← Prev in month ← Prev in thread

TAXII definition of "Done"

From
Kelley, Sarah E. <>
Date
2018-11-27T20:56:20+00:00
ID
Thread
TAXII definition of "Done"
All,

 

As I mentioned on the working call today, we have imposed a very strict definition of “Done” for new features/objects in STIX, however, we have never agreed as a TC to impose the same rigorous standards to TAXII. Given the fact that some
 of the issues that prompted us to implement this definition came about when people attempted to implement TAXII, it seems only logical to me that we would impose the same standards to both specifications.

 

As a reminder, the definition of “Done” for STIX includes:

Written specification text

Proof of concept code from at least two different developers/companies

Corresponding Interop tests

 

For some of the newer features in TAXII, namely TAXII query, it seems to make sense to me that it should be proved in code before we finalize it in the specification.

 

I wanted to bring this topic to the list and see what other people thought about this.

 

Thanks,

 

Sarah Kelley

Lead Cybersecurity Engineer, T8B2

Defensive Operations

The MITRE Corporation

703-983-6242

← Prev in month ← Prev in thread