A new version of our draft was uploaded to Datatracker last week which, we believe, addresses the comments raised during Working Group Last Call. Please do take a look and let us know if more clarification on those points would be helpful.
Thanks, Andrew -----Original Message----- From: OPSEC <opsec-boun...@ietf.org> On Behalf Of internet-dra...@ietf.org Sent: 12 September 2022 15:56 To: i-d-annou...@ietf.org Cc: opsec@ietf.org Subject: [OPSEC] I-D Action: draft-ietf-opsec-indicators-of-compromise-02.txt A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Operational Security Capabilities for IP Network Infrastructure WG of the IETF. Title : Indicators of Compromise (IoCs) and Their Role in Attack Defence Authors : Kirsty Paine Ollie Whitehouse James Sellwood Andrew Shaw Filename : draft-ietf-opsec-indicators-of-compromise-02.txt Pages : 29 Date : 2022-09-12 Abstract: Cyber defenders frequently rely on Indicators of Compromise (IoCs) to identify, trace, and block malicious activity in networks or on endpoints. This draft reviews the fundamentals, opportunities, operational limitations, and best practices of IoC use. It highlights the need for IoCs to be detectable in implementations of Internet protocols, tools, and technologies - both for the IoCs' initial discovery and their use in detection - and provides a foundation for new approaches to operational challenges in network security. The IETF datatracker status page for this draft is: https://datatracker.ietf.org/doc/draft-ietf-opsec-indicators-of-compromise/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-ietf-opsec-indicators-of-compromise-02.html A diff from the previous version is available at: https://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-indicators-of-compromise-02 Internet-Drafts are also available by rsync at rsync.ietf.org::internet-drafts _______________________________________________ OPSEC mailing list OPSEC@ietf.org https://www.ietf.org/mailman/listinfo/opsec This information is exempt under the Freedom of Information Act 2000 (FOIA) and may be exempt under other UK information legislation. Refer any FOIA queries to ncscinfo...@ncsc.gov.uk. All material is UK Crown Copyright (c) _______________________________________________ OPSEC mailing list OPSEC@ietf.org https://www.ietf.org/mailman/listinfo/opsec