oasis-tcs / cti-stix2

OASIS CTI TC: Provides issue tracking and wiki pages for the STIX 2.x Work Products
https://github.com/oasis-tcs/cti-stix2
Other
24 stars 9 forks source link

ITU Feedback #322

Closed ejratl closed 7 months ago

ejratl commented 8 months ago

Review and accept/reject alterations that were requested by the ITU as described in the draft document.

ejratl commented 8 months ago

There is a request to remove the following: This section including vocabulary items and their descriptions is based on the Threat Agent Library publication from Intel Corp in September 2007 <>. This gives credit for the prior art in the field - if we remove the credit, do we need to also remove some of the vocabulary items?

ejratl commented 8 months ago

There is a request to remove the following: If objects are found where this property is not present, the implicit value for all STIX Objects other than SCOs is [stixliteral]#2.0#. This damages the understandability of parsing an object, so it should go into the Best Practices document as a note.

ejratl commented 8 months ago

Rather than removing the informative statement that actor types are not mutually exclusive, I would like to adapt it to change the types: -Actor types are not mutually exclusive: a threat actor can be both a disgruntled insider and a spy. <> +Actor types are not mutually exclusive: a threat actor can be both a disgruntled insider and a sensationalist.

ejratl commented 8 months ago

The PR includes the feedback referenced at the beginning of the document. A full scan of the document is still needed to look for other changes - for example, IANA Considerations was renamed to Considerations - do we want to make this change as well?