LLM WikiAccess-protected knowledge portal

WIKI

ISMP / Monitoring SFR — Data-Part Scope and Gaps

AI Summary Purpose Record the 2026 08 28 classification of pasted monitoring 관제 SFR items against the LabradorLabs data part collection and delivery system, and the clarification questions the data part should ask before estimating work. Ke

경로ai/wiki/projects/ismp-sfr-data-part-scope.md
카테고리Project
태그#airflow #cicd #crawler #data #data-pipeline #ismp #monitoring #mysql #part #project #report #scope #security #sfr #vulnerability

# ISMP / Monitoring SFR — Data-Part Scope and Gaps

AI Summary

Purpose:

against the LabradorLabs data-part collection and delivery system, and the clarification questions the data part should ask before estimating work.

Key points:

ISMP year-2 requirement note (Confluence 4197941878). Treat that identity as Assumption until confirmed.

(multi-source collection, CTI clause excluded), SFR-033 (per-source normalize; not a merged CVE operator workflow), SFR-035 (raw-text provenance; Korean translation is in-scope per 2026-08-09 conclusion 9, but no translator pipeline exists in the scrapers today), SFR-036 (collection metadata, not a trust-grade product).

2026-08-09 conclusion 10 / the customer-requirement note: CTI language in SFR-032/033, plus SFR-034, 036 CTI/refinement, 039, 040, 042.

asset master with business-registration numbers). Interface only.

GitLab Advisory, OpenSSF malicious-packages, OS-package Alpine/Debian/ Ubuntu, and library ecosystems. No dedicated GitHub Advisory crawler. No incident/ATT&CK knowledge base. Production cadence per source remains Needs confirmation.

XOR-scrambled header. It is not a certified 망연계 appliance, and it does not provide digital signatures, malware scanning, or verified automatic resync of a missing range. Error 110 is skip-and-advance.

Relevant when:

Do not read full document unless:

Linked documents:

Open Questions

separate monitoring document that reused the same SFR IDs: Assumption.

confirmation.

confirmation before implementation.

Needs confirmation.

Details

Role split

Internal definition of the security-data collection platform:

Crawler → Gather-DB → Dist-DB → BTS → collection monitoring
SFRData-part roleNote
031Owner of payload deliveryCertified 망연계 box and AV/signature are security/infra
032Owner of sources except CTINVD/KEV/OSV/OS-package/libraries exist; vendor-advisory/CTI list does not
033Per-source normalize onlyMerged CVE record, manual review, approver audit = ISMP
034OutIncident KB; RFP-deletion target
035Raw provenance; translation TBDIn-scope per 2026-08-09 #9; no scraper today
036Collection completeness metadataTrust grades and operator alerts = ISMP
039, 040, 042OutEngine/ISMP judgment consuming KEV/EPSS/CVSS fields
001–007OutISMP portal; vendor/product names are the only collection touchpoint

2026-08-09 conclusions that bind this split:

removed from the RFP.

The pasted 관제 text still contains the CTI sentences. Treat that as an unresolved RFP edit, not as a silent expansion of data-part scope.

Current system vs SFR

Present in labrador-scrapers / data-platform DAGs (code presence, not a freshness audit):

cpe_crawler, cvss_metric_collector, kev_crawler, epss_crawler, osv_vuln, gitlab_advisory_crawler, openssf_mal, OS-package alpine/debian/ubuntu/rhel (+ rhel_vex_crawler redesign).

crawlers.

(modified_id.csv, git diff, changes.csv/deletions.csv), TB_CRAWLER_STATUS.

XOR header, Go Updater apply.

Gaps that should not be papered over:

a completeness claim).

missing-range auto-resync. Truncation error 110 is skip-and-advance.

moved to CSAF/VEX. Resolve before implementing.

Question groups

The Korean brief carries the full 28 questions. Groups:

direct; vendor-advisory whitelist; who owns Korean translation; are KEV/EPSS “CTI” or CVE side-metrics.

binlog; AV owner; last-good-version meaning; resync of files vs collection watermarks; audit-log system of record.

role; raw retention; trust-grade scale; stale-data threshold.

RHEL OVAL vs VEX; GitLab advisories-community; daily-success definition; ISMP master-schema owner.

recycle vs keeping match keys; CVSS/EPSS/KEV snapshot vs live lookup.

Meeting one-liner (Korean, keep as-is)

데이터 파트는 외부망 수집·정규화·BTS 배포까지. 관제 SFR 중 031, 032(CTI 제외), 033(출처별 정규화), 035(원문), 036(수집 메타)만 해당. 034/039/040/042와 032·033의 CTI 문장은 8월 삭제 대상. 001–007은 ISMP 포털. 031의 전자서명·백신· 승인 구간은 망연계 제품 + 보안.