[scap_interest] Summary of first SCAP BOF meeting

Steve Hanna <stevehanna.travel@gmail.com> Wed, 10 November 2010 14:10 UTC

Return-Path: <stevehanna.travel@gmail.com>
X-Original-To: scap_interest@core3.amsl.com
Delivered-To: scap_interest@core3.amsl.com
Received: from localhost (localhost []) by core3.amsl.com (Postfix) with ESMTP id 0214C3A6983 for <scap_interest@core3.amsl.com>; Wed, 10 Nov 2010 06:10:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.448
X-Spam-Status: No, score=-2.448 tagged_above=-999 required=5 tests=[AWL=0.151, BAYES_00=-2.599]
Received: from mail.ietf.org ([]) by localhost (core3.amsl.com []) (amavisd-new, port 10024) with ESMTP id eCJH70KyCBjM for <scap_interest@core3.amsl.com>; Wed, 10 Nov 2010 06:10:14 -0800 (PST)
Received: from mail-qy0-f179.google.com (mail-qy0-f179.google.com []) by core3.amsl.com (Postfix) with ESMTP id 335423A69C5 for <scap_interest@ietf.org>; Wed, 10 Nov 2010 06:10:13 -0800 (PST)
Received: by qyk4 with SMTP id 4so290142qyk.10 for <scap_interest@ietf.org>; Wed, 10 Nov 2010 06:10:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:date:message-id :subject:from:to:content-type; bh=y96vkNamotgXWg//Q8VT7o4A5J9seyCIqfjKgaM8dm4=; b=dzPUTbVVsVcnyKi9Slmr+YEZmWUOAG6SN2J7/iAZU7wemvx5O1gmkX2gv+KZotQWiz zq8vcff9Zg4le09/0Fp55lUGkWMcNzEU7T9gYP0p3/2VyIDE5+sNL88gGwW8BK8ityBR uBFknPxLK0JHb7LanZb/BnTaeC99D48C99Rg0=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=ogJoex77zuQkdHWpcVY04Mt4ZQhBtmSZTYH2op6epHeJgAFSJ+d/YmwSP2BpC6QtVV aVoiJnJ+jPtRHjT5nsFcCQeU98dqi4jU3ryIIrVZ4n/m/0U+/Q8s6TwdP8ZSHVOoVhA+ gXF6FjGRtYobE9+zArWltb6G/XnduvowM3LBc=
MIME-Version: 1.0
Received: by with SMTP id ha11mr7588212qcb.235.1289398239976; Wed, 10 Nov 2010 06:10:39 -0800 (PST)
Received: by with HTTP; Wed, 10 Nov 2010 06:10:39 -0800 (PST)
Date: Wed, 10 Nov 2010 22:10:39 +0800
Message-ID: <AANLkTinDhOQ=+VwXBcpz68qvU8UuGJ+TuODqCyoKz2Rr@mail.gmail.com>
From: Steve Hanna <stevehanna.travel@gmail.com>
To: scap_interest@ietf.org
Content-Type: text/plain; charset=ISO-8859-1
Subject: [scap_interest] Summary of first SCAP BOF meeting
X-BeenThere: scap_interest@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "Discussion List for IETFers interested in the Security Content Automation Protocol \(SCAP\)." <scap_interest.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/scap_interest>, <mailto:scap_interest-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/scap_interest>
List-Post: <mailto:scap_interest@ietf.org>
List-Help: <mailto:scap_interest-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/scap_interest>, <mailto:scap_interest-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Nov 2010 14:10:15 -0000

While we're waiting for initial minutes from the SCAP BOF, here's the
summary that I sent to SAAG (Security Area Advisory Group). FYI.




The SCAP BOF met on Tuesday, November 9 from 1520 to 1810. This was
an exploratory BOF devoted to exploring the possible ways in which the
IETF and SCAP communities can work together. After an SCAP Overview
and several presentations that looked at SCAP from several perspectives
(Network Management, NEA, and ITU CYBEX), there was an extensive Q&A
and a discussion of the possibilities for collaboration. The group
agreed to write
up an Internet Draft with collaboration ideas, focusing especially on network
protocols that the SCAP community needs: reporting on SCAP compliance
within a NEA assessment, provisioning XCCDF and OVAL content to an
endpoint, etc. This draft can stimulate more concrete discussions about
whether a WG should be formed.