[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

CNA Rules Revision Phase 2 - Week 4

NOTE: Next week's CNA Rules Revision Update will be sent on Tuesday, September 5th instead of the usual Monday due to the Labor Day holiday in the US.




We are continuing the second phase of the 2017 CNA Rules Revision process.


You can see the schedule of what issues we will be discussing each week on the Wiki section of our GitHub site:




with the issues listed in the Issue tracker:




The document from which we are starting all discussion, CNA Rules 1.1, is here:




The CURRENT NEW DRAFT, including the previous weeks' updates, is here:




The section of the GitHub site where the rules suggestions were originally tracked is here:




Each week, I will post a reminder to the CNA list of what issues we will be focusing on for that week.


Week 4


This week we will be discussing:

Week #4: August 28 - September 3

Issue Number

Add explicit how-to steps for submitting CVE entries to the Primary CNA


Make JSON the preferred format


Define how quickly CNAs are expected to submit entries after publishing an advisory


Require reporting of which reserved CVE IDs have and have not been assigned to a vulnerability


Notify requester when a CVE ID has been assigned.



You can add your thoughts or comments to the GitHub issue tracker directly. You can also discuss a particular issue on the cve-cna-list mailing list.


By the end of each week, the final language for any changes will be written. For any issues that are not resolved for that week, we will put a hold on those issues and move on to the next week's issues. The goal is to discuss the entire set of issues in the eight-week period of the review cycle. If there are outstanding issues at the end of the cycle, we can decide how to proceed as a group (including dropping the issue or setting a short deadline for resolving the issue after the review cycle).


Please let us know if you have any questions, and thank you in advance for your input into this process.






Daniel Adinolfi, CISSP

Lead Cybersecurity Engineer, The MITRE Corporation

CVE Communications and CNA Coordinator

Email: <dadinolfi@mitre.org>  Phone: 781-271-5774






Page Last Updated or Reviewed: August 28, 2017