Greetings,
MITRE would like the Board's feedback on our plan for providing documentation needed to support the CNA program. These documents are for the public and CNAs. They describe CVE and the CNA program and offer guidance regarding
CNA operations.
Attached is an outline of a documentation tree. This tree shows the relationships between different documents. It also has brief descriptions of each document. This is an early draft of this documentation tree, and we will improve
the appearance and clarity of the tree for public consumption. We are sharing this version with the Board to being the process of collecting your feedback.
Is there documentation that you feel is missing?
What are the top 3 documents based on priority, in your opinion?
Based on your feedback, we will develop a schedule for completing the initial versions of these documents. For each document, we will share an outline with the appropriate group for their discussion over a week. Once a draft
is ready for review, that review period will be two weeks, and we will then have the final draft completed within two weeks of that. When the draft is finalized, it will be submitted to the Board for approval.
The Board will review general CVE documents themselves over the Board mailing list.
Documents that directly affect CNA operations will be reviewed on the cve-cna-list mailing list.
Documents that are related to automation will be reviewed on the Automation Working Group mailing list.
MITRE will maintain the document masters and act as editor. These masters will be maintained in GitHub.
Please let us know if you agree with this process. Our goal is to complete a number of documents over the next few months and bolster the CNA program and CVE in general.
Thank you.
-Dan
_________________________
Daniel Adinolfi, CISSP
Lead Cybersecurity Engineer, The MITRE Corporation
CVE Communications and CNA Coordinator
Email: <dadinolfi@mitre.org> Phone:
781-271-5774