-
Type: Task
-
Status: Closed
-
Priority: Major
-
Resolution: Fixed
-
Component/s: Registration / Template Request
-
Labels:None
-
Environment:
OpenC2
Your name:
David Lemire
Project name:
Open Command and Control (OpenC2)
Project email address:
[1]openc2@lists-oasis-open.org
Work product title and version number:
OpenC2 Actuator Profile for Posture Attribute Collection Version 1.0
Work Product Abbreviation:
ap-pac
Track
Standards Track work product
Abstract:
Open Command and Control (OpenC2) is a concise and extensible language to enable machine-to-machine communications for purposes of command and control of cyber defense components, subsystems, and systems in a manner that is agnostic of the underlying products, technologies, transport mechanisms, or other aspects of the implementation. This specification defines an actuator profile to automate collection of security posture attributes from virtual and physical computing resources using OpenC2. Security Posture Attribute Collection (PAC) supports security automation by providing mechanisms to collect and aggregate the configuration and status of network components for use in situational awareness, security posture evaluation, and response actions. This actuator profile defines the OpenC2 Actions, Targets, Arguments, and Specifiers along with conformance clauses to enable the operation of OpenC2 Producers and Consumers in the context of PAC. It covers identification of computing resources, definition of security-relevant resource attributes, and controlling the collection of those attributes using direct pull or event-based push mechanisms.
Format:
Markdown
Chair(s):
Duncan Sparrell (duncan@sfractal.com), sFractal Consulting LLC
Michael Rosa (mjrosa@cyber.nsa.gov), National Security Agency
Editor(s):
David Lemire (david.lemire@hii-tsd), National Security Agency
David Kemp (d.kemp@cyber.nsa.gov), National Security Agency
Notes:
a companion request will be submitted for a version control instance
----------------------------------------------------------------------------------------
[1] openc2@lists-oasis-open.org