Return-Path: <Kent_Landfield@mcafee.com>
X-Original-To: scap_interest@ietfa.amsl.com
Delivered-To: scap_interest@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
 with ESMTP id 843B521E80D3 for <scap_interest@ietfa.amsl.com>;
 Tue, 14 Feb 2012 13:48:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.598
X-Spam-Level: 
X-Spam-Status: No, score=-6.598 tagged_above=-999 required=5
 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id thOeL64rcOlR for
 <scap_interest@ietfa.amsl.com>; Tue, 14 Feb 2012 13:48:04 -0800 (PST)
Received: from dalsmrelay2.nai.com (dalsmrelay2.nai.com [205.227.136.216]) by
 ietfa.amsl.com (Postfix) with ESMTP id 5E20521E8016 for
 <scap_interest@ietf.org>; Tue, 14 Feb 2012 13:48:04 -0800 (PST)
Received: from (unknown [10.64.5.51]) by dalsmrelay2.nai.com with smtp id
 0239_6dc7_8e4e1736_5755_11e1_93fc_00219b929abd;
 Tue, 14 Feb 2012 15:47:56 -0600
Received: from AMERDALEXMB1.corp.nai.org ([fe80::387d:3d79:ad3b:b517]) by
 DALEXHT1.corp.nai.org ([::1]) with mapi; Tue, 14 Feb 2012 15:46:57 -0600
From: <Kent_Landfield@McAfee.com>
To: <amontville@tripwire.com>, <scap_interest@ietf.org>
Date: Tue, 14 Feb 2012 15:47:29 -0600
Thread-Topic: [scap_interest] Just throwing this out there: Compliance
 Frameworks
Thread-Index: AczrYiurhX3t074lStyhuKNG40cHyg==
Message-ID: <CB602F34.2C555%kent_landfield@mcafee.com>
In-Reply-To: <CB600D8F.9218%amontville@tripwire.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
user-agent: Microsoft-MacOutlook/14.14.0.111121
acceptlanguage: en-US
Content-Type: multipart/alternative;
 boundary="_000_CB602F342C555kentlandfieldmcafeecom_"
MIME-Version: 1.0
Subject: Re: [scap_interest] Just throwing this out there: Compliance
 Frameworks
X-BeenThere: scap_interest@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content
 Automation Protocol \(SCAP\)." <scap_interest.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/scap_interest>,
 <mailto:scap_interest-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/scap_interest>
List-Post: <mailto:scap_interest@ietf.org>
List-Help: <mailto:scap_interest-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/scap_interest>,
 <mailto:scap_interest-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Feb 2012 21:48:05 -0000

--_000_CB602F342C555kentlandfieldmcafeecom_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Adam,

I agree that an effort such as this has great potential.  Think of the cont=
ent authors today. They use XML Editors or internally developed tools to cr=
eate OVAL to do the compliance checking.  This is very time consuming and v=
ery costly, while limiting the available checks and benchmarks.

If there was a means where all regulations and security policies could be u=
niversally mapped and the specifics around them, based on individual platfo=
rms, were also attached to each unified record, it is possible to auto gene=
rate not just the benchmarks but the individual checks.  Some of this resea=
rch has been successful in the past.  This is doable. The problem has been =
there is not an authoritative source for that data.

Today too many people are manually writing content that could be auto gener=
ated from a database with the right schema and software.  The problem thoug=
h is as much on the front end as it is on the generation side.  Someone nee=
ds to maintain that information or have an infrastructure put in place wher=
e guidance authors for regulations or security policies can update their in=
formation in the shared datastore.

I think this is one of the missing pieces and it may be useful to have a di=
scussion with interested parties but you would need to include participants=
 from the two mentioned efforts below.

Kent Landfield
Director Content Strategy, Architecture and Standards

McAfee | An Intel Company
5000 Headquarters Dr.
Plano, Texas 75024

Direct: +1.972.963.7096
Mobile: +1.817.637.8026
Web: www.mcafee.com<http://www.mcafee.com/>

From: Adam Montville <amontville@tripwire.com<mailto:amontville@tripwire.co=
m>>
Date: Tue, 14 Feb 2012 15:09:34 -0600
To: "scap_interest@ietf.org<mailto:scap_interest@ietf.org>" <scap_interest@=
ietf.org<mailto:scap_interest@ietf.org>>
Subject: [scap_interest] Just throwing this out there: Compliance Framework=
s

All,

I had a brief discussion with several members of this list with respect to =
compliance frameworks, which met some resistance.  Still, I think presentin=
g the idea to a larger audience to solicit feedback is a good idea.

>From an automation perspective, it seems that some method of being able to =
map benchmark-level tests to some higher level policy representation may be=
 warranted.  At the end of the day, we perform assessments to ensure that w=
e are in a secure state =96 to be compliant with a particular set of polici=
es.

Is there any interest in being able to represent a compliance framework wit=
h either a new specification or potentially revitalizing and extending an e=
xisting specification (CCI: http://iase.disa.mil/stigs/cci.html), or to sim=
ply rely upon any existing commercial efforts, such as UCF (https://www.uni=
fiedcompliance.com)?

Or, is this type of representation simply not needed =96 there's enough the=
re, the present demand doesn't justify the work, or something else?

Thoughts?

Regards,

Adam W. Montville | Security and Compliance Architect

Direct: 503 276-7661
Mobile: 360 471-7815

TRIPWIRE | Take CONTROL
http://www.tripwire.com

_______________________________________________
scap_interest mailing list
scap_interest@ietf.org<mailto:scap_interest@ietf.org>
https://www.ietf.org/mailman/listinfo/scap_interest


--_000_CB602F342C555kentlandfieldmcafeecom_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html><head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252"></head><body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space;=
 -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 16p=
x; font-family: 'Times New Roman', sans-serif; "><div><div><div>Adam,</div>=
<div><br></div><div>I agree that an effort such as this has great potential=
. &nbsp;Think of the content authors today. They use XML Editors or interna=
lly developed tools to create OVAL to do the compliance checking. &nbsp;Thi=
s is very time consuming and very costly, while limiting the available chec=
ks and benchmarks.</div><div><br></div><div>If there was a means where all =
regulations and security policies could be universally mapped and the speci=
fics around them, based on individual platforms, were also attached to each=
 unified record, it is possible to auto generate not just the benchmarks bu=
t the individual checks. &nbsp;Some of this research has been successful in=
 the past. &nbsp;This is doable. The problem has been there is not an autho=
ritative source for that data. &nbsp;</div><div><br></div><div>Today too ma=
ny people are manually writing content that could be auto generated from a =
database with the right schema and software. &nbsp;The problem though is as=
 much on the front end as it is on the generation side. &nbsp;Someone needs=
 to maintain that information or have an infrastructure put in place where =
guidance authors for regulations or security policies can update their info=
rmation in the shared datastore. &nbsp;</div><div><br></div><div><div>I thi=
nk this is one of the missing pieces and it may be useful to have a discuss=
ion with interested parties but you would need to include participants from=
 the two mentioned efforts below.</div></div><div><br></div><div><div><span=
 class=3D"Apple-style-span" style=3D"font-size: 12px; color: rgb(96, 106, 1=
13); -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacin=
g: 1px; font-family: Arial, Helvetica, sans-serif; "><strong>Kent Landfield=
</strong></span><span class=3D"Apple-style-span" style=3D"font-size: 12px; =
color: rgb(96, 106, 113); -webkit-border-horizontal-spacing: 1px; -webkit-b=
order-vertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif; "><=
br></span><span class=3D"Apple-style-span" style=3D"font-size: 12px; color:=
 rgb(96, 106, 113); -webkit-border-horizontal-spacing: 1px; -webkit-border-=
vertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif; ">Directo=
r Content Strategy, Architecture and Standards</span><span class=3D"Apple-s=
tyle-span" style=3D"font-size: 12px; color: rgb(96, 106, 113); -webkit-bord=
er-horizontal-spacing: 1px; -webkit-border-vertical-spacing: 1px; font-fami=
ly: Arial, Helvetica, sans-serif; "><br></span><span class=3D"Apple-style-s=
pan" style=3D"font-size: 12px; color: rgb(96, 106, 113); -webkit-border-hor=
izontal-spacing: 1px; -webkit-border-vertical-spacing: 1px; font-family: Ar=
ial, Helvetica, sans-serif; "><br></span><span class=3D"Apple-style-span" s=
tyle=3D"font-size: 12px; color: rgb(96, 106, 113); -webkit-border-horizonta=
l-spacing: 1px; -webkit-border-vertical-spacing: 1px; font-family: Arial, H=
elvetica, sans-serif; "><strong>McAfee | An Intel Company</strong></span><s=
pan class=3D"Apple-style-span" style=3D"font-size: 12px; color: rgb(96, 106=
, 113); -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spa=
cing: 1px; font-family: Arial, Helvetica, sans-serif; "><br></span><span cl=
ass=3D"Apple-style-span" style=3D"font-size: 12px; color: rgb(96, 106, 113)=
; -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing: =
1px; font-family: Arial, Helvetica, sans-serif; ">5000 Headquarters Dr.</sp=
an><span class=3D"Apple-style-span" style=3D"font-size: 12px; color: rgb(96=
, 106, 113); -webkit-border-horizontal-spacing: 1px; -webkit-border-vertica=
l-spacing: 1px; font-family: Arial, Helvetica, sans-serif; "><br></span><sp=
an class=3D"Apple-style-span" style=3D"font-size: 12px; color: rgb(96, 106,=
 113); -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spac=
ing: 1px; font-family: Arial, Helvetica, sans-serif; ">Plano, Texas 75024</=
span><span class=3D"Apple-style-span" style=3D"font-size: 12px; color: rgb(=
96, 106, 113); -webkit-border-horizontal-spacing: 1px; -webkit-border-verti=
cal-spacing: 1px; font-family: Arial, Helvetica, sans-serif; "><br></span><=
span class=3D"Apple-style-span" style=3D"font-size: 12px; color: rgb(96, 10=
6, 113); -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-sp=
acing: 1px; font-family: Arial, Helvetica, sans-serif; "><br></span><span c=
lass=3D"Apple-style-span" style=3D"font-size: 12px; color: rgb(96, 106, 113=
); -webkit-border-horizontal-spacing: 1px; -webkit-border-vertical-spacing:=
 1px; font-family: Arial, Helvetica, sans-serif; ">Direct: &#43;1.972.963.7=
096&nbsp;</span><span class=3D"Apple-style-span" style=3D"font-size: 12px; =
color: rgb(96, 106, 113); -webkit-border-horizontal-spacing: 1px; -webkit-b=
order-vertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif; "><=
br></span><span class=3D"Apple-style-span" style=3D"font-size: 12px; color:=
 rgb(96, 106, 113); -webkit-border-horizontal-spacing: 1px; -webkit-border-=
vertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif; ">Mobile:=
 &#43;1.817.637.8026</span><span class=3D"Apple-style-span" style=3D"font-s=
ize: 12px; color: rgb(96, 106, 113); -webkit-border-horizontal-spacing: 1px=
; -webkit-border-vertical-spacing: 1px; font-family: Arial, Helvetica, sans=
-serif; "><br></span><span class=3D"Apple-style-span" style=3D"font-size: 1=
2px; color: rgb(96, 106, 113); -webkit-border-horizontal-spacing: 1px; -web=
kit-border-vertical-spacing: 1px; font-family: Arial, Helvetica, sans-serif=
; "><strong>Web:&nbsp;</strong></span><span class=3D"Apple-style-span" styl=
e=3D"font-size: 12px; color: rgb(96, 106, 113); -webkit-border-horizontal-s=
pacing: 1px; -webkit-border-vertical-spacing: 1px; font-family: Arial, Helv=
etica, sans-serif; "><a href=3D"http://www.mcafee.com/" style=3D"color: rgb=
(96, 106, 113) !important; ">www.mcafee.com</a></span></div></div></div></d=
iv><div><br></div><span id=3D"OLK_SRC_BODY_SECTION"><div style=3D"font-fami=
ly:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: me=
dium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in=
; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium n=
one; PADDING-TOP: 3pt"><span style=3D"font-weight:bold">From: </span> Adam =
Montville &lt;<a href=3D"mailto:amontville@tripwire.com">amontville@tripwir=
e.com</a>&gt;<br><span style=3D"font-weight:bold">Date: </span> Tue, 14 Feb=
 2012 15:09:34 -0600<br><span style=3D"font-weight:bold">To: </span> &quot;=
<a href=3D"mailto:scap_interest@ietf.org">scap_interest@ietf.org</a>&quot; =
&lt;<a href=3D"mailto:scap_interest@ietf.org">scap_interest@ietf.org</a>&gt=
;<br><span style=3D"font-weight:bold">Subject: </span> [scap_interest] Just=
 throwing this out there: Compliance Frameworks<br></div><div><br></div><bl=
ockquote id=3D"MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style=3D"BORDER-LEFT: #b=
5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;"><div><div><div>All,</div><=
div><br></div><div>I had a brief discussion with several members of this li=
st with respect to compliance frameworks, which met some resistance.&nbsp;&=
nbsp;Still, I think presenting the idea to a larger audience to solicit fee=
dback is a good idea.</div><div><br></div><div>From an automation perspecti=
ve, it seems that some method of being able to map benchmark-level tests to=
 some higher level policy representation may be warranted.&nbsp;&nbsp;At th=
e end of the day, we perform assessments to ensure that we are in a secure =
state =96 to be compliant with a particular set of policies.</div><div><br>=
</div><div>Is there any interest in being able to represent a compliance fr=
amework with either a new specification or potentially revitalizing and ext=
ending an existing specification (CCI: <a href=3D"http://iase.disa.mil/stig=
s/cci.html">http://iase.disa.mil/stigs/cci.html</a>), or to simply rely upo=
n any existing commercial efforts, such as UCF (<a href=3D"https://www.unif=
iedcompliance.com">https://www.unifiedcompliance.com</a>)?</div><div><br></=
div><div>Or, is this type of representation simply not needed =96 there's e=
nough there, the present demand doesn't justify the work, or something else=
?</div><div><br></div><div>Thoughts?</div><div><br></div><div>Regards,</div=
><div><br></div><div>Adam W. Montville | Security and Compliance Architect<=
/div><div><br></div><div>Direct: 503 276-7661</div><div>Mobile: 360 471-781=
5</div><div><br></div><div>TRIPWIRE | Take CONTROL</div><div><a href=3D"htt=
p://www.tripwire.com">http://www.tripwire.com</a></div><div><br></div><div>=
_______________________________________________</div><div>scap_interest mai=
ling list</div><div><a href=3D"mailto:scap_interest@ietf.org">scap_interest=
@ietf.org</a></div><div><a href=3D"https://www.ietf.org/mailman/listinfo/sc=
ap_interest">https://www.ietf.org/mailman/listinfo/scap_interest</a></div><=
div><br></div></div></div></blockquote></span></body></html>

--_000_CB602F342C555kentlandfieldmcafeecom_--
