Board Members, The CVE team would like to judge your level of interest in establishing a CVE Entry Quality Working Group. The main focus of the group would be on improving the quality of CVE entry content. The output of the group would be best practices
and guidelines on how to generate a CVE entry, and possibly propose changes to the CNA Rules.
Example issues the group could cover include:
Would the Board be interested in establishing the CVE Entry Quality Working Group, and are any Board members interested in stepping up to be the chair? Please respond by Friday Nov 30. The CVE Team |
I agree. I will be happy to participate in the discussions as well. Thank you, Gracias, Grazie, 谢谢, Merci!, Спасибо!, Bedankt,
Danke!, ありがとう, धन्यवाद! -- Kent Landfield +1.817.637.8026 From: David Waltermire <[hidden email]>
I think establishing this WG is a great idea. I'd be happy to participate. Board Members, The CVE team would like to judge your level of interest in establishing a CVE Entry Quality Working Group. The main focus of the group would be on improving the quality of CVE entry content. The output of the group would be best practices
and guidelines on how to generate a CVE entry, and possibly propose changes to the CNA Rules.
Example issues the group could cover include:
·
Should the CVSS vector be allowed in a CVE Entry description?
·
What is the best way to describe relationships between products (e.g. Product A bundles Product B)?
·
If the only public data for two different vulnerabilities would result in an identical description, what should be done? Would the Board be interested in establishing the CVE Entry Quality Working Group, and are any Board members interested in stepping up to be the chair? Please respond by Friday Nov 30. The CVE Team |
In reply to this post by Coffin, Chris
On Mon, Nov 26, 2018 at 8:32 AM Coffin, Chris <[hidden email]> wrote:
> > Board Members, > > > > The CVE team would like to judge your level of interest in establishing a CVE Entry Quality Working Group. The main focus of the group would be on improving the quality of CVE entry content. The output of the group would be best practices and guidelines on how to generate a CVE entry, and possibly propose changes to the CNA Rules. > > > > Example issues the group could cover include: > > Should the CVSS vector be allowed in a CVE Entry description? > What is the best way to describe relationships between products (e.g. Product A bundles Product B)? > If the only public data for two different vulnerabilities would result in an identical description, what should be done? > > > > Would the Board be interested in establishing the CVE Entry Quality Working Group, and are any Board members interested in stepping up to be the chair? Please respond by Friday Nov 30. > > > > The CVE Team Great idea, and I'd like to participate in this. -- Regards, Ken Williams Vulnerability Response Director, Product Vulnerability Response Team CA Technologies, A Broadcom Company, 520 Madison Av, 22nd Floor, NY NY 10022 Office: +1 631 533 7151 | Mobile: +1 816 914 4225 | [hidden email] |
In reply to this post by Coffin, Chris
On 11/26/18 9:32 AM, Coffin, Chris wrote:
> The CVE team would like to judge your level of interest in establishing a CVE Entry Quality Working Group. The main focus of the group would be on improving the quality of CVE entry content. The output of the group would be best practices and guidelines on how to generate a CVE entry, and possibly propose changes to the CNA Rules. +me please. - Art |
Please include me as well. > -----Original Message----- > From: Art Manion <[hidden email]> > Sent: Thursday, November 29, 2018 5:21 AM > To: Coffin, Chris <[hidden email]>; CVE Editorial Board Discussion <[hidden email]> > Subject: Re: CVE Entry Quality Working Group > > On 11/26/18 9:32 AM, Coffin, Chris wrote: > > > The CVE team would like to judge your level of interest in establishing a CVE Entry Quality Working Group. The main > focus of the group would be on improving the quality of CVE entry content. The output of the group would be best > practices and guidelines on how to generate a CVE entry, and possibly propose changes to the CNA Rules. > > +me please. > > - Art |
Free forum by Nabble | Edit this page |