CWE/CAPEC Board Members, Good afternoon – I hope you are all doing well. I wanted to send a courtesy notification update on the User Experience Working Group community leadership.
We have identified a co-chair for the CWE/CAPEC User Experience Working Group: Shadya Maldonado Rosado. She brings significant experience and enthusiasm to the role! Here’s a little bio that she provided: Shadya Maldonado Rosado joined Sandia National Laboratory (SNL) as a principal cybersecurity engineer in 2021, bringing 12 years of experience in national security, analysis, and operations. Shadya’s previous technical leadership efforts and contributions supported computer network defense, situational awareness, nuclear engineering, and analysis, in addition to multi-domain threat assessments. Her research and external outreach activities include engaging data scientists and engineers to develop analytic tools to support transitioning emerging technologies from research to operation. Shadya’s current work supports domestic and international stakeholders in the cyber and nuclear industries. She currently serves as the Sandia technical lead for a multi-lab collaboration working to build a Cyber Security Operations Center (CSOC) that is enabled by Software-Defined Networking (SDN) within the Department of Energy’s (DOE) International Nuclear Security (INS) portfolio. Shadya has experience using CWE/CAPEC information directly and working with teams that do so as well. She is passionate about helping us find ways to modernize the CWE/CAPEC user experience in collaboration with our community stakeholders. She will hit the ground running in her new role during our next meeting on June 1, where we will likely: 1. Begin finishing up the user persona analysis definitions (soon to be published on the site) 2. Continue to explore the possibility of restructuring the various presentation filters of CWE/CAPEC content into a two-user-type model (per community suggestion – we can discuss more during the next Board meeting June 3) 3. Continue the discussion on definitions (e.g., “vulnerability”, “weakness”, “attack pattern” about which I emailed previously) Shadya will have direct involvement with the operation of the working group in terms of managing meeting agenda topics, driving working group activities, coordinating comms with the community between sessions, tracking progress on objectives, identifying other opportunities for discussion/action, etc. Lastly, as co-chair she might periodically brief the CWE/CAPEC Board with me to update you on UEWG activities. I’m very happy to welcome her into this new role. Cheers, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integration –––––––––––––––––––––––––––––––––––– MITRE - Solving Problems for a Safer World™