Scope Material

for

Software Facts

Nothing can satisfy everybody's needs. To do anything meaningful, we must choose our audiences, classes of products or services, and goals. This page lists some possibilities.

Audiences

The following three audiences were selected at the DHS Software Assurance working group meeting, Arlington, VA, July 2008.

Product Classes

Operating systems, email programs, and solitaire card games probably need quite different information. We haven't thought about classes as much. Perhaps they should be organized by threat classes. For instance an on-line game may need more security information than a sophisticated 3D modeling application that never uses the Internet. Services or downloaded software may be additional classes or concerns.

Goals

What should these facts accomplish? We should be clear about why we're even doing this. Anti-goals, that is, this is not meant to

Means, or, Criteria

Related to goals, we can express possible criteria for the set of software facts as a whole.

The following criteria were considered, but almost unanimously rejected (DHS SwA working group meeting, Arlington, VA, July 2008).

The Process of Software Facts

A software developer might obtain a set of software facts many different ways.

Terminology

We want to convey the correct perception of this work, or at least minimize (undue) negative reactions. The DHS Software Assurance working group (Arlington, VA, July 2008) overwhelming and generally approved simply "software facts" as a name for this effort. Here are other terms brought up.

All the facts together need a collective name. "Label" has many negative connotations, as the above vote shows. Other possible terms are "set", "collection", and "digest".


Up to the software facts main page

Created Mon Aug 4 12:37:25 2008

by Paul E. Black  (paul.black@nist.gov)

Updated Thu Feb 28 15:29:55 2013

by Paul E. Black  (paul.black@nist.gov)

Information Technology Laboratory, Software and Systems Division
PRIVACY/SECURITY ISSUESFOIADisclaimerUSA.gov
NIST is an agency of the U.S. Commerce Department

This page's URL is http://hissa.nist.gov/~black/SoftwareFacts/possibleScope.html