Development meeting proposal

9 messages Options
Embed this post
Permalink
Charles Schmidt (MITRE)

Development meeting proposal

Reply Threaded More More options
Print post
Permalink
Hello everyone,

At Security Automation Developer Days it was suggested that scheduling short developer teleconferences might prove to be a better way to achieve consensus on proposed changes than via isolated email threads. In general, these sessions will be highly technical in nature and are intended to produce specific changes to XCCDF's schema and documentation. Two weeks before the session I'll send out an issue for discussion along with one or more sample solutions, the latter intended as bases for discussion. Following the meeting, minutes and revised excerpts of the schema and documentation will be published for community comment. Barring significant new issues or concerns, the changes will be considered approved after two weeks and will go into the next release of XCCDF (whenever that occurs).

I would like to have the first of these teleconferences in two weeks. I propose a 90 minute meeting starting at 3:00 PM, Eastern Time. If you are interested in participating, please respond to me _directly_ ([hidden email]) and indicate which of Tues Aug 18, Wed Aug 19, or Thurs Aug 20 you would be able to call in. I will send out a final schedule and dial in number later this week. Please respond by close of business on Wednesday if you have a preference regarding dates.

I propose using the conditional checking structures outlined at Security Automation Developer Days as an initial topic of discussion. I have attached an initial write-up and proposal to this email. I encourage people to read and discuss the issue and proposal over the mailing list ahead of time.

If this approach appears to work, I would like to try to continue having short developer meetings every other week for the next few months until the backlog of issues is cleared. Once the backlog has been cleared I hope to continue regular developer meetings, but at a significantly more relaxed pace.

I welcome any comments or suggestions on the proposed plan. I'm hopeful that this approach will allow us to clear the backlog of XCCDF issues in an efficient and transparent manner and result in a standard that better serves the needs of the community.

Thanks,
Charles Schmidt
The MITRE Corp


ConditionalChecks.pdf (115K) Download Attachment
Charles Schmidt (MITRE)

RE: Development meeting proposal - Aug 19

Reply Threaded More More options
Print post
Permalink

Hello all,

It looks like Wednesday, August 19th at 3:00 works for a majority of those who have responded. Dial-in information is below.

If you are available, I encourage you to attend this discussion. We will be discussing the technical details of how best to integrate conditional checking into XCCDF.

Thanks,
Charles
The MITRE Corp.

=====================================

Date/Time:  August 19 2009 at 03:00 PM America/New_York
Length:     90  (minutes)
Frequency:  once


Meeting ID: 643982
Meeting Password:

Phone Number: 703-983-6338 (x36338) in Washington 781-271-6338 (x16338) in Bedford or Toll Free 866-648-7367 (866-MITRE-MP)
Toll Free number is for North America callers only.  Other countries must dial either the Washington or Bedford numbers to attend.

Information on MeetingPlace must be unclassified and releasable to all meeting participants


TO ATTEND THE WEB CONFERENCE AND THEN JOIN WITH AUDIO:

1. Go to: http://audioconference.mitre.org
2. Enter Meetng ID and click on Attend Meeting.
   - Accept any security warnings you receive and wait for the Meeting Room to initialize.


TEST YOUR BROWSER BEFORE YOU ATTEND YOUR FIRST WEB CONFERENCE

Visit http://audioconference.mitre.org to test your web browser for compatibility with the web conference.Follow
this link to your home page,change to your preferred language and look for the Browser Test link.

=====================================

>-----Original Message-----
>From: [hidden email] [mailto:[hidden email]] On Behalf Of
>Schmidt, Charles M.
>Sent: Monday, August 03, 2009 9:26 AM
>To: Multiple recipients of list
>Subject: Development meeting proposal
>
>Hello everyone,
>
>At Security Automation Developer Days it was suggested that scheduling
>short developer teleconferences might prove to be a better way to
>achieve consensus on proposed changes than via isolated email threads.
>In general, these sessions will be highly technical in nature and are
>intended to produce specific changes to XCCDF's schema and
>documentation. Two weeks before the session I'll send out an issue for
>discussion along with one or more sample solutions, the latter intended
>as bases for discussion. Following the meeting, minutes and revised
>excerpts of the schema and documentation will be published for community
>comment. Barring significant new issues or concerns, the changes will be
>considered approved after two weeks and will go into the next release of
>XCCDF (whenever that occurs).
>
>I would like to have the first of these teleconferences in two weeks. I
>propose a 90 minute meeting starting at 3:00 PM, Eastern Time. If you
>are interested in participating, please respond to me _directly_
>([hidden email]) and indicate which of Tues Aug 18, Wed Aug 19, or
>Thurs Aug 20 you would be able to call in. I will send out a final
>schedule and dial in number later this week. Please respond by close of
>business on Wednesday if you have a preference regarding dates.
>
>I propose using the conditional checking structures outlined at Security
>Automation Developer Days as an initial topic of discussion. I have
>attached an initial write-up and proposal to this email. I encourage
>people to read and discuss the issue and proposal over the mailing list
>ahead of time.
>
>If this approach appears to work, I would like to try to continue having
>short developer meetings every other week for the next few months until
>the backlog of issues is cleared. Once the backlog has been cleared I
>hope to continue regular developer meetings, but at a significantly more
>relaxed pace.
>
>I welcome any comments or suggestions on the proposed plan. I'm hopeful
>that this approach will allow us to clear the backlog of XCCDF issues in
>an efficient and transparent manner and result in a standard that better
>serves the needs of the community.
>
>Thanks,
>Charles Schmidt
>The MITRE Corp


---------------------------------------------------------------

To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.

Kent_Landfield

RE: Development meeting proposal - Aug 19

Reply Threaded More More options
Print post
Permalink

I recommend that meetings like this be sent out as Outlook Calendar requests so it is easier for all to get them added to their calendars. Making it easier to book the time will increase the chance of having more people attend.

Just a thought.

--
Kent Landfield
Director, Risk and Compliance Security Research
McAfee, Inc.
+1 972.963.7096 Direct
+1 214.385.1138 Mobile
[hidden email]

-----Original Message-----
From: [hidden email] [mailto:[hidden email]] On Behalf Of Schmidt, Charles M.
Sent: Thursday, August 06, 2009 7:40 AM
To: Multiple recipients of list
Subject: RE: Development meeting proposal - Aug 19


Hello all,

It looks like Wednesday, August 19th at 3:00 works for a majority of those who have responded. Dial-in information is below.

If you are available, I encourage you to attend this discussion. We will be discussing the technical details of how best to integrate conditional checking into XCCDF.

Thanks,
Charles
The MITRE Corp.

=====================================

Date/Time:  August 19 2009 at 03:00 PM America/New_York
Length:     90  (minutes)
Frequency:  once


Meeting ID: 643982
Meeting Password:

Phone Number: 703-983-6338 (x36338) in Washington 781-271-6338 (x16338) in Bedford or Toll Free 866-648-7367 (866-MITRE-MP)
Toll Free number is for North America callers only.  Other countries must dial either the Washington or Bedford numbers to attend.

Information on MeetingPlace must be unclassified and releasable to all meeting participants


TO ATTEND THE WEB CONFERENCE AND THEN JOIN WITH AUDIO:

1. Go to: http://audioconference.mitre.org
2. Enter Meetng ID and click on Attend Meeting.
   - Accept any security warnings you receive and wait for the Meeting Room to initialize.


TEST YOUR BROWSER BEFORE YOU ATTEND YOUR FIRST WEB CONFERENCE

Visit http://audioconference.mitre.org to test your web browser for compatibility with the web conference.Follow
this link to your home page,change to your preferred language and look for the Browser Test link.

=====================================

>-----Original Message-----
>From: [hidden email] [mailto:[hidden email]] On Behalf Of
>Schmidt, Charles M.
>Sent: Monday, August 03, 2009 9:26 AM
>To: Multiple recipients of list
>Subject: Development meeting proposal
>
>Hello everyone,
>
>At Security Automation Developer Days it was suggested that scheduling
>short developer teleconferences might prove to be a better way to
>achieve consensus on proposed changes than via isolated email threads.
>In general, these sessions will be highly technical in nature and are
>intended to produce specific changes to XCCDF's schema and
>documentation. Two weeks before the session I'll send out an issue for
>discussion along with one or more sample solutions, the latter intended
>as bases for discussion. Following the meeting, minutes and revised
>excerpts of the schema and documentation will be published for community
>comment. Barring significant new issues or concerns, the changes will be
>considered approved after two weeks and will go into the next release of
>XCCDF (whenever that occurs).
>
>I would like to have the first of these teleconferences in two weeks. I
>propose a 90 minute meeting starting at 3:00 PM, Eastern Time. If you
>are interested in participating, please respond to me _directly_
>([hidden email]) and indicate which of Tues Aug 18, Wed Aug 19, or
>Thurs Aug 20 you would be able to call in. I will send out a final
>schedule and dial in number later this week. Please respond by close of
>business on Wednesday if you have a preference regarding dates.
>
>I propose using the conditional checking structures outlined at Security
>Automation Developer Days as an initial topic of discussion. I have
>attached an initial write-up and proposal to this email. I encourage
>people to read and discuss the issue and proposal over the mailing list
>ahead of time.
>
>If this approach appears to work, I would like to try to continue having
>short developer meetings every other week for the next few months until
>the backlog of issues is cleared. Once the backlog has been cleared I
>hope to continue regular developer meetings, but at a significantly more
>relaxed pace.
>
>I welcome any comments or suggestions on the proposed plan. I'm hopeful
>that this approach will allow us to clear the backlog of XCCDF issues in
>an efficient and transparent manner and result in a standard that better
>serves the needs of the community.
>
>Thanks,
>Charles Schmidt
>The MITRE Corp


---------------------------------------------------------------

To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.



---------------------------------------------------------------

To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.

Gary Gapinski-4

Re: Development meeting proposal - Aug 19

Reply Threaded More More options
Print post
Permalink

[hidden email] wrote:
> I recommend that meetings like this be sent out as Outlook Calendar requests so it is easier for all to get them added to their calendars. Making it easier to book the time will increase the chance of having more people attend.
>  

A good idea, but much better would be MIME-encapsulated RFC2445
(iCalendar) format. Not everyone happens to use Microsoft Outlook.

Regards,

Gary


---------------------------------------------------------------

To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.

Charles Schmidt (MITRE)

RE: Development meeting proposal - Aug 19

Reply Threaded More More options
Print post
Permalink
An excellent idea. I have attached an iCalendar meeting to this email and will include them in future meeting announcements.

Charles

>-----Original Message-----
>From: [hidden email] [mailto:[hidden email]] On Behalf Of Gary
>Gapinski
>Sent: Thursday, August 06, 2009 10:10 AM
>To: Multiple recipients of list
>Subject: Re: Development meeting proposal - Aug 19
>
>
>[hidden email] wrote:
>> I recommend that meetings like this be sent out as Outlook Calendar
>requests so it is easier for all to get them added to their calendars.
>Making it easier to book the time will increase the chance of having
>more people attend.
>>
>
>A good idea, but much better would be MIME-encapsulated RFC2445
>(iCalendar) format. Not everyone happens to use Microsoft Outlook.
>
>Regards,
>
>Gary
>
>
>---------------------------------------------------------------
>
>To unsubscribe from this mailing list, please send an e-mail to
>[hidden email] with the words "unsubscribe xccdf-dev" in the
>body. You will need to send this from the email account that you
>used to initially subscribe to xccdf-dev.

[XCCDF Developer meeting.ics]

BEGIN:VCALENDAR
PRODID:-//Microsoft Corporation//Outlook 12.0 MIMEDIR//EN
VERSION:2.0
METHOD:REQUEST
X-MS-OLK-FORCEINSPECTOROPEN:TRUE
BEGIN:VEVENT
ATTENDEE;CN="Foreman, Beth";RSVP=TRUE:mailto:[hidden email]
CLASS:PUBLIC
CREATED:20090806T170107Z
DESCRIPTION:This announcement is for a short developer meeting for the XCCD
        F standard. This meeting will focus on conditional checking and will aim a
        t developing technical solutions that could be integrated in a future vers
        ion of the standard. A PDF summarizing the issue and presenting one possib
        le solution can be downloaded from the XCCDF Nabble archive: http://n2.nab
        ble.com/Development-meeting-proposal-td3377726.html#a3377726. If you have
        initial comments or suggestions\, please feel free to raise them via the x
        ccdf-dev mailing list.\n\nThe dial-in information for the meeting appears
        below.\n\nThanks\,\nCharles \nThe MITRE Corp\n\nDate/Time:  August 19 2009
         at 03:00 PM America/New_York\nLength:     90  (minutes)\nFrequency:  once
        \n\n\nMeeting ID: 643982\nMeeting Password: \n\nPhone Number: 703-983-6338
         (x36338) in Washington 781-271-6338 (x16338) in Bedford or Toll Free 866-
        648-7367 (866-MITRE-MP)\nToll Free number is for North America callers onl
        y.  Other countries must dial either the Washington or Bedford numbers to
        attend.\n\nInformation on MeetingPlace must be unclassified and releasable
         to all meeting participants\n\n\nTO ATTEND THE WEB CONFERENCE AND THEN JO
        IN WITH AUDIO:\n\n1. Go to: http://audioconference.mitre.org\n2. Enter Mee
        tng ID and click on Attend Meeting.\n   - Accept any security warnings you
         receive and wait for the Meeting Room to initialize.\n\n\nTEST YOUR BROWS
        ER BEFORE YOU ATTEND YOUR FIRST WEB CONFERENCE\n\nVisit http://audioconfer
        ence.mitre.org to test your web browser for compatibility with the web con
        ference.Follow\nthis link to your home page\,change to your preferred lang
        uage and look for the Browser Test link.\n\n\n
DTEND:20090819T203000Z
DTSTAMP:20090806T130653Z
DTSTART:20090819T190000Z
LAST-MODIFIED:20090806T170107Z
LOCATION:Meetingplace -pin  643982
ORGANIZER;CN="Schmidt, Charles M.":mailto:[hidden email]
PRIORITY:5
SEQUENCE:0
SUMMARY;LANGUAGE=en-us:XCCDF Developer meeting
TRANSP:OPAQUE
UID:040000008200E00074C5B7101A82E00800000000109D71BF7116CA01000000000000000
        0100000006ECDDE576CA2A64EA89D207710916C5F
X-ALT-DESC;FMTTYPE=text/html:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//E
        N">\n<HTML>\n<HEAD>\n<META NAME="Generator" CONTENT="MS Exchange Server ve
        rsion 08.00.0681.000">\n<TITLE></TITLE>\n</HEAD>\n<BODY>\n<!-- Converted f
        rom text/rtf format -->\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE="Conso
        las">This announcement is for a short developer meeting for the XCCDF stan
        dard. This meeting will focus on conditional checking and will aim at deve
        loping technical solutions that could be integrated in a fu</FONT></SPAN><
        SPAN LANG="en-us"><FONT FACE="Consolas">ture version of the standard. A PD
        F summarizing the issue and presenting one possible solution can be downlo
        aded from the XCCDF Nabble archive:</FONT></SPAN><SPAN LANG="en-us"> </SPA
        N><A HREF="http://n2.nabble.com/Development-meeting-proposal-td3377726.htm
        l#a3377726"><SPAN LANG="en-us"><U><FONT COLOR="#0000FF" FACE="Consolas">ht
        tp://n2.nabble.com/Development-meeting-proposal-td3377726.html#a3377726</F
        ONT></U></SPAN><SPAN LANG="en-us"></SPAN></A><SPAN LANG="en-us"><FONT FACE
        ="Consolas">. If you have initial comments or suggestions\, please feel fr
        ee to raise them via the xccdf-dev mailing</FONT></SPAN><SPAN LANG="en-us"
        > <FONT FACE="Consolas">list.</FONT></SPAN><SPAN LANG="en-us"></SPAN></P>\
        n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE="Consolas">The dial-in informa
        tion</FONT></SPAN><SPAN LANG="en-us"> <FONT FACE="Consolas">for the meetin
        g appears below.</FONT></SPAN></P>\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT
        FACE="Consolas">Thanks\,</FONT></SPAN></P>\n\n<P DIR=LTR><SPAN LANG="en-us
        "><FONT FACE="Consolas">Charles </FONT></SPAN></P>\n\n<P DIR=LTR><SPAN LAN
        G="en-us"><FONT FACE="Consolas">The MITRE Corp</FONT></SPAN><SPAN LANG="en
        -us"></SPAN></P>\n\n<P DIR=LTR><SPAN LANG="en-us"></SPAN></P>\n\n<P DIR=LT
        R><SPAN LANG="en-us"><FONT FACE="Consolas">Date/Time: \; August 19 200
        9 at 03:00 PM America/New_York</FONT></SPAN></P>\n\n<P DIR=LTR><SPAN LANG=
        "en-us"><FONT FACE="Consolas">Length: \; \; \; \; 90 \
        ; (minutes)</FONT></SPAN></P>\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE=
        "Consolas">Frequency: \; once</FONT></SPAN></P>\n<BR>\n\n<P DIR=LTR><S
        PAN LANG="en-us"><FONT FACE="Consolas">Meeting ID: 643982</FONT></SPAN></P
        >\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE="Consolas">Meeting Password:
         </FONT></SPAN></P>\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE="Consolas"
        >Phone Number: 703-983-6338 (x36338) in Washington 781-271-6338 (x16338) i
        n Bedford or Toll Free 866-648-7367 (866-MITRE-MP)</FONT></SPAN></P>\n\n<P
         DIR=LTR><SPAN LANG="en-us"><FONT FACE="Consolas">Toll Free number is for
        North America callers only. \; Other countries must dial either the Wa
        shington or Bedford numbers to attend.</FONT></SPAN></P>\n\n<P DIR=LTR><SP
        AN LANG="en-us"><FONT FACE="Consolas">Information on MeetingPlace must be
        unclassified and releasable to all meeting participants</FONT></SPAN></P>\
        n<BR>\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE="Consolas">TO ATTEND THE
         WEB CONFERENCE AND THEN JOIN WITH AUDIO:</FONT></SPAN></P>\n\n<P DIR=LTR>
        <SPAN LANG="en-us"><FONT FACE="Consolas">1. Go to:</FONT></SPAN><SPAN LANG
        ="en-us"> </SPAN><A HREF="http://audioconference.mitre.org"><SPAN LANG="en
        -us"><U><FONT COLOR="#0000FF" FACE="Consolas">http://audioconference.mitre
        .org</FONT></U></SPAN><SPAN LANG="en-us"></SPAN></A><SPAN LANG="en-us"></S
        PAN></P>\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE="Consolas">2. Enter M
        eetng ID and click on Attend Meeting.</FONT></SPAN></P>\n\n<P DIR=LTR><SPA
        N LANG="en-us"><FONT FACE="Consolas"> \; \; - Accept any security
        warnings you receive and wait for the Meeting Room to initialize.</FONT></
        SPAN></P>\n<BR>\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE="Consolas">TES
        T YOUR BROWSER BEFORE YOU ATTEND YOUR FIRST WEB CONFERENCE</FONT></SPAN></
        P>\n\n<P DIR=LTR><SPAN LANG="en-us"><FONT FACE="Consolas">Visit</FONT></SP
        AN><SPAN LANG="en-us"> </SPAN><A HREF="http://audioconference.mitre.org"><
        SPAN LANG="en-us"><U><FONT COLOR="#0000FF" FACE="Consolas">http://audiocon
        ference.mitre.org</FONT></U></SPAN><SPAN LANG="en-us"></SPAN></A><SPAN LAN
        G="en-us"><FONT FACE="Consolas"> to test your web browser for compatibilit
        y with the web conference.Follow</FONT></SPAN></P>\n\n<P DIR=LTR><SPAN LAN
        G="en-us"><FONT FACE="Consolas">this link to your home page\,change to you
        r preferred language and look for the Browser Test link.</FONT></SPAN></P>
        \n\n<P DIR=LTR><SPAN LANG="en-us"></SPAN><SPAN LANG="en-us"></SPAN></P>\n\
        n</BODY>\n</HTML>
X-MICROSOFT-CDO-BUSYSTATUS:BUSY
X-MICROSOFT-CDO-IMPORTANCE:1
X-MICROSOFT-DISALLOW-COUNTER:FALSE
X-MS-OLK-ALLOWEXTERNCHECK:TRUE
X-MS-OLK-APPTSEQTIME:20090806T130653Z
X-MS-OLK-AUTOFILLLOCATION:FALSE
X-MS-OLK-CONFTYPE:0
BEGIN:VALARM
TRIGGER:-PT5M
ACTION:DISPLAY
DESCRIPTION:Reminder
END:VALARM
END:VEVENT
END:VCALENDAR

Kent_Landfield

RE: Development meeting proposal - Aug 19

Reply Threaded More More options
Print post
Permalink
In reply to this post by Gary Gapinski-4

Works for me. ;-)  

--
Kent Landfield
Director, Risk and Compliance Security Research
McAfee, Inc.
+1 972.963.7096 Direct
+1 214.385.1138 Mobile
[hidden email]
-----Original Message-----
From: [hidden email] [mailto:[hidden email]] On Behalf Of Gary Gapinski
Sent: Thursday, August 06, 2009 9:10 AM
To: Multiple recipients of list
Subject: Re: Development meeting proposal - Aug 19


[hidden email] wrote:
> I recommend that meetings like this be sent out as Outlook Calendar requests so it is easier for all to get them added to their calendars. Making it easier to book the time will increase the chance of having more people attend.
>  

A good idea, but much better would be MIME-encapsulated RFC2445
(iCalendar) format. Not everyone happens to use Microsoft Outlook.

Regards,

Gary


---------------------------------------------------------------

To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.



---------------------------------------------------------------

To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.

Charles Schmidt (MITRE)

Reminder: Development meeting proposal - Aug 19 (tomorrow)

Reply Threaded More More options
Print post
Permalink
In reply to this post by Charles Schmidt (MITRE)

Hello,

This is just a quick reminder that there will be an XCCDF developer telecon tomorrow, August 19 at 3:00 Eastern Time. The topic of this meeting will be the implementation of conditional checks in XCCDF. A summary of the issues and a sample proposal can be found in the mailing list archive: http://n2.nabble.com/attachment/3377726/0/ConditionalChecks.pdf

All interested parties are encouraged to attend. Dial in information is below.

Thanks,
Charles
The MITRE Corp.

>-----Original Message-----
>From: [hidden email] [mailto:[hidden email]] On Behalf Of
>Schmidt, Charles M.
>Sent: Thursday, August 06, 2009 7:40 AM
>To: Multiple recipients of list
>Subject: RE: Development meeting proposal - Aug 19
>
>Date/Time:  August 19 2009 at 03:00 PM America/New_York
>Length:     90  (minutes)
>Frequency:  once
>
>
>Meeting ID: 643982
>Meeting Password:
>
>Phone Number: 703-983-6338 (x36338) in Washington 781-271-6338 (x16338)
>in Bedford or Toll Free 866-648-7367 (866-MITRE-MP)
>Toll Free number is for North America callers only.  Other countries
>must dial either the Washington or Bedford numbers to attend.
>
>Information on MeetingPlace must be unclassified and releasable to all
>meeting participants
>
>
>TO ATTEND THE WEB CONFERENCE AND THEN JOIN WITH AUDIO:
>
>1. Go to: http://audioconference.mitre.org
>2. Enter Meetng ID and click on Attend Meeting.
>   - Accept any security warnings you receive and wait for the Meeting
>Room to initialize.
>
>
>TEST YOUR BROWSER BEFORE YOU ATTEND YOUR FIRST WEB CONFERENCE
>
>Visit http://audioconference.mitre.org to test your web browser for
>compatibility with the web conference.Follow
>this link to your home page,change to your preferred language and look
>for the Browser Test link.
>
>=====================================
>>-----Original Message-----
>>From: [hidden email] [mailto:[hidden email]] On Behalf Of
>>Schmidt, Charles M.
>>Sent: Monday, August 03, 2009 9:26 AM
>>To: Multiple recipients of list
>>Subject: Development meeting proposal
>>
>>Hello everyone,
>>
>>At Security Automation Developer Days it was suggested that scheduling
>>short developer teleconferences might prove to be a better way to
>>achieve consensus on proposed changes than via isolated email threads.
>>In general, these sessions will be highly technical in nature and are
>>intended to produce specific changes to XCCDF's schema and
>>documentation. Two weeks before the session I'll send out an issue for
>>discussion along with one or more sample solutions, the latter intended
>>as bases for discussion. Following the meeting, minutes and revised
>>excerpts of the schema and documentation will be published for
>community
>>comment. Barring significant new issues or concerns, the changes will
>be
>>considered approved after two weeks and will go into the next release
>of
>>XCCDF (whenever that occurs).
>>
>>I would like to have the first of these teleconferences in two weeks. I
>>propose a 90 minute meeting starting at 3:00 PM, Eastern Time. If you
>>are interested in participating, please respond to me _directly_
>>([hidden email]) and indicate which of Tues Aug 18, Wed Aug 19, or
>>Thurs Aug 20 you would be able to call in. I will send out a final
>>schedule and dial in number later this week. Please respond by close of
>>business on Wednesday if you have a preference regarding dates.
>>
>>I propose using the conditional checking structures outlined at
>Security
>>Automation Developer Days as an initial topic of discussion. I have
>>attached an initial write-up and proposal to this email. I encourage
>>people to read and discuss the issue and proposal over the mailing list
>>ahead of time.
>>
>>If this approach appears to work, I would like to try to continue
>having
>>short developer meetings every other week for the next few months until
>>the backlog of issues is cleared. Once the backlog has been cleared I
>>hope to continue regular developer meetings, but at a significantly
>more
>>relaxed pace.
>>
>>I welcome any comments or suggestions on the proposed plan. I'm hopeful
>>that this approach will allow us to clear the backlog of XCCDF issues
>in
>>an efficient and transparent manner and result in a standard that
>better
>>serves the needs of the community.
>>
>>Thanks,
>>Charles Schmidt
>>The MITRE Corp
>
>
>---------------------------------------------------------------
>
>To unsubscribe from this mailing list, please send an e-mail to
>[hidden email] with the words "unsubscribe xccdf-dev" in the
>body. You will need to send this from the email account that you
>used to initially subscribe to xccdf-dev.



---------------------------------------------------------------

To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.

Gary Gapinski-4

Re: Development meeting proposal - Aug 19

Reply Threaded More More options
Print post
Permalink
In reply to this post by Charles Schmidt (MITRE)

Someone (I do not recall who) cited (I think) the XCCDF specification
page 37 regarding the order in which XCCDF "Traversal" occurs.

I have checked
http://csrc.nist.gov/publications/nistir/ir7275r3/NISTIR-7275r3.pdf and
cannot find an unambiguous definition.

Page 36 specifies "…a pre-order, depth-first walk through all the Items
that make up a Benchmark.…".

Page 37 specifies "…tools must process the Items of the Benchmark in
order…".

The latter seems to depend on the former for precise definition.

The former lacks precision because it does not mention that such a
pre-order depth-first traversal be applied to the result of "resolution"
(pp33-34), and furthermore does not specify if it is "left-to-right"
(resolved document order) or "right-to-left" (reverse resolved document
order).

What am I missing here? As far as I can tell, the order is ambiguous.
IMO, it should simply be (resolved) document order.

Worse, the resolution phase does not mandate that any original document
order be preserved in the resolved document (no order of resolution is
specified).

Regards,

Gary


---------------------------------------------------------------

To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.

Charles Schmidt (MITRE)

RE: Development meeting proposal - Aug 19

Reply Threaded More More options
Print post
Permalink
In reply to this post by Charles Schmidt (MITRE)
Hello all,

The meeting minutes from the developer meeting on August 19 are attached. Please let me know if you have corrections or comments. Thank you to everyone who participated.

For those of you who could not make it, we had a challenging and extremely productive discussion on conditional checks. The discussion revealed that, while there is overall agreement on the need for conditional structures, there are two use cases with very different needs with regard to this functionality. Given the discussions our only ideas were to either ignore the needs of one of these communities, or split XCCDF into two, separately validated, "dialects". As both of these are somewhat drastic responses, I'm proposing that we table this issue for the moment and continue working through the back-issues before returning to it. Rest assured that the comments made in the conditional-checking discussion will not be lost - instead I'm hoping by adding additional context from other open issues we will be able to shed more light on the competing use cases of XCCDF and better evaluate how to serve the community.

Again, thank you to everyone who participated in the last meeting - the input was extremely helpful.

Thanks,
Charles

>-----Original Message-----
>From: [hidden email] [mailto:[hidden email]] On Behalf Of
>Schmidt, Charles M.
>Sent: Thursday, August 06, 2009 7:40 AM
>To: Multiple recipients of list
>Subject: RE: Development meeting proposal - Aug 19
>
>
>Hello all,
>
>It looks like Wednesday, August 19th at 3:00 works for a majority of
>those who have responded. Dial-in information is below.
>
>If you are available, I encourage you to attend this discussion. We will
>be discussing the technical details of how best to integrate conditional
>checking into XCCDF.
>
>Thanks,
>Charles
>The MITRE Corp.
>
>=====================================
>
>Date/Time:  August 19 2009 at 03:00 PM America/New_York
>Length:     90  (minutes)
>Frequency:  once
>
>
>Meeting ID: 643982
>Meeting Password:
>
>Phone Number: 703-983-6338 (x36338) in Washington 781-271-6338 (x16338)
>in Bedford or Toll Free 866-648-7367 (866-MITRE-MP)
>Toll Free number is for North America callers only.  Other countries
>must dial either the Washington or Bedford numbers to attend.
>
>Information on MeetingPlace must be unclassified and releasable to all
>meeting participants
>
>
>TO ATTEND THE WEB CONFERENCE AND THEN JOIN WITH AUDIO:
>
>1. Go to: http://audioconference.mitre.org
>2. Enter Meetng ID and click on Attend Meeting.
>   - Accept any security warnings you receive and wait for the Meeting
>Room to initialize.
>
>
>TEST YOUR BROWSER BEFORE YOU ATTEND YOUR FIRST WEB CONFERENCE
>
>Visit http://audioconference.mitre.org to test your web browser for
>compatibility with the web conference.Follow
>this link to your home page,change to your preferred language and look
>for the Browser Test link.
>
>=====================================
>>-----Original Message-----
>>From: [hidden email] [mailto:[hidden email]] On Behalf Of
>>Schmidt, Charles M.
>>Sent: Monday, August 03, 2009 9:26 AM
>>To: Multiple recipients of list
>>Subject: Development meeting proposal
>>
>>Hello everyone,
>>
>>At Security Automation Developer Days it was suggested that scheduling
>>short developer teleconferences might prove to be a better way to
>>achieve consensus on proposed changes than via isolated email threads.
>>In general, these sessions will be highly technical in nature and are
>>intended to produce specific changes to XCCDF's schema and
>>documentation. Two weeks before the session I'll send out an issue for
>>discussion along with one or more sample solutions, the latter intended
>>as bases for discussion. Following the meeting, minutes and revised
>>excerpts of the schema and documentation will be published for
>community
>>comment. Barring significant new issues or concerns, the changes will
>be
>>considered approved after two weeks and will go into the next release
>of
>>XCCDF (whenever that occurs).
>>
>>I would like to have the first of these teleconferences in two weeks. I
>>propose a 90 minute meeting starting at 3:00 PM, Eastern Time. If you
>>are interested in participating, please respond to me _directly_
>>([hidden email]) and indicate which of Tues Aug 18, Wed Aug 19, or
>>Thurs Aug 20 you would be able to call in. I will send out a final
>>schedule and dial in number later this week. Please respond by close of
>>business on Wednesday if you have a preference regarding dates.
>>
>>I propose using the conditional checking structures outlined at
>Security
>>Automation Developer Days as an initial topic of discussion. I have
>>attached an initial write-up and proposal to this email. I encourage
>>people to read and discuss the issue and proposal over the mailing list
>>ahead of time.
>>
>>If this approach appears to work, I would like to try to continue
>having
>>short developer meetings every other week for the next few months until
>>the backlog of issues is cleared. Once the backlog has been cleared I
>>hope to continue regular developer meetings, but at a significantly
>more
>>relaxed pace.
>>
>>I welcome any comments or suggestions on the proposed plan. I'm hopeful
>>that this approach will allow us to clear the backlog of XCCDF issues
>in
>>an efficient and transparent manner and result in a standard that
>better
>>serves the needs of the community.
>>
>>Thanks,
>>Charles Schmidt
>>The MITRE Corp
>
>
>---------------------------------------------------------------
>
>To unsubscribe from this mailing list, please send an e-mail to
>[hidden email] with the words "unsubscribe xccdf-dev" in the
>body. You will need to send this from the email account that you
>used to initially subscribe to xccdf-dev.


Minutes - XCCDF Developer Meeting 19Aug09.pdf (142K) Download Attachment