[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: CVE ID Syntax - Seeking Suggestions for Outreach

On Wed, 2 Apr 2014 10:01:46 -0400
"Steven M. Christey" <coley@mitre.org> wrote:

> * Are there Board members who are willing to announce the change
>    and/or post educational material to their customer base?  If so,
>    what form would be the most useful - PowerPoint slides, a web page,
>    newsletter, webinar, etc.?

I'll write a CERIAS blog entry about it.

> * Would it be effective for us to encourage implementers to announce
>    when they have achieved "compliance" with the new syntax, and then
>    publicize these vendors?  Would this be useful in fostering some
>    competiveness to drive organizations to a resolution?

Give people a png "badge" to display on web pages about
compliance with the new format?

> * Are there ways that we can help customers to directly engage with
>    their vendors to ensure that the issues are addressed?  We have not
>    yet directly emphasized customers in our outreach, but they might
> be the most effective in contacting the right people within the
> vendors and getting resolution.

I expect most customers will get engaged only when something breaks.
I think it would be most useful to publicize the switch and send notices
just before you run out of old format IDs.  What "just before" means
could be "1 week" but is of course debatable.


Page Last Updated or Reviewed: October 03, 2014