Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Manager component - unclear what it is #17

Open
warrenrjwc opened this issue Nov 3, 2020 · 1 comment
Open

Manager component - unclear what it is #17

warrenrjwc opened this issue Nov 3, 2020 · 1 comment

Comments

@warrenrjwc
Copy link
Contributor

I am unclear on the manager component listed in the latest diagrams https://github.com/opencybersecurityalliance/documentation/blob/dee00b859dd2d1255fa22c05a0817420f6902518/Architecture%20Documents/SACM-container.pdf

It would seem the threat intelligence system and the configuration policy management system would directly query the repository. Can you elaborate on the management component to clarify this?

@adammontville
Copy link
Contributor

This is a good question, and one of the differences between the SCAPv2 architecture and what we've also been working on in IETF SACM. So far, the SCAPv2 community working on this architecture has put the Manager (essentially a posture assessment orchestrator) between any application relying on the and the repository itself.

I think it's probably a good idea to revisit this within the group.

That said, we do have a desire to rely on data for a certain period, and also to recognize when data is no longer reliable (i.e. it's lost its freshness). If we support direct repository interactions, then either the requester would need to handle what to do about stale information (i.e. interact with the Manager to gain fresh information), or the Repository would need to do that on behalf of the requester (i.e. the Repository would interact with the Manager to gain fresh information).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants