Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FIRST services framework #314

Open
j--- opened this issue Sep 26, 2023 · 2 comments
Open

FIRST services framework #314

j--- opened this issue Sep 26, 2023 · 2 comments
Labels
documentation Improvements or additions to documentation enhancement New feature or request

Comments

@j---
Copy link
Collaborator

j--- commented Sep 26, 2023

Service area 3 is about vulnerability triage for PSIRTs
https://www.first.org/standards/frameworks/psirts/psirt_services_framework_v1.1

Service area 7.2.2 is about CSIRT vulnerability triage
https://www.first.org/standards/frameworks/csirts/csirt_services_framework_v2.1#7-2-Service-Vulnerability-report-intake

SSVC may be in a position to be providing additional detail about these areas. I don't think we're overlapping, but if we are in fact providing additional detail to things listed in the PSIRT and CSIRT services frameworks, we should reach out to FIRST to coordinate and see if they agree and want to link to SSVC documentation for additional detail.

@ahouseholder
Copy link
Contributor

ahouseholder commented Sep 27, 2023

Need to digest the services frameworks in more detail, but I could imagine one way to represent this could be to do a cross-walk table similar to what we did with Vultron and various vulnerability disclosure ISO docs:

@j---
Copy link
Collaborator Author

j--- commented Oct 3, 2023

Something like this, yes.
In this case, I think we also have the opportunity to chat with the FIRST framework authors and get their feedback after we draft it.

@ahouseholder ahouseholder added documentation Improvements or additions to documentation enhancement New feature or request labels Oct 19, 2023
@ahouseholder ahouseholder removed this from the SSVC 2023Q4 milestone Jan 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants