cti-interoperability — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
possible work item
I am in favor of us treating other efforts as allies. And with ever one that gets created we should ask our selves the hard questions of:
"why did they feel the need to go create YACS." And "why did STIX not work for them".
Once we understand those questions we can make changes to gain greater adoption.
Bret
Sent from my Commodore 64
On Oct 27, 2015, at 5:01 AM, Davidson II, Mark S < [email protected]
> wrote:
My personal preference would be to work with them to all use the same thing vs. having some form of mapping across them. To me, this means that we would need to be open to accepting ideas from e.g., ThreatExchange and OpenTPX (Note: I’ve taken a quick look and I think there are good things to learn from both). I’ve said this privately to some already: I think ThreatExchange, OpenTPX, et al should be treated as allies in solving the problem of information sharing.
Thank you.
-Mark
From:
[email protected] [ mailto:[email protected] ] On Behalf Of Jason Keirstead
Sent: Monday, October 26, 2015 4:32 PM
To:
[email protected]
Cc:
[email protected] ;
[email protected] ;
[email protected] ; Davidson II, Mark S < [email protected]
>
Subject: Re: RE: [cti-interoperability] possible work item
It might help to get you 50% of the way, but the other 50% is the much longer pole.
- Jason Keirstead Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security
www.securityintelligence.com
Without data, all you are is just another person with an opinion - Unknown
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]