# ISMP / Monitoring SFR — Data-Part Scope and Gaps
AI Summary
Purpose:
- Record the 2026-08-28 classification of pasted monitoring (관제) SFR items
against the LabradorLabs data-part collection and delivery system, and the clarification questions the data part should ask before estimating work.
Key points:
- The user labeled the paste as 관제. The SFR IDs match the Mirae Academy
ISMP year-2 requirement note (Confluence 4197941878). Treat that identity as Assumption until confirmed.
- Data-part core: SFR-031 (delivery over the air-gap path), SFR-032
(multi-source collection, CTI clause excluded), SFR-033 (per-source normalize; not a merged CVE operator workflow), SFR-035 (raw-text provenance; Korean translation is in-scope per 2026-08-09 conclusion 9, but no translator pipeline exists in the scrapers today), SFR-036 (collection metadata, not a trust-grade product).
- Out of data-part scope, and already listed as RFP-deletion targets on
2026-08-09 conclusion 10 / the customer-requirement note: CTI language in SFR-032/033, plus SFR-034, 036 CTI/refinement, 039, 040, 042.
- SFR-001..007 are ISMP portal features (SBOM recycle, SPDX validation,
asset master with business-registration numbers). Interface only.
- Current crawlers cover NVD JSON feed, CVE API, CPE, CVSS, KEV, EPSS, OSV,
GitLab Advisory, OpenSSF malicious-packages, OS-package Alpine/Debian/ Ubuntu, and library ecosystems. No dedicated GitHub Advisory crawler. No incident/ATT&CK knowledge base. Production cadence per source remains Needs confirmation.
- SFR-031 does not match production BTS: BTS ships ROW binlog files with an
XOR-scrambled header. It is not a certified 망연계 appliance, and it does not provide digital signatures, malware scanning, or verified automatic resync of a missing range. Error 110 is skip-and-advance.
Relevant when:
- Scoping data-part work on the ISMP year-2 collection platform.
- Preparing clarification questions against SFR-031..042 and SFR-001..007.
- Checking what the 2026-08-09 meeting already decided to exclude.
Do not read full document unless:
- The full question list or the per-SFR gap table is needed.
Linked documents:
human/briefs/2026-08-28-sfr-data-part-gap-questions.md(Korean meeting brief)ai/sources/rfp/2026-08-28-vuln-monitoring-sfr-excerpt.mdai/wiki/projects/vulnerability-collection.mdai/wiki/projects/crawler-source-governance.mdai/wiki/projects/bts.mdai/wiki/projects/rhel-vex-vuln-collection.mdai/repo-notes/labrador-scrapers.mdai/worklog/2026/2026-W35.md
Open Questions
- Whether the pasted 관제 excerpt is the ISMP year-2 functional spec, or a
separate monitoring document that reused the same SFR IDs: Assumption.
- Whether the 2026-08-09 CTI-deletion request was accepted in the live RFP.
- Designated CTI source list: Unknown.
- Per-source Airflow cadence and last successful production load: Needs
confirmation.
- Customer-build RHEL source remains OVAL vs internal VEX v4: Needs
confirmation before implementation.
- Collecting-party identity (customer vs LabradorLabs API keys / ToS):
Needs confirmation.
Details
Role split
Internal definition of the security-data collection platform:
Crawler → Gather-DB → Dist-DB → BTS → collection monitoring| SFR | Data-part role | Note |
|---|---|---|
| 031 | Owner of payload delivery | Certified 망연계 box and AV/signature are security/infra |
| 032 | Owner of sources except CTI | NVD/KEV/OSV/OS-package/libraries exist; vendor-advisory/CTI list does not |
| 033 | Per-source normalize only | Merged CVE record, manual review, approver audit = ISMP |
| 034 | Out | Incident KB; RFP-deletion target |
| 035 | Raw provenance; translation TBD | In-scope per 2026-08-09 #9; no scraper today |
| 036 | Collection completeness metadata | Trust grades and operator alerts = ISMP |
| 039, 040, 042 | Out | Engine/ISMP judgment consuming KEV/EPSS/CVSS fields |
| 001–007 | Out | ISMP portal; vendor/product names are the only collection touchpoint |
2026-08-09 conclusions that bind this split:
- Scope is ISMP year-2 collection of components, CVE-centric vulns, licenses.
- Conclusion 9: Korean translations of collected CVE text are in this year.
- Conclusion 10: global CTI collection and CTI-linked refinement should be
removed from the RFP.
- Customer-delivered crawler/BTS source must not include CENTRIS/VUDDY/XVDB.
The pasted 관제 text still contains the CTI sentences. Treat that as an unresolved RFP edit, not as a silent expansion of data-part scope.
Current system vs SFR
Present in labrador-scrapers / data-platform DAGs (code presence, not a freshness audit):
- Vuln:
nvd_json_feed_crawler,cve_crawler+cve_api_crawlerDAG,
cpe_crawler, cvss_metric_collector, kev_crawler, epss_crawler, osv_vuln, gitlab_advisory_crawler, openssf_mal, OS-package alpine/debian/ubuntu/rhel (+ rhel_vex_crawler redesign).
- Components: npm, PyPI, Maven, Conan, vcpkg, Hunter, SPM, license
crawlers.
- Shared tactics: dated raw + SHA-256 skip, source watermarks
(modified_id.csv, git diff, changes.csv/deletions.csv), TB_CRAWLER_STATUS.
- Delivery: Gathering → Dist → BTS hourly-ish binlog files, ~5 MB split,
XOR header, Go Updater apply.
Gaps that should not be papered over:
- No dedicated GitHub Advisory crawler (OSV may carry GHSA; unverified as
a completeness claim).
- No campaign / ATT&CK / incident-case store.
- No Korean translation / glossary / approval workflow in etl_components.
- No unified multi-source CVE merge with confidence and human review.
- BTS is not SFR-031: no digital signature, no malware scan, no verified
missing-range auto-resync. Truncation error 110 is skip-and-advance.
- Customer RHEL decision (2026-08-19) is OVAL, while internal collection
moved to CSAF/VEX. Resolve before implementing.
Question groups
The Korean brief carries the full 28 questions. Groups:
- A. Scope: was CTI actually deleted; designated CTI list; GHSA via OSV vs
direct; vendor-advisory whitelist; who owns Korean translation; are KEV/EPSS “CTI” or CVE side-metrics.
- B. Air-gap: certified 망연계 vs BTS HTTP; who signs; SHA-256 of raw vs
binlog; AV owner; last-good-version meaning; resync of files vs collection watermarks; audit-log system of record.
- C. Normalize/quality: merge key; conflict precedence owner; reviewer
role; raw retention; trust-grade scale; stale-data threshold.
- D. Contract/ops: API-key identity; fork vs reuse of production crawlers;
RHEL OVAL vs VEX; GitLab advisories-community; daily-success definition; ISMP master-schema owner.
- E. Portal interface only: who fills business-registration fields; SBOM
recycle vs keeping match keys; CVSS/EPSS/KEV snapshot vs live lookup.
Meeting one-liner (Korean, keep as-is)
데이터 파트는 외부망 수집·정규화·BTS 배포까지. 관제 SFR 중 031, 032(CTI 제외), 033(출처별 정규화), 035(원문), 036(수집 메타)만 해당. 034/039/040/042와 032·033의 CTI 문장은 8월 삭제 대상. 001–007은 ISMP 포털. 031의 전자서명·백신· 승인 구간은 망연계 제품 + 보안.