OVAL Repository Transition Update

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

OVAL Repository Transition Update

Adam Montville-2

Hi,


As you know, the OVAL Board, in cooperation with DHS and the OVAL community, has been taking steps to improve the OVAL Repository, mailing lists and OVAL language moderation in order to:

  • Make OVAL a community-run and community-sponsored program, independent of direct U.S. Government sponsorship

  • Make governance and content management more responsive and transparent

  • Upgrade the tools, technologies and processes based on lessons learned over the past decade


This note provides an update on our progress.


CIS OVAL Repository: Beta Version Available!


The CIS OVAL Repository is hosted in GitHub here.  Keep in mind that this repository is still baking!  We’re in the process of creating a website and friendly documentation that clarify exactly how to contribute and consume OVAL content from the repository.


Contributors: please review the contribution process, try it out and provide feedback!


Consumers: look for an email next week describing options for pulling content from the new repository.


CIS-sponsored OVAL Mailing Lists: Ready for Signup!


CIS has created a subdomain, lists.cisecurity.org, and has established three mailing lists as follows:


  • OVAL_Board: A list intended to be used by members of the OVAL Board for Board-related discussions.  If you are presently on the OVAL Board and desire to continue your service, there is nothing for you to do - you will be automatically added to this mailing list before the end of the month.  If, however, you would like to discontinue your service to the OVAL Board, please contact adam.montville at cisecurity.org directly.

  • OVAL_Repository: A list intended to be used for CIS OVAL Repository discussions, including discussions pertaining to repository submissions, and the subject of those submissions (i.e. vulnerabilities, configurations, inventory, and so on).  If you would like to continue on with OVAL discussions, you must subscribe to this new mailing list.

    • Subscribe to OVAL_Repository here.

  • OVAL_Developer: A list used to discuss OVAL as a language and to provide support to its implementation community. If you would like to continue on with OVAL Developer discussions, you must subscribe to this new mailing list.

    • Subscribe to OVAL_Developer here.


We are encouraging the OVAL community to use the MITRE-run (i.e. current) mailing lists for discussions pertaining to the MITRE OVAL Repository and to use the CIS-run mailing lists for discussions pertaining to the CIS OVAL Repository.


OVAL Language Moderation: Coming Soon!


The OVAL Board will share the OVAL specification moderation transition plan with the community on the mailing lists soon.  There will be plenty of opportunities for those wishing to participate in the growth of the OVAL specifications.


What To Expect Next


  • Completed

    • Experimental CIS OVAL Repository available

    • General/tentative CIS OVAL Repository submission process proposed

  • Forthcoming

    • Complete CIS OVAL Repository submission process details proposed

    • CIS OVAL Repository website to be available for testing by content consumers

    • CIS OVAL Repository submission process details revised (if necessary)

  • Target Transition Dates

    • July 31 - MITRE OVAL Repository stops accepting submissions

    • August 1 - CIS OVAL Repository submission process begins


Comments and Questions


Please feel free to post comments or questions regarding this transition to the [hidden email] or the [hidden email].


This message and attachments may contain confidential information. If it appears that this message was sent to you by mistake, any retention, dissemination, distribution or copying of this message and attachments is strictly prohibited. Please notify the sender immediately and permanently delete the message and any attachments.
. . .
To unsubscribe, send an email message to [hidden email] with SIGNOFF OVAL-DEVELOPER-LIST in the BODY of the message. If you have difficulties, write to [hidden email].