ConfidentialityLevelType: Add amberStrict + use ISO verbs - #1419
Conversation
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
|
Discussed in AI WG call. Few adjustments made during the call (reorder the entries, and removal of the word "Personal" from "red"). The definitions and added description aligned with https://www.first.org/tlp/. Approved. |
goneall
left a comment
There was a problem hiding this comment.
To avoid possible contradictions, I would suggest we just refer to the standard rather than add our own slightly different definitions.
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
@goneall would you prefer something like this?
that would do although they will be a less self-contained definition. |
|
Also, if we strict to FIRST standard, the clients will be limited to "those people or entities that receive cybersecurity services from an organization". The vocabulary will be less applicable to other kinds of entities. |
|
Definitions in 3.0.1, for comparison: https://spdx.github.io/spdx-spec/v3.0.1/model/Dataset/Vocabularies/ConfidentialityLevelType/ |
Yes - I think that would be better - but I don't feel strongly if others feel if the readability is more important than the consistency. We could also add links to the standard in the bullets to make it easier to navigate. |
I suggest to get more feedback from the next Tech call. |
amberStrict(for TLP:AMBER+STRICT, added in TLP 2.0), as suggested by [3.1-RC1] Add amberStrict (TLP 2.0) to ConfidentialityLevelType #1366To close #1366
@henrylyons - please review