{"id":377,"date":"2023-03-12T19:51:16","date_gmt":"2023-03-12T19:51:16","guid":{"rendered":"https:\/\/idmefv2.org\/?page_id=377"},"modified":"2023-03-30T09:14:05","modified_gmt":"2023-03-30T09:14:05","slug":"ietf-standard-process","status":"publish","type":"page","link":"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/","title":{"rendered":"IETF Standard process"},"content":{"rendered":"\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-right counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/#Introduction\" >Introduction<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/#IETF_Internet_Engineering_Task_Force\" >IETF : Internet Engineering Task Force<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/#RFC_Request_For_Comments\" >RFC : Request For Comments<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/#Types_of_RFCs\" >Types of RFCs<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/#Number_of_published_RFCs_March_2023\" >Number of published RFCs (March 2023)<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/#Publication_process_the_big_picture\" >Publication process : the big picture<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/#Standard_process\" >Standard process<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/#Working_Group_Creation\" >Working Group Creation<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Introduction\"><\/span>Introduction<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The ultimate goal of the IDMEFv2 Task Force is to publish one or more IETF RFCs about IDMEFv2. The process of standardization is long and complex. It&#8217;s also very unsure as hopefully not all proposition are accepted. Not all RFCs are equivalent, depending on the maturity of the standards described:   proposed standards, drafts standards RFCs , internet standards RFCs ,informational RFCs, experimental RFCs, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, IDMEFv2 is a very new format, it is still experimented, it needs to be more experimented. IDMEFv2 propose a solution to upcoming problems with convergence of cybersecurity and physical security. So out goal is not to define a final Internet Standards but to document a detailed format so people can use it, improve it and maybe one day end up with a real internet standard.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although IETF working groups have been working on IDMEFv1, IODEF (Incident Object Definition Exchange Format) V1 and more recently V2, most of the standards defined by IETF are protocols. IDMEF is definitely a format and the transport is not very important and can be of multiple type (HTTP, Kafka, AMQP, etc.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2020 an official Charter (which aimed a cyber format with inclusion of IoT) has been sent to IETF. At the same date we started collaboration with the 7Shield project an its cyber and physical needs. The decision was taken at the time to consolidate a first draft of a cyber-physical incident format then to go back to IETF to start standardization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This time has come, V01 draft should be ready pretty soon (T2 2023)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The rest of this page details the way IETF works to prepare the next step of our work.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"IETF_Internet_Engineering_Task_Force\"><\/span>IETF : Internet Engineering Task Force<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Internet Engineering Task Force (IETF) is a large open community of network designers, operators, vendors, and researchers who are dedicated to the evolution and smooth operation of the Internet. It is an international organization that develops and promotes Internet standards, protocols, and procedures through a consensus-driven process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The IETF&#8217;s mission is to make the Internet work better by producing high-quality, relevant technical documents that influence the way people design, use, and manage the Internet. The IETF has a number of working groups that focus on specific technical areas such as routing, security, and applications, as well as cross-cutting areas such as architecture and management. These working groups develop Internet standards and protocols through an open, collaborative process that involves input and feedback from experts and stakeholders around the world.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The IETF has been in existence since 1986 and has played a critical role in the development of the Internet as we know it today. Its contributions include the development of key Internet protocols such as TCP\/IP, HTTP, and SMTP, as well as many other standards and guidelines that are widely used by network designers, operators, and users.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"RFC_Request_For_Comments\"><\/span>RFC : Request For Comments<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An RFC (Request for Comments) is a document published by the Internet Engineering Task Force (IETF) that describes a proposed standard, protocol, or other technical topic related to the Internet. RFCs are the primary means by which the IETF develops and publishes technical specifications and standards for the Internet. RFCs are numbered sequentially, and each RFC has a unique number that identifies it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RFCs may describe a wide range of topics, including networking protocols, Internet architecture, security standards, and other technical subjects. They may be authored by individuals, groups, or organizations within or outside of the IETF. RFCs are generally reviewed and commented on by the broader Internet community before they are finalized, and they may be revised and updated over time as new information or requirements emerge.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Types_of_RFCs\"><\/span>Types of RFCs<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There are several types of Request for Comments (RFCs) published by the Internet Engineering Task Force (IETF). The different types of RFCs are used to categorize and differentiate between different types of documents, depending on their purpose and status. Some of the most common types of RFCs are:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Standards Track RFCs:<\/strong> These RFCs define protocols, procedures, or conventions that are intended to be implemented and widely deployed on the Internet. Standards Track RFCs are further divided into several categories, including:<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Proposed Standard RFCs<\/strong>: These RFCs describe a protocol or specification that is well understood and has been reviewed by the IETF community, but may still undergo some changes before being widely deployed.<\/li>\n\n\n\n<li><strong>Draft Standard RFCs<\/strong>: These RFCs describe a protocol or specification that is believed to be stable and ready for implementation, but may still be revised based on implementation experience.<\/li>\n\n\n\n<li><strong>Internet Standard RFCs<\/strong>: These RFCs describe a protocol or specification that has been widely implemented and is considered stable and mature.<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\">\n<li><strong>Informational RFCs<\/strong>: These RFCs provide information, guidance, or best practices on a particular topic, but are not intended to define a standard or protocol.<\/li>\n\n\n\n<li><strong>Experimental RFCs<\/strong>: These RFCs describe a protocol or specification that is being tested or evaluated, and may not be suitable for deployment in production environments.<\/li>\n\n\n\n<li><strong>Historic RFCs<\/strong>: These RFCs describe a protocol or specification that was once widely used but is now obsolete or no longer in use.<\/li>\n\n\n\n<li><strong>Best Current Practice (BCP) RFCs<\/strong>: These RFCs describe a best practice or guideline for a particular aspect of Internet architecture or operation.<\/li>\n\n\n\n<li><strong>Independent Submission RFCs<\/strong>: These RFCs are submitted by individuals or organizations outside of the IETF, and may describe a proposed standard or other technical topic related to the Internet.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Number_of_published_RFCs_March_2023\"><\/span>Number of published RFCs (March 2023) <span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Although IETF exists since since 1986 (nearly 40 years) the number of published RFCs is not so high, specially for (final) Internet Standard, a little bit more than one hundred.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Standards Track RFCs:<\/li>\n<\/ol>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Proposed Standard RFCs: Approximately 3980<\/li>\n\n\n\n<li>Draft Standard RFCs: Approximately 139<\/li>\n\n\n\n<li>Internet Standard RFCs: Approximately 129 (HTTP, SMTP, NTP, FTP, etc.)<\/li>\n<\/ul>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\">\n<li>Informational RFCs: Approximately 2861<\/li>\n\n\n\n<li>Experimental RFCs: Approximately 530 (Note : IDMEFv1 (RFC 4765) is an experimental RFC published in 2007)<\/li>\n\n\n\n<li>Historic RFCs: Approximately 388<\/li>\n\n\n\n<li>Best Current Practice (BCP) RFCs: Approximately 312<\/li>\n\n\n\n<li>Independent Submission RFCs: Approximately 500<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The Security Area has published 629 RFCs, only 8 are Internet Standards.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Publication_process_the_big_picture\"><\/span>Publication process : the big picture<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Internet Drafts can be submitted by individuals or IETF working group. <\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"850\" height=\"366\" src=\"https:\/\/idmefv2.org\/wp-content\/uploads\/2023\/03\/image-1.png\" alt=\"\" class=\"wp-image-378\" srcset=\"https:\/\/www.idmefv2.org\/wp-content\/uploads\/2023\/03\/image-1.png 850w, https:\/\/www.idmefv2.org\/wp-content\/uploads\/2023\/03\/image-1-300x129.png 300w, https:\/\/www.idmefv2.org\/wp-content\/uploads\/2023\/03\/image-1-768x331.png 768w\" sizes=\"auto, (max-width: 850px) 100vw, 850px\" \/><figcaption class=\"wp-element-caption\">The IETF Publication Process<\/figcaption><\/figure>\n<\/div>\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Standard_process\"><\/span>Standard process<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The process for defining a new standard at the Internet Engineering Task Force (IETF) typically involves the following steps:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Proposal: A proposal for a new standard is first submitted to the IETF, typically in the form of an Internet-Draft. The proposal should describe the problem that the standard is intended to solve, the proposed solution, and any related protocols or technologies.<\/li>\n\n\n\n<li>Working Group: The proposal is reviewed by the appropriate working group within the IETF. Working groups are typically made up of volunteers who are experts in the relevant area, and who collaborate to refine and develop the proposal.<\/li>\n\n\n\n<li>Drafting: The proposal is then developed into a more detailed specification in the form of an Internet-Draft. This may involve several iterations of review and revision by the working group.<\/li>\n\n\n\n<li>Last Call: Once the Internet-Draft is considered complete by the working group, it is sent out for &#8220;last call&#8221; review. This means that the proposed standard is open to review and comment by anyone in the IETF community.<\/li>\n\n\n\n<li>IESG Review: After the last call period is over, the proposal is reviewed by the Internet Engineering Steering Group (IESG), which is responsible for approving or rejecting proposed standards. The IESG may request further revisions, or may approve the standard for publication as a Request for Comments (RFC).<\/li>\n\n\n\n<li>RFC Publication: Once approved, the standard is published as an RFC. RFCs are the official documents that define Internet standards, and they are freely available to the public.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s worth noting that the standardization process can take several years, and there is no guarantee that a proposed standard will be accepted. However, the IETF is committed to an open and transparent process, and all participants are encouraged to contribute their expertise and opinions to help shape the future of the Internet.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Working_Group_Creation\"><\/span>Working Group Creation<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The process of creating a new working group (WG) within the Internet Engineering Task Force (IETF) typically involves the following steps:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Proposal: A proposal for a new working group is first submitted to the IETF. The proposal should describe the problem or topic that the working group is intended to address, and should identify the individuals who will serve as chairs of the working group.<\/li>\n\n\n\n<li>Charter: If the proposal is accepted, a charter for the new working group is drafted. The charter should specify the goals, scope, and deliverables of the working group, as well as any milestones or deadlines. The charter should also define the working group&#8217;s relationship to other IETF groups and to external organizations.<\/li>\n\n\n\n<li>Approval: The charter is reviewed and approved by the Internet Engineering Steering Group (IESG), which is responsible for the overall management of the IETF. The IESG may request revisions to the charter before approving it.<\/li>\n\n\n\n<li>Call for Participation: Once the charter is approved, a call for participation is issued to the IETF community. Anyone who is interested in contributing to the working group&#8217;s efforts can join the group and participate in its activities.<\/li>\n\n\n\n<li>Working Group Meetings: The working group meets regularly, either in person or via teleconference, to discuss and develop its work. The chairs are responsible for managing the working group&#8217;s activities, and for ensuring that the group stays on track with its goals and milestones.<\/li>\n\n\n\n<li>Deliverables: The working group produces one or more deliverables, which may include Internet-Drafts, Request for Comments (RFCs), or other documents. These deliverables are reviewed and approved by the IESG before being published as official IETF standards.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Creating a new working group can take several months, and the process requires a significant amount of effort and coordination. However, working groups are an essential part of the IETF&#8217;s standardization process, and they provide a forum for experts to collaborate and address complex technical challenges in the Internet ecosystem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Conclusion<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Standardization process is long and uncertain. However, the IDMEFv2 task Force has produced a part of the way with the two published drafts. It needs more work and modification but it&#8217;s been already proven it&#8217;s working. As explained above, the final goal won&#8217;t be a &#8220;final&#8221; Internet Standard anyway, a good objective would probably be Experimental RFCs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction The ultimate goal of the IDMEFv2 Task Force is to publish one or more IETF RFCs about IDMEFv2. The process of standardization is long and complex. It&#8217;s also very unsure as hopefully not all proposition are accepted. Not all RFCs are equivalent, depending on the maturity of the standards described: proposed standards, drafts standards&hellip;&nbsp;<a href=\"https:\/\/www.idmefv2.org\/index.php\/ietf-standard-process\/\" rel=\"bookmark\">Read More &raquo;<span class=\"screen-reader-text\">IETF Standard process<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","footnotes":""},"class_list":["post-377","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.idmefv2.org\/index.php\/wp-json\/wp\/v2\/pages\/377","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.idmefv2.org\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.idmefv2.org\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.idmefv2.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.idmefv2.org\/index.php\/wp-json\/wp\/v2\/comments?post=377"}],"version-history":[{"count":3,"href":"https:\/\/www.idmefv2.org\/index.php\/wp-json\/wp\/v2\/pages\/377\/revisions"}],"predecessor-version":[{"id":454,"href":"https:\/\/www.idmefv2.org\/index.php\/wp-json\/wp\/v2\/pages\/377\/revisions\/454"}],"wp:attachment":[{"href":"https:\/\/www.idmefv2.org\/index.php\/wp-json\/wp\/v2\/media?parent=377"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}