[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: education suggestion



I like this. No substantive comments from me. I'd say "instance" instead of "occurrence" though.



Tom Millar, US-CERT

Sent from +1-202-631-1915
https://www.us-cert.gov
 

From: owner-cve-editorial-board-list@lists.mitre.org on behalf of Coffin, Chris
Sent: Thursday, February 16, 2017 3:59:52 PM
To: Kurt Seifried; cve-editorial-board-list
Subject: RE: education suggestion

Here is the one page document we put together on future vision and direction of the program. We’d like to use this in the next response on the Oss-security mailing list discussion. If anyone has any significant comments or suggestions, please try to provide them by COB tomorrow.

 

Chris Coffin

The CVE Team

 

From: owner-cve-editorial-board-list@lists.mitre.org [mailto:owner-cve-editorial-board-list@lists.mitre.org] On Behalf Of Coffin, Chris
Sent: Thursday, February 09, 2017 6:03 PM
To: Kurt Seifried <kseifried@redhat.com>; cve-editorial-board-list <cve-editorial-board-list@lists.mitre.org>
Subject: RE: education suggestion

 

Ø  So it would appear many people are losing their mind on oss-security, which is not surprising as we haven't really educated people about what's up. 

 

Just a heads up to the Board on this, we will be putting together a response to all of the comments received so far on the oss-security mailing list. I expect to get something sent out midday tomorrow.

 

Ø  I would suggest we come up with a quick one page education document that covers the new way forwards and why it's better/more sustainable

 

This is a great idea Kurt! We will draft something and get it sent out as soon as possible.

 

Chris Coffin

The CVE Team

 

From: owner-cve-editorial-board-list@lists.mitre.org [mailto:owner-cve-editorial-board-list@lists.mitre.org] On Behalf Of Kurt Seifried
Sent: Thursday, February 09, 2017 10:36 AM
To: cve-editorial-board-list <cve-editorial-board-list@lists.mitre.org>
Subject: education suggestion

 

So it would appear many people are losing their mind on oss-security, which is not surprising as we haven't really educated people about what's up. 

 

I would suggest we come up with a quick one page education document that covers the new way forwards and why it's better/more sustainable, major points to include:

 

1) moving forwards it's all about structured data and automation, random email requests is not sustainable

 

2) MITRE has minted many more CNAs (and continues to do so) so there won't need to be as many requests to MITRE

 

3) the DWF is in the process of doing the CVE Mentor and multiple CNA roll out, which will be way more efficient/easier then everyone in the OpenSource community having to poke MITRE constantly

 

 

 

--
Kurt Seifried -- Red Hat -- Product Security -- Cloud
PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
Red Hat Product Security contact: 
secalert@redhat.com


Page Last Updated or Reviewed: February 16, 2017