Proposed action: Establishing CWE/CAPEC Crypto Working Group

2021-09-08 Thread Alec J Summers
for release in late October. Please let me know if you have any thoughts or objections to this plan of action. Cheers, Alec p.s. If you haven’t had a chance to provide feedback to the DRAFT CWE/CAPEC Board Charter, please do so by 9/13. -- Alec J. Summers Cyber Solutions Innovation Center Group Leader

Re: OWASP 2021 View

2021-09-09 Thread Alec J Summers
will definitely prioritize getting a new view up to align with this. Cheers, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research & Practice Cyber Security Engineer, Lead O: (781) 271-6970 C: (781) 496-8426 MITRE - Sol

Board Charter draft 1.1 - for review

2021-10-08 Thread Alec J Summers
/) and decide whether we wish to proceed with adopting it for our purposes in this domain or if we would like to use our own Professional Code of Conduct tailored from that of CVE. Please give me your feedback on the charter and the Code of Conduct topic by Friday, October 22. Cheers, Alec -- Alec J

Re: CWE submission form

2021-10-06 Thread Alec J Summers
://cwe.mitre.org/data/definitions/1256.html Does this help? I can get updates to the form and changed in the near future to reflect #1-3 above in the text form for now. Again, we hope to have the web-submission form available on the site soon. Cheers, Alec -- Alec J. Summers Cyber Solutions Innovation

Re: CWE submission form

2021-10-06 Thread Alec J Summers
to on the form as well): Guidelines for individual elements: https://cwe.mitre.org/community/submissions/guidelines.html#guidelines Common problems encountered with poor submissions: https://cwe.mitre.org/community/submissions/guidelines.html#problems Best, Alec -- Alec J. Summers Cyber Solutions

Board Meeting Follow-up

2021-10-05 Thread Alec J Summers
, be on the lookout for a new draft charter by the end of the week. Cheers, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research & Practice Cyber Security Engineer, Lead O: (781) 271-6970 C: (781) 496-8426 M

Re: Question about the data

2021-11-17 Thread Alec J Summers
nd: egrep '<(Weakness|Category|View).*ID="[0-9]+"' cwec_v4.6.xml | egrep 'ID="1" The total list of deprecated entries (23 weaknesses, 35 categories, and 3 views – total of 61) can be viewed here: https://cwe.mitre.org/data/definitions/604.html Best, Alec -- Alec J. Summers Cyb

Re: Question about the data

2021-11-18 Thread Alec J Summers
Kurt, Absolutely! As I said, we started some metrics work after the recent card-sorting exercise, and by that I mean the metrics are under development at this time. The team will share drafts once we have something implemented. Best, Alec -- Alec J. Summers Cyber Solutions Innovation Center

Re: Question about the data

2021-11-18 Thread Alec J Summers
leases (Q1 2022) for Status element recalibration, attribute value changes, and related updates to the content submission guidelines/form. Best, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research & Practice Cyber Security Engineer, Lead O: (7

Re: [EXT] Re: CWE/CAPEC Rest API Working Group Documentation

2022-03-04 Thread Alec J Summers
infrastructure. It is conceivable that all CWE/CAPEC code could one day be open-source, but that is not the case right now. Cheers, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research & Practice Cyber Security Engineer, Lead O: (781) 271-6970 C: (781) 496-

CWE/CAPEC Rest API Working Group Documentation

2022-02-24 Thread Alec J Summers
Hayashi (Qualcomm) so they may provide clarifications or reply to any additional questions directly in this thread. Cheers, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research & Practice Cyber Security Engineer, Lead O: (781) 271-6970 C: (781)

Re: Question about https://cwesubmission.mitre.org/

2022-03-01 Thread Alec J Summers
an we make this more public so people don't submit duplicates, or if there are similar ones already in the works we can see it? * Yes, that is our plan. We hope that the overall quality of submissions will be improved by public review in the early stages. Best, Alec -- Alec J. Summers Cyber

Re: [EXT] Re: CWE/CAPEC Rest API Working Group Documentation

2022-03-01 Thread Alec J Summers
Kurt, Thanks for your note. This was a question that Adam et al answered in the document I shared on 2/24. In short, the working group would start working towards a REST API to start. Best, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research

Re: [EXT] Re: CWE/CAPEC Rest API Working Group Documentation

2022-03-01 Thread Alec J Summers
Clarification: “working on read access to start.” Apologies for the miscommunication. Cheers, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research & Practice Cyber Security Engineer, Lead O: (781) 271-6970 C: (781) 496-

Re: [EXT] Re: CWE/CAPEC Rest API Working Group Documentation

2022-03-01 Thread Alec J Summers
. Cheers, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research & Practice Cyber Security Engineer, Lead O: (781) 271-6970 C: (781) 496-8426 MITRE - Solving Problems for a Safer World From: Jason Oberg Date: Fr

FW: CWE/CAPEC Board Update and Meeting Availability

2022-01-19 Thread Alec J Summers
has left the MITRE Corporation. As we look to have someone else step into her communications role on CWE/CAPEC, you may be getting some more emails from me directly. Cheers, Alec -- Alec J. Summers Cyber Solutions Innovation Center Group Leader, Software Assurance Research & Practice C

Re: CWE/CAPEC Board Update and Meeting Availability

2022-01-19 Thread Alec J Summers
Kurt, Thanks for your note. I appreciate the challenges you are facing. Is this resolvable at all by choosing a different day of the week/time of day? Or, is this going to be a problem in general henceforth until the school year ends? Thanks, Alec -- Alec J. Summers Cyber Solutions

Re: Scheduling: Q3-2023 CWE Board Meeting

2023-09-05 Thread Alec J Summers
Good morning! I hope everyone had a great weekend. Just a soft reminder to please fill out the doodle poll so that we can finalize a date/time. Thanks to all who have already done so. Cheers, Alec -- Alec J. Summers Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations

Re: CWE to SQLite w/ Database

2023-09-08 Thread Alec J Summers
Wrong email thread :-) The message below was intended for the c...@mitre.org<mailto:c...@mitre.org> handle. Hope everyone has a great weekend! Cheers, Alec -- Alec J. Summers Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integration Center for Se

Scheduling: Q3-2023 CWE Board Meeting

2023-08-30 Thread Alec J Summers
, Jeremy’s proposal for discussing a multiyear look-ahead and plan, the public submissions repository, and activities in the vulnerability mapping domain). Please let me know if you have other thoughts about agenda topics. Cheers, Alec -- Alec J. Summers Cyber Security Engineer, Principal Group

Re: special hyphen breaks form

2022-05-17 Thread Alec J Summers
Kurt, Thanks for the note on this. We are actively working to replicate and troubleshoot. Separately, we will be following up on the successful submission. Cheers, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity

UEWG co-chair

2022-05-26 Thread Alec J Summers
sessions, tracking progress on objectives, identifying other opportunities for discussion/action, etc. Lastly, as co-chair she might periodically brief the CWE/CAPEC Board with me to update you on UEWG activities. I’m very happy to welcome her into this new role. Cheers, Alec -- Alec J

Glossary

2022-05-24 Thread Alec J Summers
to compare is attached. The plan would be to unify the definitions according to the above across all our sites. Would love to hear your thoughts. Cheers, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations

Re: Question: what happened to fields like "Modes of introduction"

2022-05-16 Thread Alec J Summers
second heading: External Submissions Review Process – there’s a table there with each stage). Hope that helps. Cheers, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integ

Re: Some questions on expectations of CNAs

2022-07-07 Thread Alec J Summers
Jeremy, Thanks for your note. This is a great topic for a larger discussion, I believe. But till then… elements of your email point more directly to CVMAP and questions that perhaps @Turner, Christopher<mailto:christopher.tur...@nist.gov> could answer best. Cheers, Alec -- Alec J. S

Re: [EXT] RE: Glossary

2022-07-11 Thread Alec J Summers
feedback, after which we can formally the terms in the CWE and CAPEC glossaries. Are there any objections to this course of action? If not, I will send out notes to the listservs by midweek. Cheers, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer

Re: [EXT] RE: Glossary

2022-07-13 Thread Alec J Summers
all. Cheers, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integration MITRE - Solving Problems for a Safer World™ From: SJ Jazz Date: Tuesday, July 12, 2022 at 4

CWE 4.7 Now Available!

2022-04-29 Thread Alec J Summers
are CWE SIG<http://cwedev1-mcl.mitre.org/documents/HW_CWE_SIG.pdf> discussions We are really excited about this release, and we look forward to you diving into the new content. On behalf of the CWE Program, thank you for your continued support. Cheers, Alec -- Alec J. Summers Center for S

Re: Doodle Poll: Next CWE/CAPEC Board Meeting

2022-09-01 Thread Alec J Summers
Just a soft reminder on the scheduling poll below. Thanks for all members that have responded to the poll already. -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integration

Doodle Poll: Next CWE/CAPEC Board Meeting

2022-08-31 Thread Alec J Summers
, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integration MITRE - Solving Problems for a Safer World™

Reminder: CWE/CAPEC Board Meeting

2022-09-28 Thread Alec J Summers
Just a soft reminder that we will be holding our next quarterly CWE/CAPEC Board meeting tomorrow afternoon from 2-4pm ET. Please let me know if you need me to forward the meeting invite again. Hope to see you there! Best, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber

Re: are parent relationships required for new entries?

2022-08-11 Thread Alec J Summers
publish a new one at the same time. Happy to talk more on this in advance of the Fall Board meeting. Looking forward to the discussion! Cheers, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integration

FW: are parent relationships required for new entries?

2022-08-09 Thread Alec J Summers
Kurt, Please direct emails regarding submissions to c...@mitre.org<mailto:c...@mitre.org>, not the Board email list. Thank you. Cheers, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integ

Fw: abstraction guidelines for CWE entries

2022-12-01 Thread Alec J Summers
Board members, Good morning - I hope you are all well. I am forwarding a message from Kurt that inadvertently failed to proceed through our listserv moderation process during the holiday week. Please see below... Cheers, Alec From: Seifried, Kurt Sent:

CWE Community Group Leadership Announcements

2023-02-02 Thread Alec J Summers
updates on ICS-OT SIG activities. The team is very happy to welcome both Rogue and Matt as they step into these important roles. Best, Alec -- Alec J. Summers Center for Securing the Homeland (CSH) Cyber Security Engineer, Principal Group Lead, Cybersecurity Operations and Integration