Skip to main content

Minutes interim-2019-sacm-03: Thu 14:00
minutes-interim-2019-sacm-03-201909121400-00

Meeting Minutes Security Automation and Continuous Monitoring (sacm) WG
Date and time 2019-09-12 14:00
Title Minutes interim-2019-sacm-03: Thu 14:00
State Active
Other versions plain text
Last updated 2019-10-07

minutes-interim-2019-sacm-03-201909121400-00
Agenda:
Progress on current working group items
Architecture
Information Model
Any other business
Brainstorming

Participants
Adam Montville
Henk Birkholz
Chris Inacio
Karen O'Donoghue
Ira McDonald
Kathleen Moriarty
David Waltermire

NOTES:

Architecture
	Adam reviewed changes between the 02 and 03 versions of the draft
	and requested additional review

	Kathleen asked for a timeline on the review (answer: ASAP)

	Chris pointed out a lack of specifics in the document (a general
	comment), which is where we really need to make some progress

	Adam indicated that diving deeper into the workflows would yield
	more specific results: Define components, their interfaces, and the meta
	information models required for them to communicate.

	Henk made the point that we’ve made good progress as a result of
	hackathons, and suggested that there are some base requirements on the
	Component Integration Service, ultimately proposing the idea of a quick
	“dezign team” to get together.

	“Dezign team” meeting will be held on Tuesday, 9/24 at 9:00am EDT.

Information Model

	Chris is still formulating thoughts regarding the IM, which is why
	an updated draft has not come out.

	He also mentioned that he’s looking to hire an intern to help with
	some code projects that could help inform this group

	Henk asked if the I-D source is publicly available, and if not,
	whether Chris could make it so

	Chris will make the I-D source publicly available

AOB
	SCAP 2.0 update

	Adam provided a cursory overview of the effort, noting that it seems
	that some of the vendors who initially formed SACM are also not present in
	the SCAP 2.0 efforts.

	There seems to be overlap between the two groups, and we generally
	seem to agree on the base architectural approaches allowing for different
	methods of collection

Brainstorming (led by Kathleen)