oasis-tcs / cti-stix2

OASIS CTI TC: Provides issue tracking and wiki pages for the STIX 2.x Work Products
https://github.com/oasis-tcs/cti-stix2
Other
24 stars 9 forks source link

Predefined/Subtype extensions should be possible when defining a new STIX object extension definition, even with new SDOs #321

Closed rpiazza closed 6 months ago

rpiazza commented 8 months ago

The spec doesn't explicitly prevent introducing Predefined/Subtype extensions when defining a new STIX object, but it should be more fleshed out in the spec.

Also, there is some text (see 11.3) that "STIX supports user-defined custom extensions for STIX Cyber-observable Objects (SCO)" and "Note, custom extensions can only be used with SCOs.". New SDOs types should be able to define Predefined/Subtype extensions also. Because that text is not normative, it is not prohibited to do that in STIX 2.1 (this was done with the Incident core's new SDO impact). It also is describing "custom extensions", which are not what Predefined/Subtype extensions are in this context.