Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update of 040 - Remediation & Mitigation #57

Merged
merged 6 commits into from
Oct 30, 2020
Merged

Update of 040 - Remediation & Mitigation #57

merged 6 commits into from
Oct 30, 2020

Conversation

laurie-tyz
Copy link
Contributor

There should be a footnote/endnote for the DoD I 8531.01

Changed the title Coordinating Patches to Scheduling Patches.

consider the first 2 paragraphs under Scheduling Patches. Should they be moved to an earlier part of the paper or removed?

Open to suggestions and discussions.

Laurie

Copy link
Collaborator

@j--- j--- left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comments in-line.


<!--**Talk about applying other mitigations here** TODO
-->
To further clairify terms, "Remediaton occurs when the vulnerability is eliminated or removed. Mitigation occurs when the impact of the vulnerability is decreased without reducing or eliminating the vulnerability." (DoD Instruction 8531.01, section 3.5) Examples of remediation includes, applying patches, fixes and upgrades; or removing the vulnerabil software or system from operation. Mitigating acions may include, software configuration changes, adding firewall ACLs or otherwise limiting the system's exposure to reduce the risk of the impact of the vulnerability; or accepting the risk.
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done

doc/version_1/040_treesForVulMgmt.md Outdated Show resolved Hide resolved
| Scheduled | Act during regularly scheduled maintenance time. |
| Out-of-cycle | Act more quickly than usual to apply the fix out-of-cycle, during the next available opportunity, working overtime if necessary. |
| Immediate | Act immediately; focus all resources on applying the fix as quickly as possible, including, if necessary, pausing regular organization operations. |

### Coordinating Patches
### Scheduling Patches
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What's the intent here?
We are working on the coordinator's decision tree (#11 ). So this section will be re-written as a result of that issue.
I don't think this term change supports that issue, does it?
"Patches" here probably needs to be changed to "mitigation" based on #46? Unless it specifically just means a fix, but I think "patch" here is an error in v1 and we want to say "coordinating mitigations" as what a Coordinator stakeholder does, so we are general enough. Is that right?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The title is "coordinating patches" The first 2 paragraphs speak to problems CVD and CVSS. The third talks about how to schedule your patch action when you have multiple patches with varying priorities.

Maybe the "Scheduling Patches" title should be above the last paragraph.

@laurie-tyz laurie-tyz changed the title Updat of 040 - Remediation & Mitigation Update of 040 - Remediation & Mitigation Oct 30, 2020
@laurie-tyz laurie-tyz merged commit 9d59468 into CERTCC:main Oct 30, 2020
@ahouseholder ahouseholder added this to the SSVC v2 milestone Nov 13, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants