Also available as PDF(374KB)
Based on requests by the membership, FIRST may initiate development of a standard. A standard is defined as a document that is intended to ensure interoperability of a technique or tool, and is planned to see adoption and implementation by various parties. FIRST may also develop other descriptive, rather than normative, documents such as best practices, which are not required to follow the standards process.
Both FIRST members and non-members may propose the inception of a standard. A Special Interest Group (SIG) will typically shepherd the standard.
The FIRST board will evaluate proposals for a new standard based on:
This document describes minimum governance requirements for FIRST SIGs that aim to develop standards. SIGs may define more restrictive rules, but in any case where a SIG rule conflicts with a FIRST governance requirements, that exception must be specifically approved by the FIRST Board to be valid.
Standards intended for publication and use outside of the membership must allow participation both by members and non-members of FIRST. Standards for use within the FIRST membership only may restrict membership to FIRST members only.
Active contribution of ideas to a FIRST standard requires the signing of an Intellectual Property Rights Agreement (IPR) between FIRST and the participant. The FIRST IPR is linked in Appendix E, and must be executed by “participants” and “voting participants” prior to participation. IPRs are executed by a Legal Entity defined as an individual or organization which is legally permitted to enter into a contract, and be held accountable if it fails to meet its contractual obligations.
Where multiple SIGs define standards in a single greater work area (e.g. threat intelligence or network security), chairs are encouraged to coordinate efforts. The FIRST board will look to all relevant groups to coordinate across their respective standards to avoid confusion and contradicting standards. FIRST will also look towards the SIGs to have at least one chair participate as a Participant in the other SIG to ensure alignment.
By default, FIRST grants permission for standards it develops to be implemented and/or adopted by FIRST members and non-members at no cost in perpetuity. Any exception requires an explicit approval by the FIRST board. The default license for any standard is Creative Commons CC - BY-SA (Attribution+ShareAlike). Exceptions must be approved by the FIRST Board.
Standards SIGs are expected to use clear and uniform language. Technical (non-dictionary) language must be defined and contributed to an overarching glossary maintained by FIRST across SIGs and standards. The glossary will not be prescriptive but intended to be used by FIRST members as a best practice. Important terms must be defined internally to the standard, but the glossary should be used to limit the amount of inconsistency across multiple standards.
FIRST standards use terminology defined in RFC 2119 as indicated in that best practice.
FIRST will publish a list of all voting participants (defined below) that contributed to each standard, and may post a list of all Participants.
FIRST SIGs developing a standard permit participation by three types of members:
In order to apply for Observer or Participant membership, an individual reaches out to the FIRST secretariat via e-mail at first-sec@first.org, noting the type of membership requested. The secretariat will liaise with the SIG chair to evaluate:
Each SIG developing a standard must have one chairperson, and at least one co-chair. Chairs may be either Participants or Voting Participants. The initial Chair and co-chair may be proposed by the standard initiators and is ratified by the FIRST Board. When a Chair steps down, a new Chair must be selected through a simple majority election process. Ties are addressed by re-voting. If a tie persists for more than two rounds, the tie is broken by random selection between tied candidates.
The SIG will generally aim to achieve its outcome by building consensus amongst observers, participants and voting participants.
The minimum requirement for voting is prior to the publication of specific deliverables. SIGs are encouraged to set regular milestones at which a deliverable is voted on. Each group can set more restrictive requirements for voting on individual decisions (e.g. conduct a vote for each change which materially changes the outcome of a technical tool described by the standard). Voting proposals can be initiated by each participant and must be submitted to the SIG mailing list, including at least the elements included in Appendix C.
A proposal will pass when:
Observers, Participants or Voting Participants may leave the SIG based on simple request to first-sec@first.org. If this changes voting membership in such a way that a constituency now becomes underrepresented, the Chairs may choose to make a call for additional SIG participants through the FIRST web site, a mail to the FIRST membership and its social media channels to identify a potential replacement.
FIRST will announce the intention to create a new standard publicly:
FIRST will also endeavor to identify and inform critical partners involved in the industry targeted by the standard through a direct e-mail message. As FIRST will never be aware of all possible constituents, any participant in the standard or FIRST member may request the FIRST secretariat to notify a particular constituency or can forward the notification themselves.
Once the group has iterated through working drafts (WD), and is ready to release a public draft (PD):
Once the SIG has addressed external comments, they will update the standard if necessary and present it to the FIRST Board for final publication.
Proposed standards pass through two major phases: working drafts, which are published at least internally, and public drafts, published for public comment. During its development multiple working drafts and public drafts could be produced.
Working drafts follow the following process:
The external comment period for a public draft is always at least one month. When the public draft comment period starts, the Chair sends a reminder of the disclosure obligations under the Common Patent Policy and the Specifications for Implementation of the Common Patent Policy along with a copy of the form set forth in Exhibit A.
During a standard’s lifetime, it may be in one of the following states: “Draft”, “In force” and “Obsolete”. The status must be clearly marked on any document which contains the complete standard text. Draft can be “Working Draft (WD)” or “Public Draft (PD)”. When a standard is made “Obsolete” it is no longer in force and it must not be used in new products/processes/services. An obsolete standard can be superseded by a newer or different standard. In that case it will be marked as “Obsolete, Replaced by: ....”.
Standards releases are versioned. Large versions, such as v1, v2, v3 indicate a thorough, all-up review of the standard. Minor versions, v1.1, v1.2 indicate only portions of the standard were revised.
Standard groups can choose the format they prefer for editing language of the standard. Tools that allow versioning controls are recommended, such as Word or LaTex, or the use of a versioning repository such as GitHub. A master, readable copy of the standard must be created in ASCII which is stored on the FIRST web site.
FIRST does not prescribe a standard format for standards, but recommends including an About and Background section explaining the relevance of the standard, and including sample code in appendixes or associated documents. The following mandatory metadata should be included: (1) date of release, (2) status of the standard, (3) version number, (4) contact e-mail address @first.org, (5) license.

The following minimum information is due to the FIRST secretariat to propose the development of a standard. The typical process would be for a group to be proposed on the topic, and this SIG to contain the standard as a work item.
When an existing group plans to develop a new standard, only the items marked with a * items are due. A Planning Checklist will be made available:
This list contains all information that is expected to be provided by the standard chairs when a vote on a milestone is to be made. Depending on the group’s proposed governance model, a milestone could be accepting a specific technical contribution, or the finalization of a document for publication.
While not a requirement, SIGs may choose to define their constituency up front, and maintain a balanced constituency throughout the development of the standard. An example is the below constituency used by the CVSS Standards SIG. This is an example only, and standards groups may be more open, or more flexible:
- Banking
- Health Care
- Government
- Academic
- Manufacturing and Retail
- Technology / Hardware
- Technology / Software
- Technology / Networking
- Telecommunications
- CIRTs
- Energy
- Transportation
Each organization requesting voting rights is categorized as being in one of the following constituencies, based on its primary business or purpose. Requests are only accepted if the organization’s constituency will represent 25% or less of the total organizations with voting rights if the organization is added. When a constituency is full, new Participants wishing to become Voting Participants must wait until other constituencies grow, allowing for additional room, or an existing constituency member loses or relinquishes their voting rights.
In order for FIRST to be successful in developing content which can be used by our community in an unfettered way, we must protect the intellectual property rights on our deliverables. This means that our output must not contain information over which third parties may hold a license, and deliverables we develop should be owned by FIRST. The FIRST Uniform IPR policy ensures an organization does not have the ability to introduce patented content without notification by ensuring organizations are asked to declare any patented content they are introducing. The FIRST Intellectual Property Rights (IPR) agreement can be found at https://www.first.org/about/policies/uniform-ipr. A single IPR must be signed per SIG that an organization participates in.
Comments must be as precise as possible. A comment must contain the following elements:
All comments from a single person or an organization must be submitted in a single file. The file with comments can be submitted only once. Comments must have consecutive numbers.
The editor must resolve all comments that are submitted on time. The editor can use discretion to address late comments and/or accept new comments during the discussion. Possible resolutions are: “Accepted”, “Accepted in principle”, “Not accepted”. Their meanings are as follows:
Once a comment is resolved participants do have right to raise it again (e.g. re-submit a comment that was not accepted) but it is up to editor’s discretion to choose not to address it.
A file with all comments and their resolution must be distributed to the whole SIG as a reference as soon as the process is finished.