Skip to content

Consider future policy related to IRG Appendix #194

Description

@ryancdickson

In response to the recent publication of Version 3 of the CCADB Incident Reporting Guidelines (IRGs), the CCADB Steering Committee (CCADB SC) was asked whether it was permissible to extend the set of Appendix fields beyond those described on CCADB.org.

After discussion, the CCADB SC agreed doing so was permissible. An example use case used to justify this conclusion was related to adding an "iPAddresses" field to complement the existing "dNSNames" field (with the iPAddresses field being especially compelling when the corresponding certificate is missing a dNSName).

For the time being, we have not identified a need to define requirements related to the specific ordering of elements in the Appendix, should additional fields be provided in response to an incident report.

If this view changes in the future, it'll be explored in this Issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions