|
|
Hi Kurt, You’ve raised 2 questions. Answering each in turn: By “swim lanes” we mean the set of products and information sources for which each CNA is responsible. They are usually only for products the CNA produces, but there may be overlaps and exceptions (such as non-vendor, third-party CNAs). A review of the current products and sources list is currently in progress and will be brought to the Board for review at a later date. As for counting, we need CNAs to dependably apply content decisions to determine the correct number of CVE IDs to assign. We’re looking to develop simpler counting rules overall, with the intent that they can be applied by a broader range of CNAs. This will also be brought to the Board in more detail when we open up the counting discussion.
The CVE Team The MITRE Corporation From: Kurt Seifried <kseifried@redhat.com>
Sent: Friday, December 11, 2015 10:52 AM To: Bergeron, Tiffany Cc: cve-editorial-board-list Subject: Re: Upcoming changes for CVE On Fri, Dec 11, 2015 at 9:46 AM, Bergeron, Tiffany
<tbergeron@mitre.org> wrote:
Internal research has led us to conclude that we must seek the Board's guidance on two issues before opening the discussion of adding CNAs: Can someone explain what "swim lanes" are in this context?
2) Discussion on a simpler counting approach What does "simpler counting approach" actually mean? Like simplifying CVE SPLIT/MERGE?
--
Kurt Seifried -- Red Hat -- Product Security -- Cloud PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 Red Hat Product Security contact: secalert@redhat.com |