The document shepherd is Brian Trammell. The responsible Area Director is Sean
The document extends the Incident Object Description Exchange Format (IODEF)
defined in RFC 5070 [RFC5070] to exchange enriched cybersecurity information .
It provides the capability of embedding structured information, such as
identifier- and XML-based information. It defines an IANA registry of external
schemas that can be referenced from IODEF documents.
2. Review and Consensus
The document received extensive review from the working group, which led to
significant changes in the document. Earlier versions of the document had
significant potential IPR issues (references to trademarked schema names) as
well as reference issues (normative references to non-standards documents);
these have all been resolved satisfactorily by moving these references to an
IANA registry of SCI specifications, and providing for long-term references to the MTI schema, MMDEF.
3. Intellectual Property
Each author has confirmed conformance with BCP 78/79.
Sean Turner, sponsoring AD, filed IPR disclosures 1786 and 1787 on this
document on behalf of the IPR owners. 1787 regarding NIST IPR has been
withdrawn. 1786 indicates that the names of MITRE documents which were
previously referenced by this document are trademarked. In any case, MITRE has
indicated to the firstname.lastname@example.org list that it is willing to grant license for
purposes of interoperability should these schemas be added to the resulting
IANA registry, and the schemas themselves have been removed from the present
revision of the document in any case.
4. Other Points
The document creates an IANA registry for schemas to be referenced from IODEF
subject to expert review and specification required, specifying only one such
schema as MTI. The intention is to add additional schemas after the publication
of the document.