-microso=
ft-com:vml" xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"=
urn:schemas-microsoft-com:office:word" xmlns:m=3D"http://schemas.microsoft.=
com/office/2004/12/omml" xmlns=3D"http://www.w3.org/TR/REC-html40"><meta ht=
tp-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8"><meta name=
=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--><div lang=3D"EN-US" link=3D"blue" vlink=
=3D"purple"><div class=3D"WordSection1"><p class=3D"MsoNormal"><span style=
=3D"font-size: 11pt; color: rgb(31, 73, 125); font-family: Calibri, sans-se=
rif; ">Thanks for starting the thread, Adam and offering to help Karen!<o:p=
></o:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; co=
lor: rgb(31, 73, 125); font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p=
></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color: r=
gb(31, 73, 125); font-family: Calibri, sans-serif; ">A few of us have been =
working to update the use case document that David Waltermire circulated.&n=
bsp; We may need help here as I am not sure if we have content for
 each of the use cases yet.&nbsp; I provided content to update use case 5.<=
o:p></o:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt;=
 color: rgb(31, 73, 125); font-family: Calibri, sans-serif; "><o:p>&nbsp;</=
o:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color=
: rgb(31, 73, 125); font-family: Calibri, sans-serif; ">The hope was to rev=
iew the use cases in a side meeting and start looking at a charter in suppo=
rt of the defined use cases.&nbsp; From there, we can figure out what
 work is needed to support the use cases and charter.&nbsp; This would be u=
sed to set the milestones.<o:p></o:p></span></p><p class=3D"MsoNormal"><spa=
n style=3D"font-size: 11pt; color: rgb(31, 73, 125); font-family: Calibri, =
sans-serif; "><o:p>&nbsp;</o:p></span></p><p class=3D"MsoNormal"><span styl=
e=3D"font-size: 11pt; color: rgb(31, 73, 125); font-family: Calibri, sans-s=
erif; ">Should we set a meeting for the Sunday again?<o:p></o:p></span></p>=
<p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 1=
25); font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></span></p><p cla=
ss=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); f=
ont-family: Calibri, sans-serif; ">Thank you,<o:p></o:p></span></p><p class=
=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); fon=
t-family: Calibri, sans-serif; ">Kathleen<o:p></o:p></span></p><p class=3D"=
MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); font-fa=
mily: Calibri, sans-serif; "><o:p>&nbsp;</o:p></span></p><div style=3D"bord=
er:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in"><p class=
=3D"MsoNormal"><b><span style=3D"font-size: 10pt; font-family: Tahoma, sans=
-serif; ">From:</span></b><span style=3D"font-size: 10pt; font-family: Taho=
ma, sans-serif; "> <a href=3D"mailto:sacm-bounces@ietf.org">sacm-bounces@ie=
tf.org</a> [<a href=3D"mailto:sacm-bounces@ietf.org">mailto:sacm-bounces@ie=
tf.org</a>]
<b>On Behalf Of </b>Karen Scarfone<br><b>Sent:</b> Thursday, June 28, 2012 =
12:22 PM<br><b>To:</b> <a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><b=
r><b>Subject:</b> Re: [sacm] IETF 84<o:p></o:p></span></p></div><p class=3D=
"MsoNormal"><o:p>&nbsp;</o:p></p><p class=3D"MsoNormal">I've gotten out of =
the loop on this as well. I'm still available to edit any documents being p=
roduced by this effort.<o:p></o:p></p><div><p class=3D"MsoNormal"><o:p>&nbs=
p;</o:p></p></div><div><p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p></div><d=
iv><p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt">Karen<o:p></o:p></=
p><div><p class=3D"MsoNormal">On Thu, Jun 28, 2012 at 12:03 PM, Adam Montvi=
lle &lt;<a href=3D"mailto:amontville@tripwire.com" target=3D"_blank">amontv=
ille@tripwire.com</a>&gt; wrote:<o:p></o:p></p><p class=3D"MsoNormal">All:<=
br><br>
I've been out of this loop for a while, unfortunately. &nbsp;Hopefully, the=
re<br>
is progress being made on the use cases and other efforts (I.e. content<br>=
repository) that were proposed a couple of months ago.<br><br>
Can anyone tell me whether there is a scheduled meeting (side or<br>
otherwise) for SACM during IETF 84? &nbsp;If so, do we have any idea when i=
t<br>
will be held?<br><br>
Regards,<br><br>
Adam<br><br><br>
_______________________________________________<br>
sacm mailing list<br><a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>=
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=3D"_blank">ht=
tps://www.ietf.org/mailman/listinfo/sacm</a><o:p></o:p></p></div><p class=
=3D"MsoNormal"><br><br clear=3D"all"><o:p></o:p></p><div><p class=3D"MsoNor=
mal"><o:p>&nbsp;</o:p></p></div><p class=3D"MsoNormal" style=3D"margin-bott=
om:12.0pt">-- <br>
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity<br><a href=3D"=
mailto:karen@scarfonecybersecurity.com" target=3D"_blank">karen@scarfonecyb=
ersecurity.com</a>&nbsp;&nbsp; (703)401-1018<o:p></o:p></p></div></div></di=
v></div></blockquote></span></body></html>

--_000_CC11F4A436422kentlandfieldmcafeecom_--

From amontville@tripwire.com  Thu Jun 28 09:52:46 2012
Return-Path: <amontville@tripwire.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 480D621F84E7 for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:52:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.099
X-Spam-Level: 
X-Spam-Status: No, score=-5.099 tagged_above=-999 required=5 tests=[AWL=1.500,  BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NKleRbpneprc for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:52:39 -0700 (PDT)
Received: from tx2outboundpool.messaging.microsoft.com (tx2ehsobe001.messaging.microsoft.com [65.55.88.11]) by ietfa.amsl.com (Postfix) with ESMTP id 03E2521F8540 for <sacm@ietf.org>; Thu, 28 Jun 2012 09:52:39 -0700 (PDT)
Received: from mail61-tx2-R.bigfish.com (10.9.14.240) by TX2EHSOBE004.bigfish.com (10.9.40.24) with Microsoft SMTP Server id 14.1.225.23; Thu, 28 Jun 2012 16:50:51 +0000
Received: from mail61-tx2 (localhost [127.0.0.1])	by mail61-tx2-R.bigfish.com (Postfix) with ESMTP id A812360332; Thu, 28 Jun 2012 16:50:51 +0000 (UTC)
X-Forefront-Antispam-Report: CIP:174.47.84.216; KIP:(null); UIP:(null); IPV:NLI; H:PDXED01.tripwire.com; RD:174-47-84-216.static.twtelecom.net; EFVD:NLI
X-SpamScore: -33
X-BigFish: VPS-33(zz98dI9371I9f17R148cIzz1202hzz1033IL8275bh8275dhz2dh2a8h668h839h944he5bhf0ah)
Received: from mail61-tx2 (localhost.localdomain [127.0.0.1]) by mail61-tx2 (MessageSwitch) id 1340902250133613_5480; Thu, 28 Jun 2012 16:50:50 +0000 (UTC)
Received: from TX2EHSMHS044.bigfish.com (unknown [10.9.14.249])	by mail61-tx2.bigfish.com (Postfix) with ESMTP id 1098E40052; Thu, 28 Jun 2012 16:50:50 +0000 (UTC)
Received: from PDXED01.tripwire.com (174.47.84.216) by TX2EHSMHS044.bigfish.com (10.9.99.144) with Microsoft SMTP Server (TLS) id 14.1.225.23; Thu, 28 Jun 2012 16:50:48 +0000
Received: from PDXHB01.tripwire.com (172.30.0.53) by PDXED01.tripwire.com (192.168.192.5) with Microsoft SMTP Server (TLS) id 14.1.355.2; Thu, 28 Jun 2012 09:53:25 -0700
Received: from PDXMB02.tripwire.com ([fe80::f997:7b65:8e64:438e]) by PDXHB01.tripwire.com ([fe80::d495:98d2:7df4:2154%11]) with mapi id 14.01.0355.002; Thu, 28 Jun 2012 09:52:34 -0700
From: Adam Montville <amontville@tripwire.com>
To: "Kent_Landfield@McAfee.com" <Kent_Landfield@McAfee.com>, "kathleen.moriarty@emc.com" <kathleen.moriarty@emc.com>, "karen@scarfonecybersecurity.com" <karen@scarfonecybersecurity.com>, "sacm@ietf.org" <sacm@ietf.org>
Thread-Topic: [sacm] IETF 84
Thread-Index: AQHNVUeKYUpL4z7vTUubxQ1VahOvyJcQXxeAgAAExgCAAALAgP//i6SA
Date: Thu, 28 Jun 2012 16:52:33 +0000
Message-ID: <CC11D9C8.D85E%amontville@tripwire.com>
In-Reply-To: <CC11F4A4.36422%kent_landfield@mcafee.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.2.2.120421
x-originating-ip: [172.16.97.29]
x-exclaimer-md-config: 79afcaa7-fdf4-4fa6-abe0-afeaa4640a4f
Content-Type: text/plain; charset="us-ascii"
Content-ID: <8B011A6C42221F46B3FA7ED31AC855F0@tripwire.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: tripwire.com
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 16:52:46 -0000

I would also prefer a day other than Sunday, though I can make that work if=
 needed.

Adam

From: kent_landfield <kent_landfield@mcafee.com<mailto:kent_landfield@mcafe=
e.com>>
Date: Thursday, June 28, 2012 9:48 AM
To: "kathleen.moriarty@emc.com<mailto:kathleen.moriarty@emc.com>" <kathleen=
.moriarty@emc.com<mailto:kathleen.moriarty@emc.com>>, "karen@scarfonecybers=
ecurity.com<mailto:karen@scarfonecybersecurity.com>" <karen@scarfonecyberse=
curity.com<mailto:karen@scarfonecybersecurity.com>>, "sacm@ietf.org<mailto:=
sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.org>>
Subject: Re: [sacm] IETF 84

Personally I'd rather not do Sunday if we can. It worked but we had a coupl=
e people that wanted to be there that did not arrive until after the meetin=
g and could not listen in as they were in transit at the time.

Kent Landfield

McAfee | An Intel Company
Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: Kathleen Moriarty <kathleen.moriarty@emc.com<mailto:kathleen.moriarty=
@emc.com>>
To: "karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com=
>" <karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>=
>, "sacm@ietf.org<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.or=
g>>
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From:sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-bounc=
es@ietf.org] On Behalf Of Karen Scarfone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018


From kathleen.moriarty@emc.com  Thu Jun 28 09:59:16 2012
Return-Path: <kathleen.moriarty@emc.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 729D421F8540 for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:59:16 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[AWL=0.001,  BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zeuUsxBnIdOL for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:59:15 -0700 (PDT)
Received: from mexforward.lss.emc.com (hop-nat-141.emc.com [168.159.213.141]) by ietfa.amsl.com (Postfix) with ESMTP id 0E3E921F853D for <sacm@ietf.org>; Thu, 28 Jun 2012 09:59:14 -0700 (PDT)
Received: from hop04-l1d11-si01.isus.emc.com (HOP04-L1D11-SI01.isus.emc.com [10.254.111.54]) by mexforward.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id q5SGxD7e024372 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 28 Jun 2012 12:59:14 -0400
Received: from mailhub.lss.emc.com (mailhub.lss.emc.com [10.254.222.130]) by hop04-l1d11-si01.isus.emc.com (RSA Interceptor); Thu, 28 Jun 2012 12:58:59 -0400
Received: from mxhub30.corp.emc.com (mxhub30.corp.emc.com [128.222.70.170]) by mailhub.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id q5SGwvIh005326; Thu, 28 Jun 2012 12:58:57 -0400
Received: from mx15a.corp.emc.com ([169.254.1.189]) by mxhub30.corp.emc.com ([128.222.70.170]) with mapi; Thu, 28 Jun 2012 12:58:56 -0400
From: <kathleen.moriarty@emc.com>
To: <amontville@tripwire.com>, <Kent_Landfield@McAfee.com>, <karen@scarfonecybersecurity.com>, <sacm@ietf.org>
Date: Thu, 28 Jun 2012 12:58:55 -0400
Thread-Topic: [sacm] IETF 84
Thread-Index: AQHNVUeKYUpL4z7vTUubxQ1VahOvyJcQXxeAgAAExgCAAALAgP//i6SAgAAAr7A=
Message-ID: <F5063677821E3B4F81ACFB7905573F2403949B4B@MX15A.corp.emc.com>
References: <CC11F4A4.36422%kent_landfield@mcafee.com> <CC11D9C8.D85E%amontville@tripwire.com>
In-Reply-To: <CC11D9C8.D85E%amontville@tripwire.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-EMM-MHVC: 1
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 16:59:16 -0000

OK, with a side-meeting, we are restricted to times that do not conflict wi=
th other meetings.  Evenings or early morning could work.  We do have a soc=
ial at this meeting, so Tuesday night is out.  I think we need to avoid the=
 plenary nights as well.  When we held the first MILE meeting, it was after=
 one of the plenary meetings and that was hard as it was late and people wa=
nted to eat.

I don't see an agenda posted yet, so we'll need to work around plenary meet=
ings once they are scheduled if we meet one evening.

I agree with Dave on the agenda.

Thanks,
Kathleen


-----Original Message-----
From: Adam Montville [mailto:amontville@tripwire.com]=20
Sent: Thursday, June 28, 2012 12:53 PM
To: Kent_Landfield@McAfee.com; Moriarty, Kathleen; karen@scarfonecybersecur=
ity.com; sacm@ietf.org
Subject: Re: [sacm] IETF 84

I would also prefer a day other than Sunday, though I can make that work if=
 needed.

Adam

From: kent_landfield <kent_landfield@mcafee.com<mailto:kent_landfield@mcafe=
e.com>>
Date: Thursday, June 28, 2012 9:48 AM
To: "kathleen.moriarty@emc.com<mailto:kathleen.moriarty@emc.com>" <kathleen=
.moriarty@emc.com<mailto:kathleen.moriarty@emc.com>>, "karen@scarfonecybers=
ecurity.com<mailto:karen@scarfonecybersecurity.com>" <karen@scarfonecyberse=
curity.com<mailto:karen@scarfonecybersecurity.com>>, "sacm@ietf.org<mailto:=
sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.org>>
Subject: Re: [sacm] IETF 84

Personally I'd rather not do Sunday if we can. It worked but we had a coupl=
e people that wanted to be there that did not arrive until after the meetin=
g and could not listen in as they were in transit at the time.

Kent Landfield

McAfee | An Intel Company
Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: Kathleen Moriarty <kathleen.moriarty@emc.com<mailto:kathleen.moriarty=
@emc.com>>
To: "karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com=
>" <karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>=
>, "sacm@ietf.org<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.or=
g>>
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From:sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-bounc=
es@ietf.org] On Behalf Of Karen Scarfone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018


From bakerj@mitre.org  Thu Jun 28 09:59:24 2012
Return-Path: <bakerj@mitre.org>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 429F921F8599 for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:59:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.598
X-Spam-Level: 
X-Spam-Status: No, score=-6.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Qsi0FTs5i6RO for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 09:59:23 -0700 (PDT)
Received: from smtpksrv1.mitre.org (smtpksrv1.mitre.org [198.49.146.77]) by ietfa.amsl.com (Postfix) with ESMTP id 46E9821F854E for <sacm@ietf.org>; Thu, 28 Jun 2012 09:59:23 -0700 (PDT)
Received: from smtpksrv1.mitre.org (localhost.localdomain [127.0.0.1]) by localhost (Postfix) with SMTP id 7400521B0FE0; Thu, 28 Jun 2012 12:59:22 -0400 (EDT)
Received: from IMCCAS04.MITRE.ORG (imccas04.mitre.org [129.83.29.81]) by smtpksrv1.mitre.org (Postfix) with ESMTP id 624DB21B0410; Thu, 28 Jun 2012 12:59:22 -0400 (EDT)
Received: from IMCMBX03.MITRE.ORG ([169.254.3.107]) by IMCCAS04.MITRE.ORG ([129.83.29.81]) with mapi id 14.02.0283.003; Thu, 28 Jun 2012 12:59:21 -0400
From: "Baker, Jon" <bakerj@mitre.org>
To: "kathleen.moriarty@emc.com" <kathleen.moriarty@emc.com>, "karen@scarfonecybersecurity.com" <karen@scarfonecybersecurity.com>, "sacm@ietf.org" <sacm@ietf.org>
Thread-Topic: [sacm] IETF 84
Thread-Index: AQHNVUeKYUpL4z7vTUubxQ1VahOvyJcQLMyAgAAExgD//8HKoA==
Date: Thu, 28 Jun 2012 16:59:21 +0000
Message-ID: <6C1C15D8B5510B4B8FF132B10D38651301DEE548@IMCMBX03.MITRE.ORG>
References: <CC11CE59.D81E%amontville@tripwire.com> <CAAfuYh_qi0DaGTtMjiYtVoJCQVGa1UpxdLuOW_=Nwng2A8YEDA@mail.gmail.com> <F5063677821E3B4F81ACFB7905573F2403949B40@MX15A.corp.emc.com>
In-Reply-To: <F5063677821E3B4F81ACFB7905573F2403949B40@MX15A.corp.emc.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [129.83.31.58]
Content-Type: multipart/alternative; boundary="_000_6C1C15D8B5510B4B8FF132B10D38651301DEE548IMCMBX03MITREOR_"
MIME-Version: 1.0
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 16:59:24 -0000

--_000_6C1C15D8B5510B4B8FF132B10D38651301DEE548IMCMBX03MITREOR_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Does this conversation need to wait until the ietf meeting?

Given that many of the participants will be at developer days in two weeks =
maybe some discussion could be held afterhours there?

This might allow for a more mature draft to be discussed at the IETF meetin=
g a few weeks later.

Jon

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Jonathan O. Baker
G022 - IA Industry Collaboration
The MITRE Corporation
Email: bakerj@mitre.org<mailto:bakerj@mitre.org>

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of kat=
hleen.moriarty@emc.com
Sent: Thursday, June 28, 2012 12:39 PM
To: karen@scarfonecybersecurity.com; sacm@ietf.org
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From: sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-boun=
ces@ietf.org]<mailto:[mailto:sacm-bounces@ietf.org]> On Behalf Of Karen Sca=
rfone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018

--_000_6C1C15D8B5510B4B8FF132B10D38651301DEE548IMCMBX03MITREOR_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Does this conversation ne=
ed to wait until the ietf meeting?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Given that many of the pa=
rticipants will be at developer days in two weeks maybe some discussion cou=
ld be held afterhours there?
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">This might allow for a mo=
re mature draft to be discussed at the IETF meeting a few weeks later.<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Jon<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Jonathan O. Baker<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">G022 - IA Industry Collab=
oration<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">The MITRE Corporation<o:p=
></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Email:
<a href=3D"mailto:bakerj@mitre.org"><span style=3D"color:#1F497D;text-decor=
ation:none">bakerj@mitre.org</span></a><o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> sacm-bou=
nces@ietf.org [mailto:sacm-bounces@ietf.org]
<b>On Behalf Of </b>kathleen.moriarty@emc.com<br>
<b>Sent:</b> Thursday, June 28, 2012 12:39 PM<br>
<b>To:</b> karen@scarfonecybersecurity.com; sacm@ietf.org<br>
<b>Subject:</b> Re: [sacm] IETF 84<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Thanks for starting the t=
hread, Adam and offering to help Karen!<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">A few of us have been wor=
king to update the use case document that David Waltermire circulated.&nbsp=
; We may need help here as I am not sure if we have content for
 each of the use cases yet.&nbsp; I provided content to update use case 5.<=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">The hope was to review th=
e use cases in a side meeting and start looking at a charter in support of =
the defined use cases.&nbsp; From there, we can figure out what
 work is needed to support the use cases and charter.&nbsp; This would be u=
sed to set the milestones.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Should we set a meeting f=
or the Sunday again?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Thank you,<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Kathleen<o:p></o:p></span=
></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;">
<a href=3D"mailto:sacm-bounces@ietf.org">sacm-bounces@ietf.org</a> <a href=
=3D"mailto:[mailto:sacm-bounces@ietf.org]">
[mailto:sacm-bounces@ietf.org]</a> <b>On Behalf Of </b>Karen Scarfone<br>
<b>Sent:</b> Thursday, June 28, 2012 12:22 PM<br>
<b>To:</b> <a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>
<b>Subject:</b> Re: [sacm] IETF 84<o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I've gotten out of the loop on this as well. I'm sti=
ll available to edit any documents being produced by this effort.<o:p></o:p=
></p>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt">Karen<o:p></o:p></p>
<div>
<p class=3D"MsoNormal">On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville &lt=
;<a href=3D"mailto:amontville@tripwire.com" target=3D"_blank">amontville@tr=
ipwire.com</a>&gt; wrote:<o:p></o:p></p>
<p class=3D"MsoNormal">All:<br>
<br>
I've been out of this loop for a while, unfortunately. &nbsp;Hopefully, the=
re<br>
is progress being made on the use cases and other efforts (I.e. content<br>
repository) that were proposed a couple of months ago.<br>
<br>
Can anyone tell me whether there is a scheduled meeting (side or<br>
otherwise) for SACM during IETF 84? &nbsp;If so, do we have any idea when i=
t<br>
will be held?<br>
<br>
Regards,<br>
<br>
Adam<br>
<br>
<br>
_______________________________________________<br>
sacm mailing list<br>
<a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=3D"_blank">ht=
tps://www.ietf.org/mailman/listinfo/sacm</a><o:p></o:p></p>
</div>
<p class=3D"MsoNormal"><br>
<br clear=3D"all">
<o:p></o:p></p>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt">-- <br>
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity<br>
<a href=3D"mailto:karen@scarfonecybersecurity.com" target=3D"_blank">karen@=
scarfonecybersecurity.com</a>&nbsp;&nbsp; (703)401-1018<o:p></o:p></p>
</div>
</div>
</div>
</body>
</html>

--_000_6C1C15D8B5510B4B8FF132B10D38651301DEE548IMCMBX03MITREOR_--

From tonynad@microsoft.com  Thu Jun 28 10:00:32 2012
Return-Path: <tonynad@microsoft.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA11321F854E for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 10:00:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.617
X-Spam-Level: 
X-Spam-Status: No, score=-0.617 tagged_above=-999 required=5 tests=[AWL=-0.150, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, UNRESOLVED_TEMPLATE=3.132]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7m5cEQaSl6VY for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 10:00:32 -0700 (PDT)
Received: from db3outboundpool.messaging.microsoft.com (db3ehsobe003.messaging.microsoft.com [213.199.154.141]) by ietfa.amsl.com (Postfix) with ESMTP id 9B11B21F8540 for <sacm@ietf.org>; Thu, 28 Jun 2012 10:00:31 -0700 (PDT)
Received: from mail8-db3-R.bigfish.com (10.3.81.251) by DB3EHSOBE003.bigfish.com (10.3.84.23) with Microsoft SMTP Server id 14.1.225.23; Thu, 28 Jun 2012 16:58:44 +0000
Received: from mail8-db3 (localhost [127.0.0.1])	by mail8-db3-R.bigfish.com (Postfix) with ESMTP id D37454013B	for <sacm@ietf.org>; Thu, 28 Jun 2012 16:58:43 +0000 (UTC)
X-Forefront-Antispam-Report: CIP:131.107.125.8; KIP:(null); UIP:(null); IPV:NLI; H:TK5EX14HUBC102.redmond.corp.microsoft.com; RD:none; EFVD:NLI
X-SpamScore: -35
X-BigFish: VS-35(zz98dI9371I9f17R148cI542Mzz1202h1082kzz1033IL8275bh8275dhz2fh2a8h683h839h944hd25hf0ah)
Received-SPF: pass (mail8-db3: domain of microsoft.com designates 131.107.125.8 as permitted sender) client-ip=131.107.125.8; envelope-from=tonynad@microsoft.com; helo=TK5EX14HUBC102.redmond.corp.microsoft.com ; icrosoft.com ; 
X-Forefront-Antispam-Report-Untrusted: CIP:157.56.240.21; KIP:(null); UIP:(null); (null); H:BL2PRD0310HT002.namprd03.prod.outlook.com; R:internal; EFV:INT
Received: from mail8-db3 (localhost.localdomain [127.0.0.1]) by mail8-db3 (MessageSwitch) id 1340902722711567_16513; Thu, 28 Jun 2012 16:58:42 +0000 (UTC)
Received: from DB3EHSMHS007.bigfish.com (unknown [10.3.81.252])	by mail8-db3.bigfish.com (Postfix) with ESMTP id A17F440004A	for <sacm@ietf.org>; Thu, 28 Jun 2012 16:58:42 +0000 (UTC)
Received: from TK5EX14HUBC102.redmond.corp.microsoft.com (131.107.125.8) by DB3EHSMHS007.bigfish.com (10.3.87.107) with Microsoft SMTP Server (TLS) id 14.1.225.23; Thu, 28 Jun 2012 16:58:39 +0000
Received: from am1outboundpool.messaging.microsoft.com (157.54.51.112) by mail.microsoft.com (157.54.7.154) with Microsoft SMTP Server (TLS) id 14.2.309.3; Thu, 28 Jun 2012 17:00:18 +0000
Received: from mail46-am1-R.bigfish.com (10.3.201.254) by AM1EHSOBE002.bigfish.com (10.3.204.22) with Microsoft SMTP Server id 14.1.225.23; Thu, 28 Jun 2012 16:57:28 +0000
Received: from mail46-am1 (localhost [127.0.0.1])	by mail46-am1-R.bigfish.com (Postfix) with ESMTP id E3F4D4A0248	for <sacm@ietf.org.FOPE.CONNECTOR.OVERRIDE>; Thu, 28 Jun 2012 16:57:27 +0000 (UTC)
Received: from mail46-am1 (localhost.localdomain [127.0.0.1]) by mail46-am1 (MessageSwitch) id 1340902645907270_19911; Thu, 28 Jun 2012 16:57:25 +0000 (UTC)
Received: from AM1EHSMHS015.bigfish.com (unknown [10.3.201.246])	by mail46-am1.bigfish.com (Postfix) with ESMTP id D1A154E0049; Thu, 28 Jun 2012 16:57:25 +0000 (UTC)
Received: from BL2PRD0310HT002.namprd03.prod.outlook.com (157.56.240.21) by AM1EHSMHS015.bigfish.com (10.3.207.153) with Microsoft SMTP Server (TLS) id 14.1.225.23; Thu, 28 Jun 2012 16:57:25 +0000
Received: from BL2PRD0310MB362.namprd03.prod.outlook.com ([169.254.10.205]) by BL2PRD0310HT002.namprd03.prod.outlook.com ([10.255.97.37]) with mapi id 14.16.0164.004; Thu, 28 Jun 2012 16:59:04 +0000
From: Anthony Nadalin <tonynad@microsoft.com>
To: Adam Montville <amontville@tripwire.com>, "Kent_Landfield@McAfee.com" <Kent_Landfield@McAfee.com>, "kathleen.moriarty@emc.com" <kathleen.moriarty@emc.com>, "karen@scarfonecybersecurity.com" <karen@scarfonecybersecurity.com>, "sacm@ietf.org" <sacm@ietf.org>
Thread-Topic: [sacm] IETF 84
Thread-Index: AQHNVUeKYUpL4z7vTUubxQ1VahOvyJcP6b6AgAAExgCAAALAgIAAAP+AgAABzMA=
Date: Thu, 28 Jun 2012 16:59:03 +0000
Message-ID: <B26C1EF377CB694EAB6BDDC8E624B6E74F3BAC5D@BL2PRD0310MB362.namprd03.prod.outlook.com>
References: <CC11F4A4.36422%kent_landfield@mcafee.com> <CC11D9C8.D85E%amontville@tripwire.com>
In-Reply-To: <CC11D9C8.D85E%amontville@tripwire.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [131.107.174.57]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OrganizationHeadersPreserved: BL2PRD0310HT002.namprd03.prod.outlook.com
X-FOPE-CONNECTOR: Id%0$Dn%*$RO%0$TLS%0$FQDN%$TlsDn%
X-FOPE-CONNECTOR: Id%59$Dn%TRIPWIRE.COM$RO%2$TLS%6$FQDN%131.107.125.5$TlsDn%
X-FOPE-CONNECTOR: Id%59$Dn%MCAFEE.COM$RO%2$TLS%6$FQDN%131.107.125.5$TlsDn%
X-FOPE-CONNECTOR: Id%59$Dn%EMC.COM$RO%2$TLS%6$FQDN%131.107.125.5$TlsDn%
X-FOPE-CONNECTOR: Id%59$Dn%SCARFONECYBERSECURITY.COM$RO%2$TLS%6$FQDN%131.107.125.5$TlsDn%
X-FOPE-CONNECTOR: Id%59$Dn%IETF.ORG$RO%2$TLS%6$FQDN%131.107.125.5$TlsDn%
X-CrossPremisesHeadersPromoted: TK5EX14HUBC102.redmond.corp.microsoft.com
X-CrossPremisesHeadersFiltered: TK5EX14HUBC102.redmond.corp.microsoft.com
X-OriginatorOrg: microsoft.com
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 17:00:32 -0000

+1

-----Original Message-----
From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of Ada=
m Montville
Sent: Thursday, June 28, 2012 9:53 AM
To: Kent_Landfield@McAfee.com; kathleen.moriarty@emc.com; karen@scarfonecyb=
ersecurity.com; sacm@ietf.org
Subject: Re: [sacm] IETF 84

I would also prefer a day other than Sunday, though I can make that work if=
 needed.

Adam

From: kent_landfield <kent_landfield@mcafee.com<mailto:kent_landfield@mcafe=
e.com>>
Date: Thursday, June 28, 2012 9:48 AM
To: "kathleen.moriarty@emc.com<mailto:kathleen.moriarty@emc.com>" <kathleen=
.moriarty@emc.com<mailto:kathleen.moriarty@emc.com>>, "karen@scarfonecybers=
ecurity.com<mailto:karen@scarfonecybersecurity.com>" <karen@scarfonecyberse=
curity.com<mailto:karen@scarfonecybersecurity.com>>, "sacm@ietf.org<mailto:=
sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.org>>
Subject: Re: [sacm] IETF 84

Personally I'd rather not do Sunday if we can. It worked but we had a coupl=
e people that wanted to be there that did not arrive until after the meetin=
g and could not listen in as they were in transit at the time.

Kent Landfield

McAfee | An Intel Company
Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: Kathleen Moriarty <kathleen.moriarty@emc.com<mailto:kathleen.moriarty=
@emc.com>>
To: "karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com=
>" <karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>=
>, "sacm@ietf.org<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.or=
g>>
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From:sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-bounc=
es@ietf.org] On Behalf Of Karen Scarfone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there is=
 progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it wil=
l be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018

_______________________________________________
sacm mailing list
sacm@ietf.org
https://www.ietf.org/mailman/listinfo/sacm






From kathleen.moriarty@emc.com  Thu Jun 28 10:10:28 2012
Return-Path: <kathleen.moriarty@emc.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DCCFE21F8555 for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 10:10:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.298
X-Spam-Level: 
X-Spam-Status: No, score=-2.298 tagged_above=-999 required=5 tests=[AWL=0.300,  BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jyxumJAl2QCR for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 10:10:26 -0700 (PDT)
Received: from mexforward.lss.emc.com (hop-nat-141.emc.com [168.159.213.141]) by ietfa.amsl.com (Postfix) with ESMTP id C400C21F853E for <sacm@ietf.org>; Thu, 28 Jun 2012 10:10:25 -0700 (PDT)
Received: from hop04-l1d11-si01.isus.emc.com (HOP04-L1D11-SI01.isus.emc.com [10.254.111.54]) by mexforward.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id q5SHA3Pm009195 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 28 Jun 2012 13:10:16 -0400
Received: from mailhub.lss.emc.com (mailhubhoprd04.lss.emc.com [10.254.222.226]) by hop04-l1d11-si01.isus.emc.com (RSA Interceptor); Thu, 28 Jun 2012 13:09:49 -0400
Received: from mxhub11.corp.emc.com (mxhub11.corp.emc.com [10.254.92.106]) by mailhub.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id q5SH9mkf020529; Thu, 28 Jun 2012 13:09:48 -0400
Received: from mx15a.corp.emc.com ([169.254.1.189]) by mxhub11.corp.emc.com ([10.254.92.106]) with mapi; Thu, 28 Jun 2012 13:09:48 -0400
From: <kathleen.moriarty@emc.com>
To: <bakerj@mitre.org>, <karen@scarfonecybersecurity.com>, <sacm@ietf.org>
Date: Thu, 28 Jun 2012 13:09:47 -0400
Thread-Topic: [sacm] IETF 84
Thread-Index: AQHNVUeKYUpL4z7vTUubxQ1VahOvyJcQLMyAgAAExgD//8HKoIAAAc0A
Message-ID: <F5063677821E3B4F81ACFB7905573F2403949B53@MX15A.corp.emc.com>
References: <CC11CE59.D81E%amontville@tripwire.com> <CAAfuYh_qi0DaGTtMjiYtVoJCQVGa1UpxdLuOW_=Nwng2A8YEDA@mail.gmail.com> <F5063677821E3B4F81ACFB7905573F2403949B40@MX15A.corp.emc.com> <6C1C15D8B5510B4B8FF132B10D38651301DEE548@IMCMBX03.MITRE.ORG>
In-Reply-To: <6C1C15D8B5510B4B8FF132B10D38651301DEE548@IMCMBX03.MITRE.ORG>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_F5063677821E3B4F81ACFB7905573F2403949B53MX15Acorpemccom_"
MIME-Version: 1.0
X-EMM-MHVC: 1
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 17:10:29 -0000

--_000_F5063677821E3B4F81ACFB7905573F2403949B53MX15Acorpemccom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Jon,

We need to set an agenda and plan for a meeting, so the discussion does nee=
d to happen and is good to have on the list so that participation is not li=
mited to those that can't attend developer days.  We can of course discuss =
the use case development at developer days, but need to have discussions on=
 the list for the broader community.

We also have timelines to post -00 drafts and -01 prior to the IETF meeting=
s adhering to the IETF meeting dates schedule.  This gives attendees enough=
 time to review documents prior to the meeting.

Thank you,
Kathleen

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of Bak=
er, Jon
Sent: Thursday, June 28, 2012 12:59 PM
To: Moriarty, Kathleen; karen@scarfonecybersecurity.com; sacm@ietf.org
Subject: Re: [sacm] IETF 84

Does this conversation need to wait until the ietf meeting?

Given that many of the participants will be at developer days in two weeks =
maybe some discussion could be held afterhours there?

This might allow for a more mature draft to be discussed at the IETF meetin=
g a few weeks later.

Jon

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Jonathan O. Baker
G022 - IA Industry Collaboration
The MITRE Corporation
Email: bakerj@mitre.org<mailto:bakerj@mitre.org>

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of kat=
hleen.moriarty@emc.com
Sent: Thursday, June 28, 2012 12:39 PM
To: karen@scarfonecybersecurity.com; sacm@ietf.org
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From: sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-boun=
ces@ietf.org]<mailto:[mailto:sacm-bounces@ietf.org]> On Behalf Of Karen Sca=
rfone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018

--_000_F5063677821E3B4F81ACFB7905573F2403949B53MX15Acorpemccom_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40"><head><meta http-equiv=3DContent-Type content=
=3D"text/html; charset=3Dus-ascii"><meta name=3DGenerator content=3D"Micros=
oft Word 12 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle19
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle20
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue vli=
nk=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Hi Jon,<o=
:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;fo=
nt-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p=
><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri"=
,"sans-serif";color:#1F497D'>We need to set an agenda and plan for a meetin=
g, so the discussion does need to happen and is good to have on the list so=
 that participation is not limited to those that can&#8217;t attend develop=
er days.&nbsp; We can of course discuss the use case development at develop=
er days, but need to have discussions on the list for the broader community=
.&nbsp; <o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size=
:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p>=
</span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family=
:"Calibri","sans-serif";color:#1F497D'>We also have timelines to post -00 d=
rafts and -01 prior to the IETF meetings adhering to the IETF meeting dates=
 schedule.&nbsp; This gives attendees enough time to review documents prior=
 to the meeting.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbs=
p;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;fon=
t-family:"Calibri","sans-serif";color:#1F497D'>Thank you,<o:p></o:p></span>=
</p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calib=
ri","sans-serif";color:#1F497D'>Kathleen<o:p></o:p></span></p><p class=3DMs=
oNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";=
color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div style=3D'border:none;b=
order-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNorm=
al><b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>Fr=
om:</span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-se=
rif"'> sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] <b>On Behalf Of=
 </b>Baker, Jon<br><b>Sent:</b> Thursday, June 28, 2012 12:59 PM<br><b>To:<=
/b> Moriarty, Kathleen; karen@scarfonecybersecurity.com; sacm@ietf.org<br><=
b>Subject:</b> Re: [sacm] IETF 84<o:p></o:p></span></p></div></div><p class=
=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><span style=3D'font-=
size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Does this con=
versation need to wait until the ietf meeting?<o:p></o:p></span></p><p clas=
s=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-s=
erif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span=
 style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D=
'>Given that many of the participants will be at developer days in two week=
s maybe some discussion could be held afterhours there? <o:p></o:p></span><=
/p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibr=
i","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNo=
rmal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";col=
or:#1F497D'>This might allow for a more mature draft to be discussed at the=
 IETF meeting a few weeks later.<o:p></o:p></span></p><p class=3DMsoNormal>=
<span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1=
F497D'><o:p>&nbsp;</o:p></span></p><div><p class=3DMsoNormal><span style=3D=
'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Jon<o:p=
></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font=
-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><=
p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","=
sans-serif";color:#1F497D'>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-siz=
e:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Jonathan O. Bake=
r<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt=
;font-family:"Calibri","sans-serif";color:#1F497D'>G022 - IA Industry Colla=
boration<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size=
:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>The MITRE Corpora=
tion<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.=
0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Email: <a href=3D"mai=
lto:bakerj@mitre.org"><span style=3D'color:#1F497D;text-decoration:none'>ba=
kerj@mitre.org</span></a><o:p></o:p></span></p></div><p class=3DMsoNormal><=
span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F=
497D'><o:p>&nbsp;</o:p></span></p><div style=3D'border:none;border-left:sol=
id blue 1.5pt;padding:0in 0in 0in 4.0pt'><div><div style=3D'border:none;bor=
der-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal=
><b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From=
:</span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-seri=
f"'> sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] <b>On Behalf Of <=
/b>kathleen.moriarty@emc.com<br><b>Sent:</b> Thursday, June 28, 2012 12:39 =
PM<br><b>To:</b> karen@scarfonecybersecurity.com; sacm@ietf.org<br><b>Subje=
ct:</b> Re: [sacm] IETF 84<o:p></o:p></span></p></div></div><p class=3DMsoN=
ormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><span style=3D'font-size:11=
.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Thanks for starting =
the thread, Adam and offering to help Karen!<o:p></o:p></span></p><p class=
=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-se=
rif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'=
>A few of us have been working to update the use case document that David W=
altermire circulated.&nbsp; We may need help here as I am not sure if we ha=
ve content for each of the use cases yet.&nbsp; I provided content to updat=
e use case 5.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font=
-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;<=
/o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-f=
amily:"Calibri","sans-serif";color:#1F497D'>The hope was to review the use =
cases in a side meeting and start looking at a charter in support of the de=
fined use cases.&nbsp; From there, we can figure out what work is needed to=
 support the use cases and charter.&nbsp; This would be used to set the mil=
estones.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size=
:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p>=
</span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family=
:"Calibri","sans-serif";color:#1F497D'>Should we set a meeting for the Sund=
ay again?<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-siz=
e:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p=
></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-famil=
y:"Calibri","sans-serif";color:#1F497D'>Thank you,<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sa=
ns-serif";color:#1F497D'>Kathleen<o:p></o:p></span></p><p class=3DMsoNormal=
><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#=
1F497D'><o:p>&nbsp;</o:p></span></p><div style=3D'border:none;border-top:so=
lid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span></=
b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> <a hr=
ef=3D"mailto:sacm-bounces@ietf.org">sacm-bounces@ietf.org</a> <a href=3D"ma=
ilto:[mailto:sacm-bounces@ietf.org]">[mailto:sacm-bounces@ietf.org]</a> <b>=
On Behalf Of </b>Karen Scarfone<br><b>Sent:</b> Thursday, June 28, 2012 12:=
22 PM<br><b>To:</b> <a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br><=
b>Subject:</b> Re: [sacm] IETF 84<o:p></o:p></span></p></div><p class=3DMso=
Normal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal>I've gotten out of the loo=
p on this as well. I'm still available to edit any documents being produced=
 by this effort.<o:p></o:p></p><div><p class=3DMsoNormal><o:p>&nbsp;</o:p><=
/p></div><div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=
=3DMsoNormal style=3D'margin-bottom:12.0pt'>Karen<o:p></o:p></p><div><p cla=
ss=3DMsoNormal>On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville &lt;<a href=
=3D"mailto:amontville@tripwire.com" target=3D"_blank">amontville@tripwire.c=
om</a>&gt; wrote:<o:p></o:p></p><p class=3DMsoNormal>All:<br><br>I've been =
out of this loop for a while, unfortunately. &nbsp;Hopefully, there<br>is p=
rogress being made on the use cases and other efforts (I.e. content<br>repo=
sitory) that were proposed a couple of months ago.<br><br>Can anyone tell m=
e whether there is a scheduled meeting (side or<br>otherwise) for SACM duri=
ng IETF 84? &nbsp;If so, do we have any idea when it<br>will be held?<br><b=
r>Regards,<br><br>Adam<br><br><br>_________________________________________=
______<br>sacm mailing list<br><a href=3D"mailto:sacm@ietf.org">sacm@ietf.o=
rg</a><br><a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=3D"=
_blank">https://www.ietf.org/mailman/listinfo/sacm</a><o:p></o:p></p></div>=
<p class=3DMsoNormal><br><br clear=3Dall><o:p></o:p></p><div><p class=3DMso=
Normal><o:p>&nbsp;</o:p></p></div><p class=3DMsoNormal style=3D'margin-bott=
om:12.0pt'>-- <br>Karen Scarfone, Principal Consultant, Scarfone Cybersecur=
ity<br><a href=3D"mailto:karen@scarfonecybersecurity.com" target=3D"_blank"=
>karen@scarfonecybersecurity.com</a>&nbsp;&nbsp; (703)401-1018<o:p></o:p></=
p></div></div></div></body></html>=

--_000_F5063677821E3B4F81ACFB7905573F2403949B53MX15Acorpemccom_--

From Kent_Landfield@mcafee.com  Thu Jun 28 10:11:48 2012
Return-Path: <Kent_Landfield@mcafee.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5F66921F8555 for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 10:11:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.598
X-Spam-Level: 
X-Spam-Status: No, score=-6.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Qn9XDnYJW9F5 for <sacm@ietfa.amsl.com>; Thu, 28 Jun 2012 10:11:47 -0700 (PDT)
Received: from dalsmrelay2.nai.com (dalsmrelay2.nai.com [205.227.136.216]) by ietfa.amsl.com (Postfix) with ESMTP id 4A10E21F853E for <sacm@ietf.org>; Thu, 28 Jun 2012 10:11:47 -0700 (PDT)
Received: from DALEXHT1.corp.nai.org (unknown [10.64.5.51]) by dalsmrelay2.nai.com with smtp id 04da_05b5_aba84bfe_8c0b_4dfc_bc82_93a5f56cf9b8; Thu, 28 Jun 2012 12:11:37 -0500
Received: from AMERDALEXMB1.corp.nai.org ([fe80::b534:4a0d:1289:2d2d]) by DALEXHT1.corp.nai.org ([::1]) with mapi; Thu, 28 Jun 2012 12:07:47 -0500
From: <Kent_Landfield@McAfee.com>
To: <bakerj@mitre.org>, <kathleen.moriarty@emc.com>, <karen@scarfonecybersecurity.com>, <sacm@ietf.org>
Date: Thu, 28 Jun 2012 12:08:35 -0500
Thread-Topic: [sacm] IETF 84
Thread-Index: Ac1VUIn35sRIjOsgTjWDcvLkwiK9Cw==
Message-ID: <CC11F87A.36431%kent_landfield@mcafee.com>
In-Reply-To: <6C1C15D8B5510B4B8FF132B10D38651301DEE548@IMCMBX03.MITRE.ORG>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.2.2.120421
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_CC11F87A36431kentlandfieldmcafeecom_"
MIME-Version: 1.0
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Jun 2012 17:11:48 -0000

--_000_CC11F87A36431kentlandfieldmcafeecom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Absolutely not!  We can be having it right now.  I agree there is no need t=
o wait for meetings to have these discussions. Quite the contrary, we shoul=
d be having these discussions on the list. Since a large section of the com=
munity participants will be at Dev Days we can also use that as a way to ma=
ture the discussion and documented use cases.

And from my perspective, I see the use case I-D covering more that what wil=
l be a single proposed working group charter might cover.  It also discusse=
s items that are currently being worked in other working groups.  We initia=
lly thought the use case document could drive the charter discussion but th=
at seems to be artificially delaying the discussion from starting.

Kent Landfield

McAfee | An Intel Company
Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: <Baker>, Jon <bakerj@mitre.org<mailto:bakerj@mitre.org>>
To: Kathleen Moriarty <kathleen.moriarty@emc.com<mailto:kathleen.moriarty@e=
mc.com>>, "karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecuri=
ty.com>" <karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurit=
y.com>>, "sacm@ietf.org<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@i=
etf.org>>
Subject: Re: [sacm] IETF 84

Does this conversation need to wait until the ietf meeting?

Given that many of the participants will be at developer days in two weeks =
maybe some discussion could be held afterhours there?

This might allow for a more mature draft to be discussed at the IETF meetin=
g a few weeks later.

Jon

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Jonathan O. Baker
G022 - IA Industry Collaboration
The MITRE Corporation
Email: bakerj@mitre.org<mailto:bakerj@mitre.org>

From: sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-boun=
ces@ietf.org] On Behalf Of kathleen.moriarty@emc.com<mailto:kathleen.moriar=
ty@emc.com>
Sent: Thursday, June 28, 2012 12:39 PM
To: karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>=
; sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From:sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-bounc=
es@ietf.org]<mailto:[mailto:sacm-bounces@ietf.org]> On Behalf Of Karen Scar=
fone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018

--_000_CC11F87A36431kentlandfieldmcafeecom_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html><head></head><body style=3D"word-wrap: break-word; -webkit-nbsp-mode:=
 space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-si=
ze: 16px; font-family: 'Times New Roman', sans-serif; "><div><div><div>Abso=
lutely not! &nbsp;We can be having it right now. &nbsp;I agree there is no =
need to wait for meetings to have these discussions. Quite the contrary, we=
 should be having these discussions on the list. Since a large section of t=
he community participants will be at Dev Days we can also use that as a way=
 to mature the discussion and documented use cases. &nbsp;</div><div><br></=
div><div>And from my perspective, I see the use case I-D covering more that=
 what will be a single proposed working group charter might cover. &nbsp;It=
 also discusses items that are currently being worked in other working grou=
ps. &nbsp;We initially thought the use case document could drive the charte=
r discussion but that seems to be artificially delaying the discussion from=
 starting. &nbsp;</div><div><br></div><div><div><span class=3D"Apple-style-=
span" style=3D"color: rgb(96, 106, 113); font-size: 12px; -webkit-border-ho=
rizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px; font-family: A=
rial, Helvetica, sans-serif; "><strong>Kent Landfield</strong></span><span =
class=3D"Apple-style-span" style=3D"color: rgb(96, 106, 113); font-size: 12=
px; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing=
: 1px; font-family: Arial, Helvetica, sans-serif; "><br></span><span class=
=3D"Apple-style-span" style=3D"color: rgb(96, 106, 113); font-size: 12px; -=
webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px=
; font-family: Arial, Helvetica, sans-serif; "><br></span><span class=3D"Ap=
ple-style-span" style=3D"color: rgb(96, 106, 113); font-size: 12px; -webkit=
-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px; font=
-family: Arial, Helvetica, sans-serif; "><strong>McAfee | An Intel Company<=
/strong></span><span class=3D"Apple-style-span" style=3D"color: rgb(96, 106=
, 113); font-size: 12px; -webkit-border-horizontal-spacing: 1px; -webkit-bo=
rder-vertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif; "><b=
r></span><span class=3D"Apple-style-span" style=3D"color: rgb(96, 106, 113)=
; font-size: 12px; -webkit-border-horizontal-spacing: 1px; -webkit-border-v=
ertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif; ">Direct: =
+1.972.963.7096&nbsp;</span><span class=3D"Apple-style-span" style=3D"color=
: rgb(96, 106, 113); font-size: 12px; -webkit-border-horizontal-spacing: 1p=
x; -webkit-border-vertical-spacing: 1px; font-family: Arial, Helvetica, san=
s-serif; "><br></span><span class=3D"Apple-style-span" style=3D"color: rgb(=
96, 106, 113); font-size: 12px; -webkit-border-horizontal-spacing: 1px; -we=
bkit-border-vertical-spacing: 1px; font-family: Arial, Helvetica, sans-seri=
f; ">Mobile: +1.817.637.8026</span><span class=3D"Apple-style-span" style=
=3D"color: rgb(96, 106, 113); font-size: 12px; -webkit-border-horizontal-sp=
acing: 1px; -webkit-border-vertical-spacing: 1px; font-family: Arial, Helve=
tica, sans-serif; "><br></span><span class=3D"Apple-style-span" style=3D"co=
lor: rgb(96, 106, 113); font-size: 12px; -webkit-border-horizontal-spacing:=
 1px; -webkit-border-vertical-spacing: 1px; font-family: Arial, Helvetica, =
sans-serif; "><strong>Web:&nbsp;</strong></span><span class=3D"Apple-style-=
span" style=3D"color: rgb(96, 106, 113); font-size: 12px; -webkit-border-ho=
rizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px; font-family: A=
rial, Helvetica, sans-serif; "><a href=3D"http://www.mcafee.com/" style=3D"=
color: rgb(96, 106, 113) !important; ">www.mcafee.com</a></span></div></div=
></div></div><div><br></div><span id=3D"OLK_SRC_BODY_SECTION"><div style=3D=
"font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-=
BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING=
-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT=
: medium none; PADDING-TOP: 3pt"><span style=3D"font-weight:bold">From: </s=
pan> &lt;Baker&gt;, Jon &lt;<a href=3D"mailto:bakerj@mitre.org">bakerj@mitr=
e.org</a>&gt;<br><span style=3D"font-weight:bold">To: </span> Kathleen Mori=
arty &lt;<a href=3D"mailto:kathleen.moriarty@emc.com">kathleen.moriarty@emc=
.com</a>&gt;, "<a href=3D"mailto:karen@scarfonecybersecurity.com">karen@sca=
rfonecybersecurity.com</a>" &lt;<a href=3D"mailto:karen@scarfonecybersecuri=
ty.com">karen@scarfonecybersecurity.com</a>&gt;, "<a href=3D"mailto:sacm@ie=
tf.org">sacm@ietf.org</a>" &lt;<a href=3D"mailto:sacm@ietf.org">sacm@ietf.o=
rg</a>&gt;<br><span style=3D"font-weight:bold">Subject: </span> Re: [sacm] =
IETF 84<br></div><div><br></div><blockquote id=3D"MAC_OUTLOOK_ATTRIBUTION_B=
LOCKQUOTE" style=3D"BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0=
 0 0 5;"><div xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:sche=
mas-microsoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:offic=
e:word" xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=
=3D"http://www.w3.org/TR/REC-html40"><meta http-equiv=3D"Content-Type" cont=
ent=3D"text/html; charset=3Dutf-8"><meta name=3D"Generator" content=3D"Micr=
osoft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--><div lang=3D"EN-US" link=3D"blue" vlink=
=3D"purple"><div class=3D"WordSection1"><p class=3D"MsoNormal"><span style=
=3D"font-size: 11pt; color: rgb(31, 73, 125); font-family: Calibri, sans-se=
rif; ">Does this conversation need to wait until the ietf meeting?<o:p></o:=
p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color: =
rgb(31, 73, 125); font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></sp=
an></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31=
, 73, 125); font-family: Calibri, sans-serif; ">Given that many of the part=
icipants will be at developer days in two weeks maybe some discussion could=
 be held afterhours there?
<o:p></o:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt=
; color: rgb(31, 73, 125); font-family: Calibri, sans-serif; "><o:p>&nbsp;<=
/o:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; colo=
r: rgb(31, 73, 125); font-family: Calibri, sans-serif; ">This might allow f=
or a more mature draft to be discussed at the IETF meeting a few weeks late=
r.<o:p></o:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11=
pt; color: rgb(31, 73, 125); font-family: Calibri, sans-serif; "><o:p>&nbsp=
;</o:p></span></p><div><p class=3D"MsoNormal"><span style=3D"font-size: 11p=
t; color: rgb(31, 73, 125); font-family: Calibri, sans-serif; ">Jon<o:p></o=
:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color:=
 rgb(31, 73, 125); font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></s=
pan></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(3=
1, 73, 125); font-family: Calibri, sans-serif; ">=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D<o:p></o:p></span></p><p class=3D"MsoNorma=
l"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); font-family: Ca=
libri, sans-serif; ">Jonathan O. Baker<o:p></o:p></span></p><p class=3D"Mso=
Normal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); font-famil=
y: Calibri, sans-serif; ">G022 - IA Industry Collaboration<o:p></o:p></span=
></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, =
73, 125); font-family: Calibri, sans-serif; ">The MITRE Corporation<o:p></o=
:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color:=
 rgb(31, 73, 125); font-family: Calibri, sans-serif; ">Email:
<a href=3D"mailto:bakerj@mitre.org"><span style=3D"color:#1F497D;text-decor=
ation:none">bakerj@mitre.org</span></a><o:p></o:p></span></p></div><p class=
=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); fon=
t-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></span></p><div style=3D"=
border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt"><div><d=
iv style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0i=
n 0in"><p class=3D"MsoNormal"><b><span style=3D"font-size: 10pt; font-famil=
y: Tahoma, sans-serif; ">From:</span></b><span style=3D"font-size: 10pt; fo=
nt-family: Tahoma, sans-serif; "> <a href=3D"mailto:sacm-bounces@ietf.org">=
sacm-bounces@ietf.org</a> [<a href=3D"mailto:sacm-bounces@ietf.org">mailto:=
sacm-bounces@ietf.org</a>]
<b>On Behalf Of </b><a href=3D"mailto:kathleen.moriarty@emc.com">kathleen.m=
oriarty@emc.com</a><br><b>Sent:</b> Thursday, June 28, 2012 12:39 PM<br><b>=
To:</b> <a href=3D"mailto:karen@scarfonecybersecurity.com">karen@scarfonecy=
bersecurity.com</a>; <a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>=
<b>Subject:</b> Re: [sacm] IETF 84<o:p></o:p></span></p></div></div><p clas=
s=3D"MsoNormal"><o:p>&nbsp;</o:p></p><p class=3D"MsoNormal"><span style=3D"=
font-size: 11pt; color: rgb(31, 73, 125); font-family: Calibri, sans-serif;=
 ">Thanks for starting the thread, Adam and offering to help Karen!<o:p></o=
:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color:=
 rgb(31, 73, 125); font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></s=
pan></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(3=
1, 73, 125); font-family: Calibri, sans-serif; ">A few of us have been work=
ing to update the use case document that David Waltermire circulated.&nbsp;=
 We may need help here as I am not sure if we have content for
 each of the use cases yet.&nbsp; I provided content to update use case 5.<=
o:p></o:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt;=
 color: rgb(31, 73, 125); font-family: Calibri, sans-serif; "><o:p>&nbsp;</=
o:p></span></p><p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color=
: rgb(31, 73, 125); font-family: Calibri, sans-serif; ">The hope was to rev=
iew the use cases in a side meeting and start looking at a charter in suppo=
rt of the defined use cases.&nbsp; From there, we can figure out what
 work is needed to support the use cases and charter.&nbsp; This would be u=
sed to set the milestones.<o:p></o:p></span></p><p class=3D"MsoNormal"><spa=
n style=3D"font-size: 11pt; color: rgb(31, 73, 125); font-family: Calibri, =
sans-serif; "><o:p>&nbsp;</o:p></span></p><p class=3D"MsoNormal"><span styl=
e=3D"font-size: 11pt; color: rgb(31, 73, 125); font-family: Calibri, sans-s=
erif; ">Should we set a meeting for the Sunday again?<o:p></o:p></span></p>=
<p class=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 1=
25); font-family: Calibri, sans-serif; "><o:p>&nbsp;</o:p></span></p><p cla=
ss=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); f=
ont-family: Calibri, sans-serif; ">Thank you,<o:p></o:p></span></p><p class=
=3D"MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); fon=
t-family: Calibri, sans-serif; ">Kathleen<o:p></o:p></span></p><p class=3D"=
MsoNormal"><span style=3D"font-size: 11pt; color: rgb(31, 73, 125); font-fa=
mily: Calibri, sans-serif; "><o:p>&nbsp;</o:p></span></p><div style=3D"bord=
er:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in"><p class=
=3D"MsoNormal"><b><span style=3D"font-size: 10pt; font-family: Tahoma, sans=
-serif; ">From:</span></b><span style=3D"font-size: 10pt; font-family: Taho=
ma, sans-serif; "><a href=3D"mailto:sacm-bounces@ietf.org">sacm-bounces@iet=
f.org</a> <a href=3D"mailto:[mailto:sacm-bounces@ietf.org]">
[mailto:sacm-bounces@ietf.org]</a> <b>On Behalf Of </b>Karen Scarfone<br><b=
>Sent:</b> Thursday, June 28, 2012 12:22 PM<br><b>To:</b> <a href=3D"mailto=
:sacm@ietf.org">sacm@ietf.org</a><br><b>Subject:</b> Re: [sacm] IETF 84<o:p=
></o:p></span></p></div><p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p><p clas=
s=3D"MsoNormal">I've gotten out of the loop on this as well. I'm still avai=
lable to edit any documents being produced by this effort.<o:p></o:p></p><d=
iv><p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p></div><div><p class=3D"MsoNo=
rmal"><o:p>&nbsp;</o:p></p></div><div><p class=3D"MsoNormal" style=3D"margi=
n-bottom:12.0pt">Karen<o:p></o:p></p><div><p class=3D"MsoNormal">On Thu, Ju=
n 28, 2012 at 12:03 PM, Adam Montville &lt;<a href=3D"mailto:amontville@tri=
pwire.com" target=3D"_blank">amontville@tripwire.com</a>&gt; wrote:<o:p></o=
:p></p><p class=3D"MsoNormal">All:<br><br>
I've been out of this loop for a while, unfortunately. &nbsp;Hopefully, the=
re<br>
is progress being made on the use cases and other efforts (I.e. content<br>=
repository) that were proposed a couple of months ago.<br><br>
Can anyone tell me whether there is a scheduled meeting (side or<br>
otherwise) for SACM during IETF 84? &nbsp;If so, do we have any idea when i=
t<br>
will be held?<br><br>
Regards,<br><br>
Adam<br><br><br>
_______________________________________________<br>
sacm mailing list<br><a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br>=
<a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=3D"_blank">ht=
tps://www.ietf.org/mailman/listinfo/sacm</a><o:p></o:p></p></div><p class=
=3D"MsoNormal"><br><br clear=3D"all"><o:p></o:p></p><div><p class=3D"MsoNor=
mal"><o:p>&nbsp;</o:p></p></div><p class=3D"MsoNormal" style=3D"margin-bott=
om:12.0pt">-- <br>
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity<br><a href=3D"=
mailto:karen@scarfonecybersecurity.com" target=3D"_blank">karen@scarfonecyb=
ersecurity.com</a>&nbsp;&nbsp; (703)401-1018<o:p></o:p></p></div></div></di=
v></div></div></blockquote></span></body></html>

--_000_CC11F87A36431kentlandfieldmcafeecom_--

From kathleen.moriarty@emc.com  Fri Jun 29 09:07:45 2012
Return-Path: <kathleen.moriarty@emc.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4A4B421F857D for <sacm@ietfa.amsl.com>; Fri, 29 Jun 2012 09:07:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.373
X-Spam-Level: 
X-Spam-Status: No, score=-2.373 tagged_above=-999 required=5 tests=[AWL=0.225,  BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sZ1NjcE4mBzP for <sacm@ietfa.amsl.com>; Fri, 29 Jun 2012 09:07:44 -0700 (PDT)
Received: from mexforward.lss.emc.com (hop-nat-141.emc.com [168.159.213.141]) by ietfa.amsl.com (Postfix) with ESMTP id AF9E021F8513 for <sacm@ietf.org>; Fri, 29 Jun 2012 09:07:43 -0700 (PDT)
Received: from hop04-l1d11-si01.isus.emc.com (HOP04-L1D11-SI01.isus.emc.com [10.254.111.54]) by mexforward.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id q5TG7fve023100 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 29 Jun 2012 12:07:42 -0400
Received: from mailhub.lss.emc.com (mailhub.lss.emc.com [10.254.222.129]) by hop04-l1d11-si01.isus.emc.com (RSA Interceptor); Fri, 29 Jun 2012 12:07:34 -0400
Received: from mxhub33.corp.emc.com (mxhub33.corp.emc.com [10.254.93.81]) by mailhub.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id q5TG7YBZ022530; Fri, 29 Jun 2012 12:07:34 -0400
Received: from mx15a.corp.emc.com ([169.254.1.189]) by mxhub33.corp.emc.com ([::1]) with mapi; Fri, 29 Jun 2012 12:07:33 -0400
From: <kathleen.moriarty@emc.com>
To: <Kent_Landfield@McAfee.com>, <bakerj@mitre.org>, <karen@scarfonecybersecurity.com>, <sacm@ietf.org>
Date: Fri, 29 Jun 2012 12:07:32 -0400
Thread-Topic: [sacm] IETF 84
Thread-Index: Ac1VUIn35sRIjOsgTjWDcvLkwiK9CwAwFQeQ
Message-ID: <F5063677821E3B4F81ACFB7905573F2403AA99D4@MX15A.corp.emc.com>
References: <6C1C15D8B5510B4B8FF132B10D38651301DEE548@IMCMBX03.MITRE.ORG> <CC11F87A.36431%kent_landfield@mcafee.com>
In-Reply-To: <CC11F87A.36431%kent_landfield@mcafee.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_F5063677821E3B4F81ACFB7905573F2403AA99D4MX15Acorpemccom_"
MIME-Version: 1.0
X-EMM-MHVC: 1
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Jun 2012 16:07:45 -0000

--_000_F5063677821E3B4F81ACFB7905573F2403AA99D4MX15Acorpemccom_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hello,

The agenda was released for IETF 84 and is at the following link:
https://datatracker.ietf.org/meeting/84/agenda.txt

Do people have an opinion as to when they would like the meeting to take pl=
ace (cannot conflict with other IETF meeting times or plenary sessions)?  I=
f it helps, MILE is scheduled for Tuesday afternoon right now.  NEA is not =
scheduled to meet.

We will need to put in the request soon for planning purposes for both the =
IETF and attendees.

Thank you,
Kathleen

From: sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] On Behalf Of Ken=
t_Landfield@McAfee.com
Sent: Thursday, June 28, 2012 1:09 PM
To: bakerj@mitre.org; Moriarty, Kathleen; karen@scarfonecybersecurity.com; =
sacm@ietf.org
Subject: Re: [sacm] IETF 84

Absolutely not!  We can be having it right now.  I agree there is no need t=
o wait for meetings to have these discussions. Quite the contrary, we shoul=
d be having these discussions on the list. Since a large section of the com=
munity participants will be at Dev Days we can also use that as a way to ma=
ture the discussion and documented use cases.

And from my perspective, I see the use case I-D covering more that what wil=
l be a single proposed working group charter might cover.  It also discusse=
s items that are currently being worked in other working groups.  We initia=
lly thought the use case document could drive the charter discussion but th=
at seems to be artificially delaying the discussion from starting.

Kent Landfield

McAfee | An Intel Company
Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: <Baker>, Jon <bakerj@mitre.org<mailto:bakerj@mitre.org>>
To: Kathleen Moriarty <kathleen.moriarty@emc.com<mailto:kathleen.moriarty@e=
mc.com>>, "karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecuri=
ty.com>" <karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurit=
y.com>>, "sacm@ietf.org<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@i=
etf.org>>
Subject: Re: [sacm] IETF 84

Does this conversation need to wait until the ietf meeting?

Given that many of the participants will be at developer days in two weeks =
maybe some discussion could be held afterhours there?

This might allow for a more mature draft to be discussed at the IETF meetin=
g a few weeks later.

Jon

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Jonathan O. Baker
G022 - IA Industry Collaboration
The MITRE Corporation
Email: bakerj@mitre.org<mailto:bakerj@mitre.org>

From: sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-boun=
ces@ietf.org] On Behalf Of kathleen.moriarty@emc.com<mailto:kathleen.moriar=
ty@emc.com>
Sent: Thursday, June 28, 2012 12:39 PM
To: karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>=
; sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From:sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-bounc=
es@ietf.org]<mailto:[mailto:sacm-bounces@ietf.org]> On Behalf Of Karen Scar=
fone
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018

--_000_F5063677821E3B4F81ACFB7905573F2403AA99D4MX15Acorpemccom_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40"><head><meta http-equiv=3DContent-Type content=
=3D"text/html; charset=3Dus-ascii"><meta name=3DGenerator content=3D"Micros=
oft Word 12 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.apple-style-span
	{mso-style-name:apple-style-span;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle21
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle22
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle23
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue vli=
nk=3Dpurple style=3D'word-wrap: break-word;-webkit-nbsp-mode: space;-webkit=
-line-break: after-white-space'><div class=3DWordSection1><p class=3DMsoNor=
mal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";colo=
r:#1F497D'>Hello,<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'=
font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nb=
sp;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;fo=
nt-family:"Calibri","sans-serif";color:#1F497D'>The agenda was released for=
 IETF 84 and is at the following link:<o:p></o:p></span></p><p class=3DMsoN=
ormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";co=
lor:#1F497D'><a href=3D"https://datatracker.ietf.org/meeting/84/agenda.txt"=
>https://datatracker.ietf.org/meeting/84/agenda.txt</a><o:p></o:p></span></=
p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri=
","sans-serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNor=
mal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";colo=
r:#1F497D'>Do people have an opinion as to when they would like the meeting=
 to take place (cannot conflict with other IETF meeting times or plenary se=
ssions)?&nbsp; If it helps, MILE is scheduled for Tuesday afternoon right n=
ow.&nbsp; NEA is not scheduled to meet.<o:p></o:p></span></p><p class=3DMso=
Normal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";c=
olor:#1F497D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span style=
=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>We w=
ill need to put in the request soon for planning purposes for both the IETF=
 and attendees.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'fo=
nt-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp=
;</o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font=
-family:"Calibri","sans-serif";color:#1F497D'>Thank you,<o:p></o:p></span><=
/p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibr=
i","sans-serif";color:#1F497D'>Kathleen<o:p></o:p></span></p><p class=3DMso=
Normal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";c=
olor:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div style=3D'border:none;bo=
rder-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNorma=
l><b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>Fro=
m:</span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-ser=
if"'> sacm-bounces@ietf.org [mailto:sacm-bounces@ietf.org] <b>On Behalf Of =
</b>Kent_Landfield@McAfee.com<br><b>Sent:</b> Thursday, June 28, 2012 1:09 =
PM<br><b>To:</b> bakerj@mitre.org; Moriarty, Kathleen; karen@scarfonecybers=
ecurity.com; sacm@ietf.org<br><b>Subject:</b> Re: [sacm] IETF 84<o:p></o:p>=
</span></p></div></div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><div>=
<div><p class=3DMsoNormal><span style=3D'color:black'>Absolutely not! &nbsp=
;We can be having it right now. &nbsp;I agree there is no need to wait for =
meetings to have these discussions. Quite the contrary, we should be having=
 these discussions on the list. Since a large section of the community part=
icipants will be at Dev Days we can also use that as a way to mature the di=
scussion and documented use cases. &nbsp;<o:p></o:p></span></p></div><div><=
p class=3DMsoNormal><span style=3D'color:black'><o:p>&nbsp;</o:p></span></p=
></div><div><p class=3DMsoNormal><span style=3D'color:black'>And from my pe=
rspective, I see the use case I-D covering more that what will be a single =
proposed working group charter might cover. &nbsp;It also discusses items t=
hat are currently being worked in other working groups. &nbsp;We initially =
thought the use case document could drive the charter discussion but that s=
eems to be artificially delaying the discussion from starting. &nbsp;<o:p><=
/o:p></span></p></div><div><p class=3DMsoNormal><span style=3D'color:black'=
><o:p>&nbsp;</o:p></span></p></div><div><div><p class=3DMsoNormal><strong><=
span style=3D'font-size:9.0pt;font-family:"Arial","sans-serif";color:#606A7=
1'>Kent Landfield</span></strong><span style=3D'font-size:9.0pt;font-family=
:"Arial","sans-serif";color:#606A71'><br><br><strong><span style=3D'font-fa=
mily:"Arial","sans-serif"'>McAfee | An Intel Company</span></strong><br><sp=
an class=3Dapple-style-span>Direct: +1.972.963.7096&nbsp;</span><br><span c=
lass=3Dapple-style-span>Mobile: +1.817.637.8026</span><br><strong><span sty=
le=3D'font-family:"Arial","sans-serif"'>Web:&nbsp;</span></strong><span cla=
ss=3Dapple-style-span><a href=3D"http://www.mcafee.com/">www.mcafee.com</a>=
</span></span><span style=3D'color:black'><o:p></o:p></span></p></div></div=
></div></div><div><p class=3DMsoNormal><span style=3D'color:black'><o:p>&nb=
sp;</o:p></span></p></div><div style=3D'border:none;border-top:solid #B5C4D=
F 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:black'>From: </spa=
n></b><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";co=
lor:black'>&lt;Baker&gt;, Jon &lt;<a href=3D"mailto:bakerj@mitre.org">baker=
j@mitre.org</a>&gt;<br><b>To: </b>Kathleen Moriarty &lt;<a href=3D"mailto:k=
athleen.moriarty@emc.com">kathleen.moriarty@emc.com</a>&gt;, &quot;<a href=
=3D"mailto:karen@scarfonecybersecurity.com">karen@scarfonecybersecurity.com=
</a>&quot; &lt;<a href=3D"mailto:karen@scarfonecybersecurity.com">karen@sca=
rfonecybersecurity.com</a>&gt;, &quot;<a href=3D"mailto:sacm@ietf.org">sacm=
@ietf.org</a>&quot; &lt;<a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a>&=
gt;<br><b>Subject: </b>Re: [sacm] IETF 84<o:p></o:p></span></p></div><div><=
p class=3DMsoNormal><span style=3D'color:black'><o:p>&nbsp;</o:p></span></p=
></div><blockquote style=3D'border:none;border-left:solid #B5C4DF 4.5pt;pad=
ding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-right:0in' id=3D"MAC_OUTLO=
OK_ATTRIBUTION_BLOCKQUOTE"><div><div><p class=3DMsoNormal><span style=3D'fo=
nt-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Does this =
conversation need to wait until the ietf meeting?</span><span style=3D'colo=
r:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-siz=
e:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>&nbsp;</span><sp=
an style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span s=
tyle=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>=
Given that many of the participants will be at developer days in two weeks =
maybe some discussion could be held afterhours there? </span><span style=3D=
'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'fon=
t-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>&nbsp;</spa=
n><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><s=
pan style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F4=
97D'>This might allow for a more mature draft to be discussed at the IETF m=
eeting a few weeks later.</span><span style=3D'color:black'><o:p></o:p></sp=
an></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D'>&nbsp;</span><span style=3D'color:black'=
><o:p></o:p></span></p><div><p class=3DMsoNormal><span style=3D'font-size:1=
1.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Jon</span><span sty=
le=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=
=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>&nbs=
p;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNo=
rmal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";col=
or:#1F497D'>=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D</span=
><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><sp=
an style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F49=
7D'>Jonathan O. Baker</span><span style=3D'color:black'><o:p></o:p></span><=
/p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibr=
i","sans-serif";color:#1F497D'>G022 - IA Industry Collaboration</span><span=
 style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span sty=
le=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Th=
e MITRE Corporation</span><span style=3D'color:black'><o:p></o:p></span></p=
><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri"=
,"sans-serif";color:#1F497D'>Email: <a href=3D"mailto:bakerj@mitre.org"><sp=
an style=3D'color:#1F497D;text-decoration:none'>bakerj@mitre.org</span></a>=
</span><span style=3D'color:black'><o:p></o:p></span></p></div><p class=3DM=
soNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"=
;color:#1F497D'>&nbsp;</span><span style=3D'color:black'><o:p></o:p></span>=
</p><div style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in =
0in 4.0pt'><div><div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;pa=
dding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span style=3D'font-size:1=
0.0pt;font-family:"Tahoma","sans-serif";color:black'>From:</span></b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:black'> <=
a href=3D"mailto:sacm-bounces@ietf.org">sacm-bounces@ietf.org</a> [<a href=
=3D"mailto:sacm-bounces@ietf.org">mailto:sacm-bounces@ietf.org</a>] <b>On B=
ehalf Of </b><a href=3D"mailto:kathleen.moriarty@emc.com">kathleen.moriarty=
@emc.com</a><br><b>Sent:</b> Thursday, June 28, 2012 12:39 PM<br><b>To:</b>=
 <a href=3D"mailto:karen@scarfonecybersecurity.com">karen@scarfonecybersecu=
rity.com</a>; <a href=3D"mailto:sacm@ietf.org">sacm@ietf.org</a><br><b>Subj=
ect:</b> Re: [sacm] IETF 84</span><span style=3D'color:black'><o:p></o:p></=
span></p></div></div><p class=3DMsoNormal><span style=3D'color:black'>&nbsp=
;<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt=
;font-family:"Calibri","sans-serif";color:#1F497D'>Thanks for starting the =
thread, Adam and offering to help Karen!</span><span style=3D'color:black'>=
<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;=
font-family:"Calibri","sans-serif";color:#1F497D'>&nbsp;</span><span style=
=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'=
font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>A few of=
 us have been working to update the use case document that David Waltermire=
 circulated.&nbsp; We may need help here as I am not sure if we have conten=
t for each of the use cases yet.&nbsp; I provided content to update use cas=
e 5.</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMso=
Normal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";c=
olor:#1F497D'>&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></=
p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri=
","sans-serif";color:#1F497D'>The hope was to review the use cases in a sid=
e meeting and start looking at a charter in support of the defined use case=
s.&nbsp; From there, we can figure out what work is needed to support the u=
se cases and charter.&nbsp; This would be used to set the milestones.</span=
><span style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><sp=
an style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F49=
7D'>&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=
=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-se=
rif";color:#1F497D'>Should we set a meeting for the Sunday again?</span><sp=
an style=3D'color:black'><o:p></o:p></span></p><p class=3DMsoNormal><span s=
tyle=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>=
&nbsp;</span><span style=3D'color:black'><o:p></o:p></span></p><p class=3DM=
soNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif"=
;color:#1F497D'>Thank you,</span><span style=3D'color:black'><o:p></o:p></s=
pan></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"C=
alibri","sans-serif";color:#1F497D'>Kathleen</span><span style=3D'color:bla=
ck'><o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.=
0pt;font-family:"Calibri","sans-serif";color:#1F497D'>&nbsp;</span><span st=
yle=3D'color:black'><o:p></o:p></span></p><div style=3D'border:none;border-=
top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b>=
<span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:bla=
ck'>From:</span></b><span style=3D'font-size:10.0pt;font-family:"Tahoma","s=
ans-serif";color:black'><a href=3D"mailto:sacm-bounces@ietf.org">sacm-bounc=
es@ietf.org</a> <a href=3D"mailto:[mailto:sacm-bounces@ietf.org]">[mailto:s=
acm-bounces@ietf.org]</a> <b>On Behalf Of </b>Karen Scarfone<br><b>Sent:</b=
> Thursday, June 28, 2012 12:22 PM<br><b>To:</b> <a href=3D"mailto:sacm@iet=
f.org">sacm@ietf.org</a><br><b>Subject:</b> Re: [sacm] IETF 84</span><span =
style=3D'color:black'><o:p></o:p></span></p></div><p class=3DMsoNormal><spa=
n style=3D'color:black'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal><s=
pan style=3D'color:black'>I've gotten out of the loop on this as well. I'm =
still available to edit any documents being produced by this effort.<o:p></=
o:p></span></p><div><p class=3DMsoNormal><span style=3D'color:black'>&nbsp;=
<o:p></o:p></span></p></div><div><p class=3DMsoNormal><span style=3D'color:=
black'>&nbsp;<o:p></o:p></span></p></div><div><p class=3DMsoNormal style=3D=
'margin-bottom:12.0pt'><span style=3D'color:black'>Karen<o:p></o:p></span><=
/p><div><p class=3DMsoNormal><span style=3D'color:black'>On Thu, Jun 28, 20=
12 at 12:03 PM, Adam Montville &lt;<a href=3D"mailto:amontville@tripwire.co=
m" target=3D"_blank">amontville@tripwire.com</a>&gt; wrote:<o:p></o:p></spa=
n></p><p class=3DMsoNormal><span style=3D'color:black'>All:<br><br>I've bee=
n out of this loop for a while, unfortunately. &nbsp;Hopefully, there<br>is=
 progress being made on the use cases and other efforts (I.e. content<br>re=
pository) that were proposed a couple of months ago.<br><br>Can anyone tell=
 me whether there is a scheduled meeting (side or<br>otherwise) for SACM du=
ring IETF 84? &nbsp;If so, do we have any idea when it<br>will be held?<br>=
<br>Regards,<br><br>Adam<br><br><br>_______________________________________=
________<br>sacm mailing list<br><a href=3D"mailto:sacm@ietf.org">sacm@ietf=
.org</a><br><a href=3D"https://www.ietf.org/mailman/listinfo/sacm" target=
=3D"_blank">https://www.ietf.org/mailman/listinfo/sacm</a><o:p></o:p></span=
></p></div><p class=3DMsoNormal><span style=3D'color:black'><br><br clear=
=3Dall><o:p></o:p></span></p><div><p class=3DMsoNormal><span style=3D'color=
:black'>&nbsp;<o:p></o:p></span></p></div><p class=3DMsoNormal style=3D'mar=
gin-bottom:12.0pt'><span style=3D'color:black'>-- <br>Karen Scarfone, Princ=
ipal Consultant, Scarfone Cybersecurity<br><a href=3D"mailto:karen@scarfone=
cybersecurity.com" target=3D"_blank">karen@scarfonecybersecurity.com</a>&nb=
sp;&nbsp; (703)401-1018<o:p></o:p></span></p></div></div></div></div></bloc=
kquote></div></body></html>=

--_000_F5063677821E3B4F81ACFB7905573F2403AA99D4MX15Acorpemccom_--

From amontville@tripwire.com  Fri Jun 29 09:26:51 2012
Return-Path: <amontville@tripwire.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 67FC721F877A for <sacm@ietfa.amsl.com>; Fri, 29 Jun 2012 09:26:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.349
X-Spam-Level: 
X-Spam-Status: No, score=-4.349 tagged_above=-999 required=5 tests=[AWL=-0.750, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 659divJWem1i for <sacm@ietfa.amsl.com>; Fri, 29 Jun 2012 09:26:50 -0700 (PDT)
Received: from va3outboundpool.messaging.microsoft.com (va3ehsobe001.messaging.microsoft.com [216.32.180.11]) by ietfa.amsl.com (Postfix) with ESMTP id 45FDA21F8781 for <sacm@ietf.org>; Fri, 29 Jun 2012 09:26:50 -0700 (PDT)
Received: from mail57-va3-R.bigfish.com (10.7.14.246) by VA3EHSOBE011.bigfish.com (10.7.40.61) with Microsoft SMTP Server id 14.1.225.23; Fri, 29 Jun 2012 16:25:00 +0000
Received: from mail57-va3 (localhost [127.0.0.1])	by mail57-va3-R.bigfish.com (Postfix) with ESMTP id 369CD2C0478; Fri, 29 Jun 2012 16:25:00 +0000 (UTC)
X-Forefront-Antispam-Report: CIP:174.47.84.216; KIP:(null); UIP:(null); IPV:NLI; H:PDXED01.tripwire.com; RD:174-47-84-216.static.twtelecom.net; EFVD:NLI
X-SpamScore: -34
X-BigFish: VPS-34(zz98dI9371I9f17R148cI62a3Izz1202hzz1033IL8275bh8275dhz2dh2a8h668h839h944he5bhf0ah)
Received: from mail57-va3 (localhost.localdomain [127.0.0.1]) by mail57-va3 (MessageSwitch) id 1340987097934551_12066; Fri, 29 Jun 2012 16:24:57 +0000 (UTC)
Received: from VA3EHSMHS011.bigfish.com (unknown [10.7.14.253])	by mail57-va3.bigfish.com (Postfix) with ESMTP id D5F7A460053; Fri, 29 Jun 2012 16:24:57 +0000 (UTC)
Received: from PDXED01.tripwire.com (174.47.84.216) by VA3EHSMHS011.bigfish.com (10.7.99.21) with Microsoft SMTP Server (TLS) id 14.1.225.23; Fri, 29 Jun 2012 16:24:57 +0000
Received: from PDXHB01.tripwire.com (172.30.0.53) by PDXED01.tripwire.com (192.168.192.5) with Microsoft SMTP Server (TLS) id 14.1.355.2; Fri, 29 Jun 2012 09:27:35 -0700
Received: from PDXMB02.tripwire.com ([fe80::f997:7b65:8e64:438e]) by PDXHB01.tripwire.com ([fe80::d495:98d2:7df4:2154%11]) with mapi id 14.01.0355.002; Fri, 29 Jun 2012 09:26:45 -0700
From: Adam Montville <amontville@tripwire.com>
To: "kathleen.moriarty@emc.com" <kathleen.moriarty@emc.com>, "Kent_Landfield@McAfee.com" <Kent_Landfield@McAfee.com>, "bakerj@mitre.org" <bakerj@mitre.org>, "karen@scarfonecybersecurity.com" <karen@scarfonecybersecurity.com>, "sacm@ietf.org" <sacm@ietf.org>
Thread-Topic: [sacm] IETF 84
Thread-Index: AQHNVUeKYUpL4z7vTUubxQ1VahOvyJcQXxeAgAAExgCAAAWmgIAAApSAgAGBRgD//5ACAA==
Date: Fri, 29 Jun 2012 16:26:44 +0000
Message-ID: <CC132506.D8E9%amontville@tripwire.com>
In-Reply-To: <F5063677821E3B4F81ACFB7905573F2403AA99D4@MX15A.corp.emc.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.2.2.120421
x-originating-ip: [172.16.97.55]
x-exclaimer-md-config: 79afcaa7-fdf4-4fa6-abe0-afeaa4640a4f
Content-Type: text/plain; charset="us-ascii"
Content-ID: <45E095E672FC5F4DBFB40F32A55B65A6@tripwire.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: tripwire.com
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Jun 2012 16:26:51 -0000

I'd suggest Thursday evening.  Alternatively, the mornings of Monday and Tu=
esday are light for the security area, but we might end up interfering with=
 ops if we go that route, and if I'm not mistaken we'd like to potentially =
have some ops people attend.

Adam

From: "kathleen.moriarty@emc.com<mailto:kathleen.moriarty@emc.com>" <kathle=
en.moriarty@emc.com<mailto:kathleen.moriarty@emc.com>>
Date: Friday, June 29, 2012 9:07 AM
To: kent_landfield <kent_landfield@mcafee.com<mailto:kent_landfield@mcafee.=
com>>, Jon Baker <bakerj@MITRE.ORG<mailto:bakerj@MITRE.ORG>>, "karen@scarfo=
necybersecurity.com<mailto:karen@scarfonecybersecurity.com>" <karen@scarfon=
ecybersecurity.com<mailto:karen@scarfonecybersecurity.com>>, "sacm@ietf.org=
<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@ietf.org>>
Subject: Re: [sacm] IETF 84

Hello,

The agenda was released for IETF 84 and is at the following link:
https://datatracker.ietf.org/meeting/84/agenda.txt

Do people have an opinion as to when they would like the meeting to take pl=
ace (cannot conflict with other IETF meeting times or plenary sessions)?  I=
f it helps, MILE is scheduled for Tuesday afternoon right now.  NEA is not =
scheduled to meet.

We will need to put in the request soon for planning purposes for both the =
IETF and attendees.

Thank you,
Kathleen

From: sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-boun=
ces@ietf.org] On Behalf Of Kent_Landfield@McAfee.com<mailto:Kent_Landfield@=
McAfee.com>
Sent: Thursday, June 28, 2012 1:09 PM
To: bakerj@mitre.org<mailto:bakerj@mitre.org>; Moriarty, Kathleen; karen@sc=
arfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>; sacm@ietf.=
org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

Absolutely not!  We can be having it right now.  I agree there is no need t=
o wait for meetings to have these discussions. Quite the contrary, we shoul=
d be having these discussions on the list. Since a large section of the com=
munity participants will be at Dev Days we can also use that as a way to ma=
ture the discussion and documented use cases.

And from my perspective, I see the use case I-D covering more that what wil=
l be a single proposed working group charter might cover.  It also discusse=
s items that are currently being worked in other working groups.  We initia=
lly thought the use case document could drive the charter discussion but th=
at seems to be artificially delaying the discussion from starting.

Kent Landfield

McAfee | An Intel Company
Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: <Baker>, Jon <bakerj@mitre.org<mailto:bakerj@mitre.org>>
To: Kathleen Moriarty <kathleen.moriarty@emc.com<mailto:kathleen.moriarty@e=
mc.com>>, "karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecuri=
ty.com>" <karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurit=
y.com>>, "sacm@ietf.org<mailto:sacm@ietf.org>" <sacm@ietf.org<mailto:sacm@i=
etf.org>>
Subject: Re: [sacm] IETF 84

Does this conversation need to wait until the ietf meeting?

Given that many of the participants will be at developer days in two weeks =
maybe some discussion could be held afterhours there?

This might allow for a more mature draft to be discussed at the IETF meetin=
g a few weeks later.

Jon

=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Jonathan O. Baker
G022 - IA Industry Collaboration
The MITRE Corporation
Email: bakerj@mitre.org<mailto:bakerj@mitre.org>

From:sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org> [mailto:sacm-bounc=
es@ietf.org] On Behalf Of kathleen.moriarty@emc.com<mailto:kathleen.moriart=
y@emc.com>
Sent: Thursday, June 28, 2012 12:39 PM
To: karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>=
; sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

Thanks for starting the thread, Adam and offering to help Karen!

A few of us have been working to update the use case document that David Wa=
ltermire circulated.  We may need help here as I am not sure if we have con=
tent for each of the use cases yet.  I provided content to update use case =
5.

The hope was to review the use cases in a side meeting and start looking at=
 a charter in support of the defined use cases.  From there, we can figure =
out what work is needed to support the use cases and charter.  This would b=
e used to set the milestones.

Should we set a meeting for the Sunday again?

Thank you,
Kathleen

From:sacm-bounces@ietf.org<mailto:sacm-bounces@ietf.org>[mailto:sacm-bounce=
s@ietf.org]<mailto:[mailto:sacm-bounces@ietf.org]>On Behalf Of Karen Scarfo=
ne
Sent: Thursday, June 28, 2012 12:22 PM
To: sacm@ietf.org<mailto:sacm@ietf.org>
Subject: Re: [sacm] IETF 84

I've gotten out of the loop on this as well. I'm still available to edit an=
y documents being produced by this effort.


Karen
On Thu, Jun 28, 2012 at 12:03 PM, Adam Montville <amontville@tripwire.com<m=
ailto:amontville@tripwire.com>> wrote:
All:

I've been out of this loop for a while, unfortunately.  Hopefully, there
is progress being made on the use cases and other efforts (I.e. content
repository) that were proposed a couple of months ago.

Can anyone tell me whether there is a scheduled meeting (side or
otherwise) for SACM during IETF 84?  If so, do we have any idea when it
will be held?

Regards,

Adam


_______________________________________________
sacm mailing list
sacm@ietf.org<mailto:sacm@ietf.org>
https://www.ietf.org/mailman/listinfo/sacm



--
Karen Scarfone, Principal Consultant, Scarfone Cybersecurity
karen@scarfonecybersecurity.com<mailto:karen@scarfonecybersecurity.com>   (=
703)401-1018


From athiasjerome@gmail.com  Sat Jun 30 04:46:38 2012
Return-Path: <athiasjerome@gmail.com>
X-Original-To: sacm@ietfa.amsl.com
Delivered-To: sacm@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D843D21F861A for <sacm@ietfa.amsl.com>; Sat, 30 Jun 2012 04:46:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level: 
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qfcrs8H0Oz-z for <sacm@ietfa.amsl.com>; Sat, 30 Jun 2012 04:46:38 -0700 (PDT)
Received: from mail-wi0-f170.google.com (mail-wi0-f170.google.com [209.85.212.170]) by ietfa.amsl.com (Postfix) with ESMTP id 0D2A621F847C for <sacm@ietf.org>; Sat, 30 Jun 2012 04:46:37 -0700 (PDT)
Received: by wibhq12 with SMTP id hq12so1564390wib.1 for <sacm@ietf.org>; Sat, 30 Jun 2012 04:46:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=otIwA/rxHJduY1E9gOVKJynPgrvN0/T2ajNj/eYNfVY=; b=U9SuWPvC/rTLpgsFVV2cV93Zv/rwK1Kw9oK5Z72c4wkgCxdpczknntltKwDoIieO/E neU9fEXIEBopGhkh2i6PZtu3z51ZuQmnTITb13Qj0oS8TUIdn/fqI3BDYqX1tJEPvR4w hban5AGHnVqgYKY8Jq5T9lSlxSq+Xup17eyn8TkaALDalH4+vivJU3w2R7h+4fjsn+MP Isf3WoxJUw0tXIgwo5pUPIHOcLOxsJgBz7jkLyt78XSJ9kzxXAGhDkSSoE7r2lj1dQpr TiLHBxtuWrz0jiXxf+ycJWi7WwYxCWDikk1bz4b8Bqgc5tbpyUGbm/ansUxoEPeYe16A I8Xg==
MIME-Version: 1.0
Received: by 10.180.84.169 with SMTP id a9mr4446499wiz.8.1341056797596; Sat, 30 Jun 2012 04:46:37 -0700 (PDT)
Received: by 10.194.54.7 with HTTP; Sat, 30 Jun 2012 04:46:37 -0700 (PDT)
In-Reply-To: <CC132506.D8E9%amontville@tripwire.com>
References: <F5063677821E3B4F81ACFB7905573F2403AA99D4@MX15A.corp.emc.com> <CC132506.D8E9%amontville@tripwire.com>
Date: Sat, 30 Jun 2012 13:46:37 +0200
Message-ID: <CAA=AuEdWqzbrLg1-Qk14UhD5eNfkXxYYdvn0e_iXpcFFmMxKew@mail.gmail.com>
From: Jerome Athias <athiasjerome@gmail.com>
To: Adam Montville <amontville@tripwire.com>
Content-Type: text/plain; charset=ISO-8859-1
Cc: "sacm@ietf.org" <sacm@ietf.org>, "kathleen.moriarty@emc.com" <kathleen.moriarty@emc.com>, "Kent_Landfield@McAfee.com" <Kent_Landfield@mcafee.com>, "bakerj@mitre.org" <bakerj@mitre.org>, "karen@scarfonecybersecurity.com" <karen@scarfonecybersecurity.com>
Subject: Re: [sacm] IETF 84
X-BeenThere: sacm@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <sacm.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sacm>, <mailto:sacm-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sacm>
List-Post: <mailto:sacm@ietf.org>
List-Help: <mailto:sacm-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sacm>, <mailto:sacm-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 30 Jun 2012 11:46:39 -0000

Hi,

sorry I was out of the list due to a move and new email box.
Maybe it is quite off topic, but I would like to know if some of you
were at the latest MITRE's BIG DATA meeting?
and if any of the presentations/papers are available?

Thanks

And I'm still interested to contribute to this list, help and review
new drafts...

Regards
Jerome
