Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Section 6: No software, no hardware...no endpoint? #80

Open
adammontville opened this issue Jun 20, 2017 · 2 comments
Open

Section 6: No software, no hardware...no endpoint? #80

adammontville opened this issue Jun 20, 2017 · 2 comments

Comments

@adammontville
Copy link
Contributor

The paragraph above figure 15 in section 6 (and figure 15 as well) describes an endpoint as having zero or more hardware components and zero or more software components, where each may have zero or more running instances.

...the make up of an Endpoint asset which contains zero or more hardware components and zero or more software components each of which may have zero or more instances running...

This feels incorrect, because it defines an endpoint as being capable of having neither hardware nor software, but (as mentioned elsewhere in the draft) is network addressable. Is it possible to have an endpoint without hardware and without software? Even if academically so, what place does it have in our information model?

@cliffordk
Copy link

cliffordk commented Jun 20, 2017 via email

@adammontville
Copy link
Contributor Author

Hi Cliff, thanks for your response (it's been a while :-). I do not believe the paragraph in question qualifies the endpoint model to those known to SACM sensors:

   contains zero or more hardware components and zero or more software
   components each of which may have zero or more instances running an
   endpoint at any given time as well as zero or more identities that
   act on behalf of the endpoint when interfacing with other endpoints,
   tools, or services.  An endpoint may also contain other endpoints in
   the case of a virtualized environment.```

But, I take your point relative to observations from outside the bounds of the endpoint (i.e. MAC address, as your example states). In that case, I think this ticket should change from "do we need to update our model?" to "can we improve this paragraph to mention why endpoints can be modeled without hardware or software?"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants