Groups keyboard shortcuts have been updated
Dismiss
See shortcuts

Initial Process

32 views
Skip to first unread message

David Ries

unread,
May 13, 2019, 2:22:29 PM5/13/19
to scap-dev...@list.nist.gov
Hello Working Group,

I hope you’re all well and happily returned to your respective HQs! 

Based on initial discussions at SCAP 2.0 Dev Days, I think we share the hope that this could be a relatively narrowly-scoped, rapidly-achievable project. With that in mind, I propose the following lightweight process:

  1. Document Examples
    1. Example Repositories: list a few actual repositories that we intend our proposal to address
    2. Example Content: list a few actual content feeds/packages that we intend our proposal to address
    3. Example Stories: list a few stories we intend our proposal to support
  2. Draft Metadata Requirements
    1. Content Types: identify unique content types that our proposal must support (e.g. content packages, document formats, etc.)
    2. Metadata by Content Type: for each content type, list and describe useful metadata fields
    3. Repository/Grouping Metadata: list and describe any useful repository-global or other non-content-type metadata fields
  3. Create Sample Manifests
    1. Create abbreviated, sample manifests in a variety of formats subject to interest (e.g. XML, ROLIE, JSON)
    2. Discuss and select a format (or formats)
  4. Next Steps
    1. Discuss whether we’ve more-or-less completed our work (subject to outside feedback, documentation, etc.) or… have we come to the realization that this is going to take significantly more time, work, etc.?
    2. Solicit feedback from community, repository owners, etc. (tbd)
    3. Plan next steps

Yeas, nays, feedback on the above? Feel free to revise and reply! 

If you are a working group member (or want to be), please let me know that you’ve received this.

Best, 
David

David E. Ries
Co-Founder, Business Development
ri...@jovalcm.com

Joval Continuous Monitoring

Facebook Linkedin


Stephen Banghart

unread,
May 15, 2019, 12:04:08 PM5/15/19
to scap-dev-content
David,

This looks great, thanks for putting it together. Definitely a "yea" from me.

Where would we compile the results of these steps? Is this something you imagine happening on List or on the Repo?

I can start getting some answers together for step 1 from the government perspective.

Cheers,
Stephen

David Ries

unread,
May 16, 2019, 1:35:11 PM5/16/19
to Stephen Banghart, scap-dev-content
Hi Stephen et al,

And… the ‘yeas’ have it: 2 to (silence). I’m kidding, but I think we should err on the side of pressing forward when we don’t have a lot of response—we are all busy and I trust that if/when there is a concern, it will be raised on the list. 

I’ll create a separate thread for step 1. 

-David

--
To unsubscribe from this group, send email to scap-dev-conte...@list.nist.gov
Visit this group at https://list.nist.gov/scap-dev-content
---
You received this message because you are subscribed to the Google Groups "scap-dev-content" group.
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev-conte...@list.nist.gov.
Reply all
Reply to author
Forward
0 new messages