← Prev in month ← Prev in thread
Next in thread → Next in month →

FYI on OpenC2 in ITU

From
Duncan Sparrell
Date
2020-03-26T18:58:00+00:00
ID
Thread
FYI on OpenC2 in ITU
The ITU will be sending a liaison to the OpenC2 TC that are anxiously awaiting OpenC2 (my words
theirs are more sedate). But there will be some hurdles. I ve started a wiki page on our ops github ( https://github.com/oasis-tcs/openc2-tc-ops/wiki/ItuProcessForOpenC2Adoption )
  to attempt to explain their procedures in a way that will help us help them in adopting OpenC2. I need to fill it out more. The purpose of this email (besides telling about their desire to adopt our work and informing about the wiki page so you ll keep after
  me to finish it) is to pass on some information from their report concerning our work. An attempted translation will follow:


  It was agreed that:



-         These LS are not a request to start NWI in SG17 and SG17 is not being requested to produce more work than OASIS on the topic



-         The  wrapping  of NWI from OASIS can only occur when OpenC2 is a full standard



-         Then either the  wrapping  will happen by reference or by full interpretation in SG17 in each language



-         That when this work will be finished in OASIS there should be only 1 Recommendation produced, not 3.



-         The incubation mechanism should not be changed and all the ITU-T rules and working methods at current stage should apply, e.g. A.5 (unnecessary in the case of OASIS) and A.25



-         On the comparison with other OASIS standards, that STIX was adopted but on an old (incompatible version). STIX is in final ballot and should be approved during this SG17 meeting (note
  from Chairman, and indeed it passed its ballot)



LS is Liaison Statement.
what we sent them. A  New Work Item  (NWI) is how they track their work and they are a political hot potato. Some administrations (ITU-speak for governments, recall ITU is an UN
  agency), especially the ones that foot most of the bill (usually led by US) desire that the ITU should not duplicate the work of other SDO s (Standards Development Organizations)
good news for us. There has been some debate whether a NWI should be opened
  if ITU knows it wants to adopt the work of another SDO (which is what they did with STIX
and upset some since its been languishing for a few years with nothing going on in ITU but waiting for OASIS). At this meeting Canada proposed that OpenC2 should NOT
  be a NWI since ITU isn t going to do anything yet. They agreed a NWI should be opened once OASIS has Standards (not Committee Specs) and ITU is ready to approve it.



The third bullet is about whether ITU passes a one sentence standard that says  do what OASIS xxxx says  or they republish our text in their format. The first is called  by reference  and the second is called

by incorporation . Those who pay the translation bills (Canada was lead on this issue) usually want reference since reduces budget of ITU. OASIS does not have a policy and leaves it up to TC to request which it wants. Most in the past (and I think personally
  is better) go for  by incorporation  since it is usually translated (see wiki page for more)

The fourth bullet is significant. They don t want us using up most of the numbers in the X series. I do think we could get away with 3 but I do know they would balk at tens to hundreds. They liked how STIX
  went from six to one and assume we could do similar. We can debate this later on.



The fifth bullet is about their process. I won t bother explaining incubation since they agreed we could be normal. I ll explain  A.5  on wiki page. Basically it means follow the process ITU and OASIS worked
  out or CAP, XACML, SAML, etc.

The last bullet is about STIX
but reading between the lines
it basically says go standard once you know what you are doing and then keep putting out standards. They don t want to be in state STIX is right
  now which is the CS is the real answer and the standard is the old version
because they can only adopt the OASIS standard not the CS. So they are hopeful STIX 2.1 will go standard soon.



Duncan Sparrell

sFractal Consulting LLC

iPhone, iTypo, iApologize

I welcome VSRE emails. Learn more at   http://vsre.info  /
← Prev in month ← Prev in thread
Next in thread → Next in month →