d3fend / d3fend-ontology

This repository holds the necessary content to produce the D3FEND ontology distribution.
https://d3fend.mitre.org
MIT License
59 stars 27 forks source link

Improve User defintion to bias less toward human users and include more agent/entity terminology #139

Open netfl0 opened 1 year ago

netfl0 commented 1 year ago

Discussed in https://github.com/d3fend/d3fend-ontology/discussions/136

Originally posted by **dsdr0** March 13, 2023 **User - Object Properties** & **User Account - Object Properties** States user is a person [or agent] but believe it should explicitly include Non-Person Entities (NPEs), also known as non-users in some circles. There is an important distinction between the two sets of users within many policies/requirements. ** User Account - Object Properties ** To include NPEs and lack of "login", suggest changing "login" language to authenticate. I would either remove login example or expand examples to include a web application example (or something else).
ag0x00 commented 1 year ago

Related: :UserAction versus non-user-initiated tasks and commands. MS uses "Machine Action".