Markdown version of the XCCDF Specification

22 views
Skip to first unread message

David Waltermire

unread,
Sep 17, 2019, 9:54:14 AM9/17/19
to scap-dev-authoring
Creating a searchable version of the XCCDF specification was discussed at the SCAP workshop.  Please find a Word version of this specification attached to support this effort.

It would be good to make a decision about where to host this version of the specification. One idea would be to stand up a Github repository for the specification. This would also support ongoing maintenance of the specification.

Any other ideas?

Regards,
Dave
NISTIR-7275r4-updated-20120315.doc

Gabriel Alford

unread,
Sep 17, 2019, 10:30:36 AM9/17/19
to David Waltermire, scap-dev-authoring
Would https://github.com/scapcommunity/XCCDF make sense or should it be in another repository?

Gabriel Alford

Member of the technical staff

office of the chief technologist

red hat Public Sector

Red Hat

ral...@redhat.com    T: 972-707-6483    M: 303-550-7234    



--
To unsubscribe from this group, send email to scap-dev-author...@list.nist.gov
Visit this group at https://list.nist.gov/scap-dev-authoring
---
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev-author...@list.nist.gov.

Waltermire, David A. (Fed)

unread,
Sep 17, 2019, 10:33:42 AM9/17/19
to Gabriel Alford, scap-dev-authoring

I think that would be fine. Would it be possible to create this repo under the Creative Commons Zero dedication, since this specification is already in the public domain?

 

https://creativecommons.org/share-your-work/public-domain/cc0/

 

Regards,

Dave

 

From: Gabriel Alford <ral...@redhat.com>
Sent: Tuesday, September 17, 2019 10:30 AM
To: Waltermire, David A. (Fed) <david.wa...@nist.gov>
Cc: scap-dev-authoring <scap-dev-...@list.nist.gov>
Subject: Re: [scap-dev-authoring] Markdown version of the XCCDF Specification

 

Would https://github.com/scapcommunity/XCCDF make sense or should it be in another repository?

 

Gabriel Alford

Member of the technical staff

office of the chief technologist

red hat Public Sector

Red Hat

ral...@redhat.com    T: 972-707-6483    M: 303-550-7234    

Image removed by sender.

 

David Ries

unread,
Sep 17, 2019, 10:39:31 AM9/17/19
to David Waltermire, scap-dev-authoring, Gabriel Alford
If you’re interested, I think that the OVAL Community would be willing (interested?) in hosting a GitHub repo and HTML site for this at https://github.com/OVAL-Community/XCCDF. We could host it for reference only and/or apply the OVAL governance model to it, enabling community-driven revision a la https://github.com/OVAL-Community/OVAL.

-David

David E. Ries
Co-Founder, Business Development
ri...@jovalcm.com

Joval Continuous Monitoring

Facebook Linkedin


Waltermire, David A. (Fed)

unread,
Sep 17, 2019, 10:53:13 AM9/17/19
to David Ries, scap-dev-authoring, Gabriel Alford

I am willing to go with the community consensus around where we host the XCCDF specification repo. I do want to make sure the following is true of the repo:

 

1) The content is available and maintained under the Creative Commons Zero Dedication. The specification is already in the public domain and should remain that way.

2) We need a formal governance process for addressing changes to the specification through pull requests that involves some mechanism for review and consensus over changes. Github reviews can be used to accomplish this. We could establish some standard of practice for reviews to ensure that changes are vetted by multiple stakeholders.

3) We need some assurance that when a PR is submitted that the submitter discloses any Intellectual Property Rights (IPR) that they maintain related to the contribution. This can be handled using a PR template that sets out some requirements for PRs that the submitter agrees to.

 

We should discuss how to address these items as part of where the specification get hosted. Perhaps this can be discussed on a future call?

 

Regards,

Dave

 

 

 

From: David Ries <ri...@jovalcm.com>
Sent: Tuesday, September 17, 2019 10:39 AM
To: Waltermire, David A. (Fed) <david.wa...@nist.gov>
Cc: scap-dev-authoring <scap-dev-...@list.nist.gov>; Gabriel Alford <ral...@redhat.com>
Subject: Re: [scap-dev-authoring] Markdown version of the XCCDF Specification

 

If you’re interested, I think that the OVAL Community would be willing (interested?) in hosting a GitHub repo and HTML site for this at https://github.com/OVAL-Community/XCCDF. We could host it for reference only and/or apply the OVAL governance model to it, enabling community-driven revision a la https://github.com/OVAL-Community/OVAL.

 

-David



On Sep 17, 2019, at 10:30 AM, Gabriel Alford <ral...@redhat.com> wrote:

 

Would https://github.com/scapcommunity/XCCDF make sense or should it be in another repository?

 

Gabriel Alford

Member of the technical staff

office of the chief technologist

red hat Public Sector

ral...@redhat.com    T: 972-707-6483    M: 303-550-7234    

Image removed by sender.

 

 

On Tue, Sep 17, 2019 at 7:54 AM 'David Waltermire' via scap-dev-authoring <scap-dev-...@list.nist.gov> wrote:

Creating a searchable version of the XCCDF specification was discussed at the SCAP workshop.  Please find a Word version of this specification attached to support this effort.

 

It would be good to make a decision about where to host this version of the specification. One idea would be to stand up a Github repository for the specification. This would also support ongoing maintenance of the specification.

 

Any other ideas?

 

Regards,

Dave

 

--
To unsubscribe from this group, send email to scap-dev-author...@list.nist.gov
Visit this group at https://list.nist.gov/scap-dev-authoring
---
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev-author...@list.nist.gov.

 

--
To unsubscribe from this group, send email to scap-dev-author...@list.nist.gov
Visit this group at https://list.nist.gov/scap-dev-authoring
---
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev-author...@list.nist.gov.

David E. Ries
Co-Founder, Business Development
ri...@jovalcm.com

Image removed by sender. Joval Continuous Monitoring

Image removed by sender. FacebookImage removed by sender. Linkedin

 

Gabriel Alford

unread,
Sep 17, 2019, 11:08:06 AM9/17/19
to Waltermire, David A. (Fed), David Ries, scap-dev-authoring
> Would it be possible to create this repo under the Creative Commons Zero dedication, since this specification is already in the public domain?

Done

> If you’re interested, I think that the OVAL Community would be willing (interested?) in hosting a GitHub repo and HTML site for this at https://github.com/OVAL-Community/XCCDF. > We could host it for reference only and/or apply the OVAL governance model to it, enabling community-driven revision a la https://github.com/OVAL-Community/OVAL.

Personally find that confusing having XCCDF hosted under OVAL and could see that being confusing to others.

Gabriel Alford

Member of the technical staff

office of the chief technologist

red hat Public Sector

Red Hat

ral...@redhat.com    T: 972-707-6483    M: 303-550-7234    


Reply all
Reply to author
Forward
0 new messages