...
Use Cases
- EPOS
- Life Sciences
- HelmHoltz Data Federation
Roles
- PI/Membership Manager (including Security Contact)
- Proxy Operator
- Users
- Service Management (including Security Contact)
- Infrastructure Management (including Security Contact)
Next Steps
Design a top level policy
Which policies do we need?
Policy Need | Source | Template Basis | Audience | Comment | Name | What should we produce? |
---|---|---|---|---|---|---|
Incident Response Procedure | Sirtfi | EGI Incident Response, should link to Sirtfi, AARC work | Proxy, Services | What about policies? | Incident Response Procedure | Template |
Policy on authentication, | Snctfi | EGI Operational Security Policy | Proxy, Services | Top level policy that covers physical and network security, vulnerability handling and refers to additional policies on Acceptable Assurance, Incident Response Procedure, Membership management We either make very modular or try to make this quite long | Top Level Policy | Template |
AUP for end users | Snctfi | WISE Baseline AUP | Users | EGI seems to have 2 AUPS, Infrastructure and User Community | Infrastructure AUP | Template |
Collections of users' aims and purposes | Snctfi | This is the User Community AUP. There is an example somewhere. Would be better if these could be combined. | ||||
Policies and procedures regulating the behaviour of the management of the Collection of users | Snctfi | EGI Membership Management | In XSEDE it's much more simple | Membership Management | Template | |
Data Protection Policy, e.g. DP CoCov2 | Snctfi | CoCo | Could be included in top level | Data Protection Code of Conduct | Framework description | |
Privacy Policy | CoCo | CoCo Template | Privacy Policy | Template | ||
Policy on eligibility to join the infrastructure (i.e. services) | Elixir | NOT Similar to EGI Service Operations, there is some overlap with the Top Level Policy. Try and include in overall policy | Service Eligibility | Template | ||
Risk Assessment (DPIA) | Data Privacy Statement | ?? | NOT A POLICY but could inform policy decisions | ?? | ?? |
Example Policy Sets
Differences with EGI Policies?
...