(日期:][下一个日期][线程:][线程下][日期索引][线程索引]

再保险:CVE进步



当我喜欢一个更一般的会议上,我认为我们需要关注CVE最初。之后,我们已经完成了我们需要那么我认为我们将在适当的位置有一个更通用的事件在脆弱性识别和报告和相关的工具、数据库和协调活动。史蒂夫,我喜欢涂鸦调查的想法。你可以设置,如你建议吗?我将包括三个星期,星期3月28日- 4月1日,4月11日- 15日和4月18日- 22日。建议我们应该分配3天来解决这个问题。活跃的CVE董事会成员和当前CVE团队应该目标参与者。接下来我们需要做的就是找出一个议程将是开始。我们都有一个主题列表。这将是一个有趣的锻炼的人一起把你的个人列表的关键项目你想看到解决。 This should include members of the CVE team. Then maybe, with a little correlation, we can arrive at a useful and focused agenda. --- Kent Landfield +1.817.637.8026 On 1/5/16, 3:51 PM, "Eugene H. Spafford"  wrote: >Then that is two meetings — one CVE-specific, and one more generally for >the topic area, if people want that. > > >> On Jan 5, 2016, at 4:47 PM, Landfield, Kent B >> wrote: >> >> As long as the focus would be discussing and deciding CVE related issues >> and talking about the path forward for CVE Š. That was the real purpose >> of my suggestion. We need to address the short term problems while >> planning for the long term future of CVE on a larger scale. I¹d also >>like >> to have this be restricted to the Editorial Board since they are the >>ones >> highly familiar with the existing problems and the requisite history. >> Definitely don¹t want outsiders that needs educating. That cuts into the >> time for discussions and solution development. >> --- >> Kent Landfield >> +1.817.637.8026 >> >> >> >> >> On 1/5/16, 3:34 PM, "Eugene H. Spafford" >> > gene.spafford@gmail.com> wrote: >> >>> Let me note, from a historical perspective, that CERIAS hosted a >>>workshop >>> on vulnerability databases here in January 1999. The MITRE folks >>> presented at that workshop, and decided to make their efforts public >>>as a >>> result. The CVE was ³born² in a sense as a result of that meeting, >>> although much of the work had been done prior. >>> See >>>http://www.ieee-security.org/Cipher/ConfReports/1999/CR1999-WVDB99.html> > > > > >(我也帮助组织第一次研讨会,在NIST,我记得。> > >还¹t。) > > > > > >有必要有一个后续研讨会不仅> > > CVE, > > >但是一些其他玩家的竞技场。我们可以捎带上> > > > > >年会,今年4月,这可能使它更多> > >对一些人参加。> > > > > >不过,如果我这样做,我¹d想要一些明确的> > >人们的认同,> > >包括一些谁会帮助计划。这未必是> > > > > >一样CVE编辑委员会会议,可以单独在一起> > > > > >或车间。> > > > > >喜爱spaf > > >

页面最后更新或审查:2016年1月14日,