Incident Object Description Exchange Format Usage Guidance
RFC 8274, “Incident Object Description Exchange Format Usage Guidance”, is an Informational document published in November 2017 by P. Kampanakis, M. Suzuki. The canonical text is published by the RFC Editor.
Abstract
The Incident Object Description Exchange Format (IODEF) v2 (RFC7970) defines a data representation that provides a framework for sharing information about computer security incidents commonly exchanged by Computer Security Incident Response Teams (CSIRTs) . Since the IODEF model includes a wealth of available options that can be used to describe a security incident or issue, it can be challenging for security practitioners to develop tools that leverage IODEF for incident sharing. This document provides guidelines for IODEF implementers. It addresses how common security indicators can be represented in IODEF and use-cases of how IODEF is being used. This document aims to make IODEF's adoption by vendors easier and encourage faster and wider adoption of the model by CSIRTs around the world.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 8274 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8273 Unique IPv6 Prefix per Host
- RFC 8275 Allowing Inheritable NFSv4 Access Control Entries to Override the Umask
- RFC 8272 TinyIPFIX for Smart Meters in Constrained Networks
- RFC 8276 File System Extended Attributes in NFSv4
- RFC 8271 Updates to the Resource Reservation Protocol for Fast Reroute of Traffic Engineering GMPLS Label Switched Paths
- RFC 8277 Using BGP to Bind MPLS Labels to Address Prefixes
- RFC 8270 Increase the Secure Shell Minimum Recommended Diffie-Hellman Modulus Size to 2048 Bits
- RFC 8269 The ARIA Algorithm and Its Use with the Secure Real-Time Transport Protocol