Open sbarnum opened 10 years ago
Consider "Threat Agent" on top of Threat Actor: that could allow STIX extension, for future use in incident management (and disaster recovery), for example: natural incident
Actor could be abstracted as Asset https://github.com/STIXProject/schemas/issues/234
Consider creating a new Actor top-level construct to act as a basis for extension for Threat Actor but also enabling characterization of defender and third party actors.
This would allow for consistent specification of actor-type information regardless of whether the actor is a threat actor, defender, or third-party.