Re: [cti] Internationalization in STIX 2.1

From
Sarah Kelley <>
Date
2017-06-23T18:13:02+00:00
ID
Thread
Re: [cti] Internationalization in STIX 2.1
I second the motion. 

 

Sarah Kelley

Senior Cyber Threat Analyst

Multi-State Information Sharing and Analysis Center (MS-ISAC)                   

31 Tech Valley Drive

East Greenbush, NY 12061

 



518-266-3493

24x7 Security Operations Center

 - 1-866-787-4722

 

      
           

 

From: <> on behalf of "Wunder, John A." <>

Date: Friday, June 23, 2017 at 1:38 PM

To: "" <>

Subject: [cti] Internationalization in STIX 2.1

 

Hey all,

 

One of the topics we’ve been grappling with for awhile in STIX 2.1 is internationalization. We want STIX content, specifically, to be translatable into different languages so that you can have publishers creating
 content in several languages, third party translation services for STIX content, and identification of which language specific content is in.

 

We’ve made a lot of progress towards that end. Here’s what we have:

 

Each top-level object will have a field called `lang` to indicate what language that content is in. That means that a campaign object could be published with
 a `lang` field of Japanese to indicate that the name, description, and other human text fields are in Japanese. (https://docs.google.com/document/d/1HRVFn2kAxBOTMbEb3KRu8tjMoHm-KRAI-2R8CTzGil4/edit#heading=h.xzbicbtscatx
 scroll down to `lang`)

A “granular language markings” capability, so that you can indicate that certain fields in the object are in English, while others are in Japanese. (https://docs.google.com/document/d/1HRVFn2kAxBOTMbEb3KRu8tjMoHm-KRAI-2R8CTzGil4/edit#heading=h.l6edgya0tyjq
 see new `lang` property on granular markings)

A separate “language-content” object that allows you to provide additional languages (translations) for that content. So you could publish a campaign in Japanese
 and then provide a language-content object with that same text in English. (https://docs.google.com/document/d/1HRVFn2kAxBOTMbEb3KRu8tjMoHm-KRAI-2R8CTzGil4/edit#heading=h.cfz5hcantmvx)

 

One thing we have no decided yet is whether each top-level object in STIX
MUST have the `lang` field populated on every object or SHOULD have the `lang` field populated on every object (not including bundle, observed-data, and sighting, which don’t have translatable fields). There have been previous discussions on Slack,
 e-mail, and at the face-to-face…you should be able to dig through the mailing lists to find it, the most recent one can be found in the Feb-Mar 2017 archives:

 

https://lists.oasis-open.org/archives/cti/201702/threads.html#00031

https://lists.oasis-open.org/archives/cti/201703/threads.html#00000

 

It seems like at this point we just need to have a ballot to resolve this. So, I move that the TC open a ballot to determine whether we feel the `lang` property should be required on each top-level object
 or optional on each top-level object (i.e. STIX Domain Objects, STIX Relationship Objects, data-marking objects).

 

John 

 

..... 

This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender
 immediately and permanently delete the message and any attachments.

. . . . .