RE: [cti] RE: Versioning Background Docs

From
Taylor, Marlon <>
Date
2016-03-14T15:07:40+00:00
ID
DBCF3FEEF965344D8999A6E37D87AE58A9F1B49D@D2ASEPREA021
Thread
RE: [cti] RE: Versioning Background Docs
Correct. Hashing won't provide that capability.

Relationships will provide what you're looking for.

-Marlon

 

From: Jason Keirstead

Sent: Monday, March 14, 2016 10:56:04 AM

To: Taylor, Marlon

Cc: Mates, Jeffrey CIV DC3/DCCI; ; 

Subject: RE: [cti] RE: Versioning Background Docs

Apologize for my confusion but I don't really understand what is being discussed in this thread.

Are people talking about IDs or Versions? What does hashing have to do with versioning?

I (hope?) people are not advocating to simply hash the contents of the object and use that as a version? That is not workable. A version has to be continually incrementing. I need to be able to look at a version and know if it is the latest version or if it
 is stale. You can't do that with hashes.

-

Jason Keirstead

STSM, Product Architect, Security Intelligence, IBM Security Systems

www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown 

"Taylor,
 Marlon" ---03/14/2016 11:42:28 AM---Hi All, Jeff and I spoke offline and we are in agreement with the hash based approach. Some takeaway

From: "Taylor, Marlon" <>

To: "Mates, Jeffrey CIV DC3/DCCI" <>, "" <>

Cc: "" <>

Date: 03/14/2016 11:42 AM

Subject: RE: [cti] RE: Versioning Background Docs

Sent by: <>

Hi All,

Jeff and I spoke offline and we are in agreement with the hash based approach. Some takeaways:

- cleared up "shallowness" of shallow objects

- conveyed the idea of relationships which contain arrays of ids (he calls them link aggregators)

As we finalize objects across the TC we can go into object-specific required fields. Ex: should every Indicator have an observable?

Keep up the feedback. 

-Marlon