Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Draft available at https://docs.google.com/document/d/176vzNaoK6KvKTMp8Glk2n1NaM6bxiS1QqH8M3_mu7NI/edit# 

Table of Contents

Objective 

Provide new or evolving Research Communities  and Infrastructures with the guidance they need to develop a complete policy suite supporting Federated Identity Management. This should be done with input from the wider community, through FIM4R, WISE and relevant bodies. For this work in AARC, the policy kit should be tightly scoped to the blueprint architecture but there is an expectation that the work be extended to be relevant for infrastructures in general. 

...

Policy NeedSourceTemplate BasisAudienceCommentNameWhat should we produce?Actions
Incident Response ProcedureSirtfiEGI Incident Response, should link to Sirtfi, AARC workProxy, Services
  • What about policies?
  • Incident Response Procedure from AARC
Incident Response ProcedureTemplateH to add template based on AARC and EGI

Policy on

  • authentication, 
  • authorisation, 
  • access control, 
  • physical and network security, 
  • security vulnerability handling
and
  • and 
  • security incident handling → IR procedure

for all Constituents

SnctfiEGI Operational Security PolicyProxy, Services

Top level policy that covers physical and network security, vulnerability handling and refers to additional policies on Acceptable Assurance, Incident Response Procedure, Membership management

We either make very modular or try to make this quite long


Top Level PolicyTemplate
AUP for end usersSnctfiWISE Baseline AUPUsers
  • EGI seems to have 2 AUPS, Infrastructure and User Community
  • Wait for Ian's WISE Baseline AUP
Infrastructure AUPTemplateWait for Ian, check with him
Collections of users' aims and purposesSnctfi

This is the User Community AUP. There is an example somewhere. Would be better if these could be combined.


Policies and procedures regulating the behaviour of the management of the Collection of users 

SnctfiEGI Membership Management
In XSEDE it's much more simpleMembership ManagementTemplateU to add template based on https://docs.google.com/document/d/1vPcAja1EyTp-kJPvJpwu3NSd8e1aVcytY3nSGthWNLU/edit#

Data Protection Policy, e.g. DP CoCov2

SnctfiCoCo
Could be included in top levelData Protection Code of ConductFramework descriptionU to go through CoCov2 and check whether this is prescriptive enough

Privacy Policy 

CoCoCoCo Template

Privacy PolicyTemplateH to add the Privacy Policy template from CoCov2
Policy on eligibility to join the infrastructure (i.e. services)Elixir

NOT Similar to EGI Service Operations, there is some overlap with the Top Level Policy.

Try and include in overall policy

Service EligibilityTemplate
Risk Assessment (DPIA)Data Privacy Statement??
NOT A POLICY but could inform policy decisions????

...

  • Cannot assume a CSIRT for each Infrastructure
  • Assume there is one AUP
  • Resource Centres are not relevant
  • There are not necessarily multiple User Communities


ActionStatusWho
Reword "Research Community" to Infrastructure
  •  
Hannah
IR Procedure Template
  •  
Hannah
AUP Template
  •  
Ian
Membership Management Template
  •  
Uros
CoCov2 Privacy Policy Template
  •  
Hannah
Check whether CoCov2 can be our "policy"
  •  
Uros