RE: Proposed Working group and workshop

I think we need to consider how any Strategy WG output will be aligned or used to inform DHS funding and program direction. I guess that means I'm signing up.

Looks like you are indicating you are interested as well? ;-) This will be a great question to discuss during the WG calls. I see a strategic direction question there on approaches to issuance. …

Stupid Question but why are we being so stingy with CVEs? We should be handing them out like candy, and putting the "important" ones into the database (and accepting well formed database submissions from all).


Successes since March 1:

1)Regular Board Meeting Calls


3)Federated Proof of Concept with DWF conceived and successfully started

4)CVE ID Request changes with automation aspects (new web request page)



7)MITRE communication plan for introducing public CVE process changes


9)New Board member and old ones resigning

10)Newly proposed Terms of Use to include support for Description contributions

11)CNA List created for all those actually acting as a CNA

12)CNA Governance and Rules document to be released next week to the Board

We have changed our risk averse approach to CVE to one of “We are not afraid to fail. We will evolve.”


We have taken the time to change the CNA architecture from the hub and spoke model to a federated model. The DWF “proof of concept” is operational and from all apparent perspectives, successful. While there is a lot to do, it is obvious the federated CVE CNA model is here to stay.

那么,我们希望CVE在3 - 5年内看起来像什么?我们如何计划到达那里?


The purpose of the working group is to create the overall CVE strategy, identify where it is we want to go, assure we identify what is needed to create a generic new ‘root’ CNA, (get our terminology consistent), and then start addressing a tactical plan to get there. There are lots of questions we need to address. It is envisioned we will be using the CNA Rules document as one of the more foundational documents to describe the overall effort, governance and coordination processes.

I would like to ask who would like to participate? I have talked with a few of you and there seemed to be interest in the past. I will let MITRE work the mechanics of getting things set up. They get paid to do those types of things for the Board. ;-) Chris offered. ;)

Time to have the real foundational conversations needed in order to lay the ground work for the future of CVE, it’s expanded coverage and capabilities.


