Skip to content

Secretariat should have complete editorial control #5

@zmanion

Description

@zmanion

We very carefully and intentionally balance the CNA value proposition. Particularly for "vendor" CNAs, the CNA has significant influence (editorial control) over CVE Record content. This sometimes involves languages about "ownership." In return, the Program benefits greatly from additional and distributed resources and efficient volunteer effort, since "vendor" CNAs are the least cost avoider (most likely to know the most about the vulnerabilities affecting their products).

With this in mind, as part of the current CNA Operational Rules revision, consider adding rules that make it clear that the Program owns all the content and the Secretariat retains complete editorial and content control.

Personal opinion, we're dabbling in a lot of complexity (more JSON, ADPs) when a simpler solution may be to let the Secretariat just make changes when needed.

(from CVEProject/strategic-planning-working-group#5)

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions