Attending: Charles Schmidt, Joe Sain, Masato Terada, Joe Wolfkiel, Stephen Banghart, Jessica Fitzgerald-McKay, David Solin, Bill Munyan, Adam Montville
o The SCAP data collection architecture is and will remain compatible with the ideas of using Logical Instructions.
o Support for Logical Instructions would involve addition of new SCAP components in the architecture.
o Logical Instructions would not replace Technical Instructions, such as OVAL. They are simply a different way an Application might express an assessment request.
o The current components of the SCAP data collection architecture (Manager, Collector, Repository, PCE, and PCX) can remain focused on Technical Instructions.
o As such, development of the SCAP data collection architecture can continue to progress independently of any efforts to create a Logical Instruction framework. The latter might be spun up in the SCAP group or elsewhere but does not need to add any delays to the SCAP data collection architecture work.
==== ACTION ITEMS =====
Everyone – Review the Monitoring Overlay materials and provide feedback.
Adam – Write up thoughts on what a Logical Instruction framework effort might look like.
Charles – Finish revised write-up of the SCAP data collection architecture.
--
To unsubscribe from this group, send email to scap-dev-endpo...@list.nist.gov
Visit this group at https://list.nist.gov/scap-dev-endpoint
---
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev-endpo...@list.nist.gov.
Hi Charles,Sorry for my delayed response. Yes, I believe this approach has promise. The way I see it, whether we use OVAL, PowerShell, CLI, NETCONF/RESTCONF, Ansible, Chef, whatever, we’re going to end up “talking about” the same things, just in different languages. If we are expected to understand any sort of same-as relationship, we need a model to bridge the worlds.So, I (as a policy/compliance guy, or even as a threat hunter or incident responder) could say something like “get me the value of Windows registry X on all Windows 10 machines” and not care about the details. Some data may be ultimately collected by OVAL, some data from a vendor tool using a proprietary language.
Adam
To unsubscribe from this group, send email to scap-dev...@list.nist.gov
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev...@list.nist.gov.
To unsubscribe from this group, send email to scap-dev-endpo...@list.nist.gov
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev-endpo...@list.nist.gov.
Hi Charles,
To unsubscribe from this group, send email to scap-dev-endpoint+unsub...@list.nist.gov
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev-endpoint+unsub...@list.nist.gov.
To unsubscribe from this group, send email to scap-dev-endpo...@list.nist.gov
To unsubscribe from this group and stop receiving emails from it, send an email to scap-dev-endpo...@list.nist.gov.