There were two significant problems with that
NISTIR.
1) it was highly NIST centric dealing within what
amounts to Washington agency politics, and is simply
one agency's publication. It was eclipsed if not
replaced by the new Act which is U.S. organic law,
and
2) it omitted vast swaths of the cyber security
universe.
For a far more extensive, balanced, and useful
guide to the cyber security standards universe, see
Global Cyber Security Ecosystem.
--tony
On 2016-01-08 11:53 PM, Jerome Athias
wrote:
In case some are interested by (US) strategy regarding
standardization
Ref NIST IR8074
http://www.fiercegovernmentit.com/story/white-house-aims-engage-private-sector-international-organizations-global-c/2016-01-04
Regards
On Tuesday, 5 January 2016, Tony Rutkowski <>
wrote:
Rich et al.,
For those who want to consider the rather
significant larger context in which this work is
being done and focus on the associated
data models, architectures, and interfaces:
1. The canonical reference for those uploaded slides, for
outside, non-TC access, at the moment is: https://lists.oasis-open.org/archives/cti/201601/msg00000/_cybersecurity_act_reference-model_1.1.pptx
2. For those who do not use a compatible
powerpoint application, a PDF version
is
attached.
3. For clarity's sake, members of the TC are
welcome to re-post my slide deck, if you wish,
but it's provided to the TC for information,
not as a technical contribution. It represents
a considerable amount of work not otherwise
available and is intended to be helpful to those
implementing the Act in the very short time
frames required.
4. Other OASIS technical specifications may
be useful beyond those in TC CTI.
cheers,
--tony
--
________________________________
Anthony
Michael Rutkowski
EVP, Industry
Standards & Regulatory Affairs
+1 703 999 8270
________________________________
Yaana
Technologies LLC
542 Gibraltar
Drive
Milpitas CA
95035 USA
Attachment:
tr_103306v010101p.pdf
Description: Adobe PDF document