[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: CNA Rules Revision - Final Draft

I have attached a partial review of this document. I have lots of questions on the document’s contents and believe this document could be revised to improve its readability and consistency with our longer-term goals for CVE. I still have a few appendices to review, but I wanted to send my existing comments so we can start a dialog about how to improve the document.


I also agree that artifacts of this nature should require a board vote to approve going forward. This will drive more review, which is needed.





From: owner-cve-editorial-board-list@lists.mitre.org [mailto:owner-cve-editorial-board-list@lists.mitre.org] On Behalf Of Landfield, Kent
Sent: Tuesday, December 05, 2017 10:51 AM
To: cve-editorial-board-list <cve-editorial-board-list@lists.mitre.org>
Subject: Re: CNA Rules Revision - Final Draft


Dan posted this out a couple months ago.


Due to breaking my leg and being laid up I was not really able to review this, especially using the chunky approach taken for reviewing this document.  This is called a final draft, but from the message below it appears to be the final version as timelines are specified as to when this version will take effect.  I am reviewing this document now and finding issues.  I am also aware of another Board reviewer who is also finding issues in this version.  In addition, there are 50 outstanding items that are “to be considered”.  Who determined why these 50 items would be deferred?


In the future, it would be beneficial if documents such as these are sent to the Board for a final approval as they affect the program as a whole. Also, a clean copy should be sent that has all the changes listed in the document as accepted. 


I personally believe this document is in need of work. I propose we delay this version until around the time of the Face to Face summit meeting so the Board has the opportunity to review the ‘proposed final version’ of the CNA Rules in its final form instead of the ‘1 section here, 1 section there’ approach that was taken to develop it. It still needs work if we believe this to be the foundation for CNA interaction going forward. Getting this corrected now will make it easier and better for all. 


In any case, documents of this significant should require a Board vote.




Thank you, Gracias, Grazie,  谢谢, Merci!, Спасибо!, Danke!ありがとうधन्यवाद!


Kent Landfield





From: <owner-cve-editorial-board-list@lists.mitre.org> on behalf of "Adinolfi, Daniel R" <dadinolfi@mitre.org>
Date: Thursday, October 5, 2017 at 9:10 AM
To: cve-editorial-board-list <cve-editorial-board-list@lists.mitre.org>
Subject: CNA Rules Revision - Final Draft




After three months of collecting the community's feedback, ideas, and suggestions, we have updated the CNA Rules.


Thank you to everyone who shared their time and energy to help improve CVE and the CNA Program!


The final draft is included with this message, along with a list of outstanding issues from the revision process.


CNA Rules v2.0week8.docx is the final draft revision for this year's revision process. (This file is also located at <https://github.com/CVEProject/docs/blob/cna-documents/cna/CNA%20Rules/CNA%20Rules%20Development/CNA%20Rules%20v2.0week8.docx>.) The final version of the CNA Rules v2.0 document will be posted on the CVE Website by October 13, 2017, and they will be in effect as of January 1, 2018.


OutstandingIssues.docx is a list of the open issues found in the CVE GitHub Issue Tracker: <https://github.com/CVEProject/docs/issues>. This document includes a brief description of the current state of each open issue.


The outstanding issues will remain open to allow the community to continue their discussions on those issues. If an issue finds resolution before the next CNA Rules revision cycle (starting July 2018), the CVE Board can recommend an out-of-band update to the CNA Rules if they deem it necessary.


If you have any questions about the updates, please let me know. If you have additional thoughts about the open issues, please share them on the GitHub Issue Tracker.






Daniel Adinolfi, CISSP

Lead Cybersecurity Engineer, The MITRE Corporation

CVE Numbering Authority (CNA) Coordinator

Email: <dadinolfi@mitre.org>  Phone: 781-271-5774




Attachment: CNA Rules v2.0week8+daw-20171205.docx
Description: CNA Rules v2.0week8+daw-20171205.docx

Page Last Updated or Reviewed: December 05, 2017