Re: FW: WG Review: Recharter of Operational SecurityCapabilities for IP Network Infrastructure (opsec)
Ron Bonica <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <[email protected]> |
David Harrington wrote:
> Hi,
>
> Personally, I think the scope is not clearly defined. The very wide
> scope makes me concerned that this WG could be one of those that goes
> on forever, because very little seems to be out of scope.
Dan,
OPSEC is intended to be a long-lived working group. This is because
operational challenges change from year to year. When a new operational
challenge crops up, there is a distinct benefit derived from having a WG
in place with some institutional history.
OPSEC would by no means be the only long lived WG in the OPS area.
DNSOPS, V6OPS, and GROW all come to mind.
However, OPSEC scope is not unbounded. OPSEC cannot define a protocol.
Given a new operational challenge, it has only two choices:
- apply the technology at hand
- generate a requirement and toss it over the wall to another WG
>
> I am also concerned that this is no longer just focused on documenting
> best current practice, but also is taking on the task of proposals for
> new approaches to operational challenges.
I'm not sure that I understand what you are getting at. Could you be
more specific?
>
> One reason why I am concerned is that proposals for other WGs could be
> denied on the basis that whatever work somebody else wants to do on
> best current practices or new approaches to operational challenges
> could be denied because such work would already fit into the OPsec WG
> scope. I do not think one WG should claim such a large scope.
Again, I am not sure that I am following you. Could you provide an example?
Ron
>
> David Harrington
> [email protected]
> [email protected]
> [email protected]
>
>
>> -----Original Message-----
>> From: [email protected]
>> [mailto:[email protected]] On Behalf Of Romascanu, Dan (Dan)
>> Sent: Wednesday, September 03, 2008 7:20 AM
>> To: ops-area (IETF); MIB Doctors (E-mail);
>> [email protected]; IETF DNS Directorate
>> Subject: [OPS-AREA] FW: WG Review: Recharter of Operational
>> SecurityCapabilities for IP Network Infrastructure (opsec)
>>
>>
>>
>> -----Original Message-----
>> From: [email protected] [mailto:[email protected]] On
>> Behalf Of
>> The IESG
>> Sent: Tuesday, September 02, 2008 9:15 PM
>> To: [email protected]
>> Subject: WG Review: Recharter of Operational Security Capabilities
> for
>> IP Network Infrastructure (opsec)
>>
>> A modified charter has been submitted for the Operational Security
>> Capabilities for IP Network Infrastructure (opsec) working
>> group in the
>> Operations and Management Area of the IETF. The IESG has not made
> any
>> determination as yet. The modified charter is provided below for
>> informational purposes only. Please send your comments to the IESG
>> mailing list ([email protected]) by Tuesday, September 9, 2008.
>>
>> Operational Security Capabilities for IP Network
>> Infrastructure (opsec)
>> ==============================================================
>> =========
>>
>> Last Modified: 2008-08-28
>>
>> Current Status: Active Working Group
>>
>> Chair(s):
>> Joe Abley
>> Joel Jaeggli
>>
>> Operations and Management Area Director(s):
>> Dan Romascanu
>> Ronald Bonica
>>
>> Operations and Management Area Advisor:
>> Ronald Bonica
>>
>> Mailing Lists:
>> General Discussion: [email protected]
>> To Subscribe: https://www.ietf.org/mailman/listinfo/opsec
>> In Body: In Body: subscribe
>> Archive: 2008 and later:
>> http://www.ietf.org/mail-archive/web/opsec/current/maillist.html
> 2007
>> and prior: http://ops.ietf.org/lists/opsec/
>>
>> Description of Working Group:
>> Goals:
>>
>> The OPSEC WG will document best current practices with regard
>> to network
>> security. In particular an effort will be made to clarify the
>> rationale
>> supporting current operational practice, address gaps in currently
>> understood best practices for forwarding, control plane, and
>> management
>> plane security and make clear the liabilities inherent in security
>> practices where they exist.
>>
>> Scope:
>>
>> The scope of the OPSEC WG is intended to include the protection and
>> secure operation of the forwarding, control and management planes.
>>
>> Documentation of best common practices, revision of existing
>> operational
>> security practices documents and proposals for new approaches to
>> operational challenges are in scope.
>>
>> Method:
>>
>> It is expected that the work product of the working group
>> will fall into
>> the category of best current practices documents. Taxonomy or
> problem
>> statement documents may provide a basis for best current practices
>> documents.
>>
>> Best Current Practices Document
>>
>> For each topic addressed, a document will be produced that attempts
> to
>> capture current practices related to secure operation. This will be
>> primarily based on operational experience. Each entry will list:
>>
>> * threats addressed,
>> * current practices for addressing the threat,
>> * protocols, tools and technologies extant at the time of writing
> that
>> are used to address the threat,
>> * the possibility that a solution does not exist within existing
> tools
>> or technologies.
>>
>> Taxonomy and Problem Statement Documents
>>
>> A document which attempts to describe the scope of particular
>> operational security challenge or problem space without necessarily
>> coming to a conclusion or proposing a solution. Such a
>> document might be
>> a precursor to a best common practices document.
>>
>> While the principal input of the Working Group are operational
>> experience and needs, the output should be directed both to provide
>> guidance to the operators community as well as to Working Groups
> that
>> develop protocols or the community of protocol developers at large,
> as
>> well as to the implementers of these protocols.
>>
>> Non-Goals:
>>
>> The Operations security working group is not the place to do new
>> protocols.
>>
>> New protocol work should be addressed in a working group chartered
> in
>> the appropriate area or as individual submissions. The OPSEC
>> WG may take
>> on documents related to the practices of using such work.
>>
>> Goals and Milestones:
>>
>> Nov 08 - Submit a draft to the IESG regarding filtering of
>> ICMP messages
>> in the backbone
>>
>> Mar 09 - Submit a draft to the IESG regarding backbone threats and
>> mitigations
>>
>> Mar 09 - Submit a draft to the IESG regarding BGP Session Security
>> _______________________________________________
>> OPS-AREA mailing list
>> [email protected]
>> https://www.ietf.org/mailman/listinfo/ops-area
>>
>
> _______________________________________________
> OPS-AREA mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/ops-area
>