possible work item

From
Mark Davidson <>
Date
2015-10-26T13:25:00+00:00
ID
Thread
possible work item
(This is really just a somewhat different framing, but I’ll put it in my own words)



I’d like to propose that the interoperability SC maintain awareness of related efforts and promote collaboration between the CTI TC and related efforts wherever
  possible. Specifically, I feel that treating e.g., OpenTPX and ThreatExchange as friendly will be mutually beneficial.



I realize this probably pushes the boundary of the term interoperability; if it doesn’t fit in the interop SC, maybe it’s just something we take on at the TC
  level.



Thank you.

-Mark
From:
 [mailto:]
  On Behalf Of  Jerome Athias
  Sent:  Friday, October 23, 2015 2:16 PM
To:  Jordan, Bret <>
Cc:  
Subject:  Re: [cti-interoperability] possible work item


  Yeah. At the same time they could be easily challenged, because frankly speaking (Sean could kick my ass), I don't need a new-cool-fancy format to get dshield and malware domains lists integrated in my SIEM. CSV
  is fine

 On Friday, 23 October 2015, Jordan, Bret < 
> wrote:

  One thing I would like to see this group work on is:



  * Outreach...  Meaning I would like to have us do outreach to the new OpenTPX group and the Facebook ThreatExchange group and see what kind of give-n-take would be needed for us to combine efforts.



  From looking at it, I am guessing that each group would need to give a little. But I think a unified solution would be greater than the sum of the parts.  Yes, it will challenge some of the things we have done in
  STIX, but some of the things in OpenTPX and FB ThreatExchange are neat.  And we should really look in to doing them.





Thanks,



Bret







Bret Jordan CISSP

Director of Security Architecture and Standards
Office of the CTO

Blue Coat Systems

PGP Fingerprint: 63B4 FC53 680A 6B7D 1447  F2C0 74F8 ACAE 7415 0050

"Without cryptography vihv vivc ce xhrnrw, however, the only thing that can not be unscrambled is an egg."