Skip to content

JJBittner/.github

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

Cyber Ontology Foundry Code of Conduct

1. Purpose

The Cyber Ontology Foundry is a community-governed initiative for developing open, interoperable, formally grounded ontologies for the cyber domain.

The Foundry depends on serious technical disagreement, careful review, and public collaboration. This Code of Conduct exists to make that collaboration productive, respectful, and safe for contributors, maintainers, reviewers, working group members, and users.

Participation in the Cyber Ontology Foundry is a privilege conditioned on professional conduct.


2. Scope

This Code of Conduct applies to participation in Cyber Ontology Foundry spaces, including:

  • GitHub repositories;
  • issues;
  • pull requests;
  • discussions;
  • code reviews;
  • working group meetings;
  • Steering Committee meetings;
  • public chats or forums;
  • mailing lists;
  • documentation;
  • release discussions;
  • conferences, workshops, or events where someone is representing the Foundry;
  • private communications related to Foundry work when those communications affect participation in the community.

This Code of Conduct applies to all participants, including contributors, maintainers, reviewers, working group leads, Steering Committee members, invited experts, contractors, and organizational representatives.


3. Expected behavior

Participants are expected to:

  • be respectful and professional;
  • assume good faith when possible;
  • focus criticism on ideas, artifacts, arguments, and evidence;
  • explain technical objections clearly;
  • distinguish personal preference from Foundry policy;
  • provide examples, sources, or use cases when making substantive claims;
  • be willing to revise proposals in response to review;
  • respect the time and effort of contributors and maintainers;
  • avoid unnecessary repetition after a decision has been made;
  • disclose conflicts of interest when relevant;
  • respect governance procedures;
  • follow repository contribution guidelines;
  • respect security and sensitivity rules;
  • help make decisions explicit, documented, and reviewable.

Technical disagreement is welcome. Personal attacks are not.


4. Productive technical disagreement

Ontology engineering often involves hard boundary cases. Contributors may disagree about definitions, scope, mappings, axioms, imported terms, relation reuse, and governance.

Good disagreement should:

  • identify the specific issue;
  • explain why the current proposal is problematic;
  • provide an alternative when possible;
  • cite relevant standards, ontologies, use cases, examples, or competency questions;
  • distinguish urgent blockers from optional improvements;
  • remain focused on the artifact under review.

Examples of acceptable disagreement:

  • “This definition is circular because it uses the label being defined.”
  • “This mapping should be close match, not exact match, because the source standard represents an operational technique while the Foundry term represents a type of process.”
  • “This term appears to duplicate an existing COF Core term. We should either reuse the existing term or explain the distinction.”
  • “This relation should not be introduced until we determine whether an existing CCO or RO relation already covers the intended meaning.”

Examples of unacceptable disagreement:

  • “Only an idiot would model it that way.”
  • “This contributor clearly does not understand ontology.”
  • “You people always make this mistake.”
  • “I am going to block this unless you do it my way.”

5. Unacceptable behavior

Unacceptable behavior includes:

  • harassment, intimidation, or threats;
  • personal attacks or insults;
  • discriminatory language or conduct;
  • sexualized language or imagery;
  • sustained disruption of discussions, meetings, issues, or pull requests;
  • bad-faith argumentation;
  • repeated refusal to follow maintainer or governance decisions;
  • doxxing or publishing private information without permission;
  • impersonation or misrepresentation of affiliation, authority, or approval;
  • knowingly submitting false, misleading, or plagiarized material;
  • knowingly submitting content the contributor does not have the right to contribute;
  • attempting to use the Foundry to promote vendor-specific claims in a misleading way;
  • attempting to bypass review or governance processes;
  • retaliating against someone who raises a conduct concern;
  • encouraging others to engage in unacceptable behavior.

6. Cyber-domain security expectations

Because the Foundry operates in the cyber domain, participants must also avoid conduct that creates unnecessary security risk.

Do not submit or disclose:

  • classified information;
  • controlled unclassified information without authorization;
  • proprietary information without permission;
  • unreleased vulnerability details;
  • exploit-enabling operational details;
  • target-specific operational information;
  • credentials, keys, tokens, or secrets;
  • sensitive personal information;
  • sensitive organizational information unsuitable for public release.

Do not pressure other participants to disclose sensitive information.

Do not use Foundry spaces to request, provide, or refine instructions for unauthorized access, exploitation, evasion, persistence, credential theft, or operational misuse.


7. Conflicts of interest and representation

Participants should be clear about when they are speaking:

  • as individual contributors;
  • on behalf of an employer;
  • on behalf of a working group;
  • as maintainers;
  • as Steering Committee members;
  • as representatives of the Foundry.

Participants should disclose relevant conflicts of interest when they may affect review, acceptance, governance, or public communication.

Examples of relevant conflicts include:

  • reviewing an ontology submitted by one’s own organization;
  • proposing Foundry recognition for a product, service, or ontology from which one benefits;
  • using Foundry participation to imply endorsement of a vendor or product;
  • participating in a decision where one has a direct financial or organizational interest.

A conflict of interest does not automatically prevent participation. It must be disclosed so that review and governance decisions remain trustworthy.


8. Reporting concerns

Conduct concerns may be reported to the Steering Committee or to designated Code of Conduct contacts.

Please include, when possible:

  • what happened;
  • where it happened;
  • when it happened;
  • who was involved;
  • links to relevant issues, pull requests, comments, emails, or messages;
  • names of witnesses, if any;
  • whether the concern is ongoing;
  • whether immediate action may be needed.

Reports should be sent to:

info@ncornetwork.org

About

No description, website, or topics provided.

Code of conduct

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

No releases published

Packages

 
 
 

Contributors