[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

CNA Rules Revision Phase 2 - Week 1



We have begun the second phase of the 2017 CNA Rules Revision process.


You can see the schedule of what issues we will be discussing each week on the Wiki section of our GitHub site:




with the issues listed in the Issue tracker:




The document from which we are starting all discussion, CNA Rules 1.1, is here:




The section of the GitHub site where the rules suggestions were originally tracked is here:




Each week, I will post a reminder to the CNA list of what issues we will be focusing on for that week.


Week 1


This week we will be discussing:


Week #1: August 7-13

Issue Number

Define hardware


Update definitions


Define when an entry should be marked as disputed versus rejected


Fix typo in 2.2.9


Use terminology as defined by RFC 2119 (MUST, SHOULD, MAY)


Remove "to the greatest level of detail available" from the Appendix B



You can add your thoughts or comments to the GitHub issue tracker directly. You can also discuss a particular issue on the cve-cna-list mailing list.


By the end of each week, the final language for any changes will be written. For any issues that are not resolved for that week, we will put a hold on those issues and move on to the next week's issues. The goal is to discuss the entire set of issues in the eight-week period of the review cycle. If there are outstanding issues at the end of the cycle, we can decide how to proceed as a group (including dropping the issue or setting a short deadline for resolving the issue after the review cycle).


Please let us know if you have any questions, and thank you in advance for your input into this process.






Daniel Adinolfi, CISSP

Lead Cybersecurity Engineer, The MITRE Corporation

CVE Communications and CNA Coordinator

Email: <dadinolfi@mitre.org>  Phone: 781-271-5774



Page Last Updated or Reviewed: August 09, 2017