RE: [cti-stix] Asset: the missing piece in your puzzle

From
Struse, Richard <>
Date
2015-11-27T14:14:43+00:00
ID
DE637B85E99BDF4DBA1D1C1DF89189398E6867DF@D2ASEPREA007
Thread
RE: [cti-stix] Asset: the missing piece in your puzzle
I agree completely.  Just because something (like asset information) is important and could be helpful in understanding the potential impact of a threat doesn’t mean that STIX or any component of CTI needs to define that information model.   We need to keep a laser-like focus on Cyber Threat and build bridges to other communities that are looking at asset, configuration or vulnerability information.

 

From:  [mailto:] On Behalf Of Aharon Chernin
Sent: Friday, November 27, 2015 8:31 AM
To: Patrick Maroney; Jason Keirstead; Jerome Athias
Cc: 
Subject: Re: [cti-stix] Asset: the missing piece in your puzzle

 

I am 100% behind giving us the ability to communicate asset information. Just not sure it should be in STIX, or OASIS CTI for that matter. If we can do this at a higher level than CTI, then we can use the same asset standard for vulnerability, compliance, and threats. We could even use it outside of the information security space. 

 

I say we continue using exploit target until we can figure out how to get STIX out of the asset business. 

 

Aharon

 

From: <> on behalf of Patrick Maroney <>
Date: Friday, November 27, 2015 at 7:18 AM
To: Jason Keirstead <>, Jerome Athias <>
Cc: "" <>
Subject: Re: [cti-stix] Asset: the missing piece in your puzzle

 

ExploitTarget only represents where the "pointy end" of the stick is pointed (attack surface/vulnerability), not the organization or assets behind same.  Some of us share the view that there needs to be a top level object that represents the Victim(s) and their Assets.

Patrick Maroney
President
Integrated Networking Technologies, Inc.
Desk: (856)983-0001
Cell: (609)841-5104
Email: 

 

_____________________________
From: Jason Keirstead <>
Sent: Friday, November 27, 2015 8:08 AM
Subject: Re: [cti-stix] Asset: the missing piece in your puzzle
To: Jerome Athias <>
Cc: <>

Wouldn't an asset just be linked using the already existing facility of @idref on ExploitTarget? 

Not sure something new needs to be created...

-
Jason Keirstead
Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown 

Jerome Athias ---11/27/2015 01:49:35 AM---From https://www.sans.org/critical-security-controls to ISO 27001, through the NIST CSF (#1 Identify

From: Jerome Athias <>
To: 
Date: 11/27/2015 01:49 AM
Subject: [cti-stix] Asset: the missing piece in your puzzle
Sent by: <>

From https://www.sans.org/critical-security-controls
to ISO 27001, through the NIST CSF (#1 Identify), NIST Risk Management 
Framework, SP 800-53... ... 
If you don't properly manage your Assets in cybersecurity: you will FAIL. 

Information obtained from the data that you will manipulate and 
exchange need to be linked to your Assets, the Assets of others 
(Supply Chain or Adversaries). 

So -again-, I invite you to look at http://scap.nist.gov/specifications/ai/ 

NB: While not perfect, and I can comment further with pleasure on 
where/why, the Asset concept/construct or relationships (i.e. through 
GUIDs) is, imho, NEEDED. 

PS: I will try to put effort on documenting where the current model(s) 
are currently weak regarding this domain 

Best regards 

--------------------------------------------------------------------- 
To unsubscribe from this mail list, you must leave the OASIS TC that 
generates this mail.  Follow this link to all your TCs in OASIS at: 
https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php  

Attachment:
smime.p7s

Description: S/MIME cryptographic signature