Skip to content

ConfidentialityLevelType: Add amberStrict + use ISO verbs - #1419

Open
bact wants to merge 4 commits into
spdx:developfrom
bact:dataset-amberstrict
Open

ConfidentialityLevelType: Add amberStrict + use ISO verbs#1419
bact wants to merge 4 commits into
spdx:developfrom
bact:dataset-amberstrict

Conversation

@bact

@bact bact commented Jul 22, 2026

Copy link
Copy Markdown
Collaborator

To close #1366

@henrylyons - please review

Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
@bact bact added this to the 3.1-rc2 milestone Jul 22, 2026
@bact bact added Profile:Dataset Dataset profile and related matters vocabulary labels Jul 22, 2026
bact added 2 commits July 29, 2026 20:08
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>

@bobmartin3000 bobmartin3000 left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@bact

bact commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator Author

Discussed in AI WG call. Few adjustments made during the call (reorder the entries, and removal of the word "Personal" from "red"). The definitions and added description aligned with https://www.first.org/tlp/. Approved.

@bact
bact requested a review from goneall July 30, 2026 07:53

@goneall goneall left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To avoid possible contradictions, I would suggest we just refer to the standard rather than add our own slightly different definitions.

Comment thread model/Dataset/Vocabularies/ConfidentialityLevelType.md Outdated
Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
@bact
bact requested a review from goneall July 30, 2026 19:04
@bact

bact commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator Author

To avoid possible contradictions, I would suggest we just refer to the standard rather than add our own slightly different definitions.

@goneall would you prefer something like this?

  • red: Indicates a sharing restriction equivalent to TLP:RED, as defined by the FIRST Traffic Light Protocol standard.
  • amberStrict: Indicates a sharing restriction equivalent to TLP:AMBER+STRICT, as defined by the FIRST Traffic Light Protocol standard.
  • amber: Indicates a sharing restriction equivalent to TLP:AMBER, as defined by the FIRST Traffic Light Protocol standard.
  • green: Indicates a sharing restriction equivalent to TLP:GREEN, as defined by the FIRST Traffic Light Protocol standard.
  • clear: Indicates a sharing designation equivalent to TLP:CLEAR, as defined by the FIRST Traffic Light Protocol standard.

that would do although they will be a less self-contained definition.

@bact

bact commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator Author

Also, if we strict to FIRST standard, the clients will be limited to "those people or entities that receive cybersecurity services from an organization".

The vocabulary will be less applicable to other kinds of entities.

@bact

bact commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator Author

@goneall

goneall commented Jul 30, 2026

Copy link
Copy Markdown
Member

To avoid possible contradictions, I would suggest we just refer to the standard rather than add our own slightly different definitions.

@goneall would you prefer something like this?

  • red: Indicates a sharing restriction equivalent to TLP:RED, as defined by the FIRST Traffic Light Protocol standard.
  • amberStrict: Indicates a sharing restriction equivalent to TLP:AMBER+STRICT, as defined by the FIRST Traffic Light Protocol standard.
  • amber: Indicates a sharing restriction equivalent to TLP:AMBER, as defined by the FIRST Traffic Light Protocol standard.
  • green: Indicates a sharing restriction equivalent to TLP:GREEN, as defined by the FIRST Traffic Light Protocol standard.
  • clear: Indicates a sharing designation equivalent to TLP:CLEAR, as defined by the FIRST Traffic Light Protocol standard.

that would do although they will be a less self-contained definition.

Yes - I think that would be better - but I don't feel strongly if others feel if the readability is more important than the consistency. We could also add links to the standard in the bullets to make it easier to navigate.

@bact

bact commented Jul 30, 2026

Copy link
Copy Markdown
Collaborator Author

Also, if we strict to FIRST standard, the clients will be limited to "those people or entities that receive cybersecurity services from an organization".

The vocabulary will be less applicable to other kinds of entities.

I suggest to get more feedback from the next Tech call.
Not sure if the strict adoption of FIRST will have effects on non-cybersecurity service use cases or not

@bobmartin3000

bobmartin3000 commented Jul 30, 2026 via email

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Profile:Dataset Dataset profile and related matters vocabulary

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[3.1-RC1] Add amberStrict (TLP 2.0) to ConfidentialityLevelType

4 participants