|
All,
Here is a quick update from the STIX Package name mini-group. The mini group is proposing:
- Renaming STIX-Package to STIX-Bundle
- STIX-bundle is simply a transport container
- STIX-Bundle is a grouping of STIX content that isn’t required to be related (it MIGHT be related, but being in the same bundle doesn’t mean it’s related)
- Removing all TLO Common Properties (with an open question about Data Markings)
- Removed properties: id, created_by_ref, created_time, revision, modified_time, revoked, revision_comment, confidence, object_markings_refs, granular_markings
- STIX-Bundle will keep the `spec_version` property
- All content in the bundle MUST be the same STIX version (identified by spec_version)
There is an open question about whether Data Markings should be in the STIX-Bundle. Arguments for keeping it are:
- The group seemed to have consensus that Bundle-level markings were desired, but evidence was difficult for the mini-group to find.
- Certain sharing communities would appreciate the simplicity of package marking.
- It makes objects look smaller and is more natural for people who are new to the specs
Arguments for removing it are:
- Data Marking at the bundle level is “two ways of doing things” - on-the-object markings and on-the-bundle markings
-
TLO signatures will not be valid when the Bundle-level markings are used
Thank you.
-Mark
|