Supporting communities with harmonized policy

Slides:



Advertisements
Similar presentations
David Groep Nikhef Amsterdam PDP & Grid Evolving Assurance – IGTF LoA generalisation David Groep Interoperable Global Trust Federation IGTF Documents at.
Advertisements

Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
Information Resources and Communications University of California, Office of the President UCTrust Implementation Experiences David Walker, UCOP Albert.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Authentication and Authorisation for Research and Collaboration Licia Florio (GÉANT) Christos Kanellopoulos (GRNET) Service orientation.
EResearchers Requirements the IGTF model of interoperable global trust and with a view towards FIM4R AAI Workshop Presenter: David Groep, Nikhef.
IOTA Questions for RPs Sept 9, 2013 Bucharest, Romania.
Authentication and Authorisation for Research and Collaboration Licia Florio REFEDS Meeting The AARC Project I2 Technology Exchange.
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
Authentication and Authorisation for Research and Collaboration David Groep AARC All Hands meeting Milano Policy and Best Practice.
Authentication and Authorisation for Research and Collaboration Christos Kanellopoulos Open Day Event: Towards the European Open.
Networks ∙ Services ∙ People Daniela Pöhn REFEDS EWTI, Vienna IdPs and Federations Service Aspects of Assurance SA5T1.
EGI-InSPIRE RI EGI EGI-InSPIRE RI Establishing Identity in EGI the authentication trust fabric of the IGTF and EUGridPMA.
IGTF Generalised Assurance comments by federation operators with a SAML background September 19-21, 2016 CERN, Geneva, CH.
IGTF in 10 years enabling the interoperable global trust federation Nikhef, Amsterdam supported the Dutch national e-Infrastructure funded and coordinated.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
Building Trust for Research and Collaboration
Introduction to AAI Services
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
Boosting AAI for research and collaboration
RCauth.eu CILogon-like service in EGI and the EOSC
Cross-sector and user-centric AAI
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
EGI Updates Check-in Matthew Viljoen – EGI Foundation
AARC Update What’s been happening in AARC which matters for GÉANT
Policy and Best Practices … the Story So Far
eduTEAMS platform for collaboration Niels Van Dijk
Policy and Best Practice Harmonisation
Policy and Best Practices … the Story So Far
AAI Alignment Nicolas Liampotis (based on the work of Mikael Linden)
Check-in Nicolas Liampotis
Boosting AAI for research and collaboration
Incident Response Hannah Short Sirtfi and Beyond
Incident Response for Federated Identities
Federated Identity Management for Scientific Collaborations
Bringing Harmonized Policy and Best Practice
Towards hamonized policies and best practices
The AARC Project Licia Florio (GÉANT) Christos Kanellopoulos (GRNET)
The AARC Project Licia Florio AARC Coordinator GÉANT
Minimal Level of Assurance (LoA)
Frameworks for harmonized policies and practices
Policy in harmony: our best practice
REFEDS Assurance Framework
Policy and Best Practice Harmonisation (‘NA3’)
Leveraging the IGTF authentication fabric for research
Leveraging the IGTF authentication fabric for research
Towards hamonized policies and best practices
Policy and Best Practice … in practice
WP3: Policy and Best Practice Harmonisation
AARC Athens AHM meeting – NA3 session
Updated (VO) Community Security Policies
Update - Security Policies
AARC Blueprint Architecture and Pilots
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
AARC2 JRA1 Update Nicolas Liampotis
RCauth.eu CILogon-like service in EGI and the EOSC
WP3: Policy and Best Practice Harmonisation
David Groep for the entire AARC Policy Team I2TechEX18 meeting
David Groep for the entire AARC Policy Team AARC2 AHM4 meeting
AAI in EGI Status and Evolution
Tom Barton (WG Chair) University of Chicago and Internet2
REFEDS Assurance WG REFEDS meeting 16 June 2019
Baseline Expectations for Trust in Federation
Combined Assurance Model
Federated Incident Response
REFEDS Assurance Suite
Presentation transcript:

Supporting communities with harmonized policy as well as best practices, templates, and guidelines David Groep NA3 Coordinator Dutch National Institute for Subatomic Physics Nikhef I2GS Federated ID Topics May 2018

Policies and practices to support FIM for Research & Collaboration Operational Security for FIM Communities supporting policies for Infrastructures bulk model 167 entities Baseline Assurance known individual Password authenticator Documented vetting Persistent identifiers Self-assessment Fresh status attribute few unalienable expectations by research and collaborative services ‘low-risk’ use cases generic e-Infrastructure services access to common compute and data services that do not hold sensitive personal data protection of sensitive resources access to data of real people, where positive ID of researchers and 2-factor authentication is needed Slice includes: assumed ID vetting ‘Kantara LoA2’, ‘eIDAS low’, or ‘IGTF BIRCH’ Affiliation freshness better than 1 month Good entropy passwords Verified ID vetting ‘eIDAS substantial’, ‘Kantara LoA3’ Multi-factor authenticator guidance for Researchers & Community Engagement and Harmonisation 2

A Security Incident Response Trust Framework – Sirtfi summary Require that a security incident response capability exists with sufficient authority to mitigate, contain the spread of, and remediate the effects of an incident. Operational Security Assure confidentiality of information exchanged Identify trusted contacts Guarantee a response during collaboration Incident Response Improve the usefulness of logs Ensure logs are kept in accordance with policy Traceability Confirm that end users are aware of an appropriate AUP Participant Responsibilities see http://refeds.org/sirtfi

Incident response process evolution in federations – beyond this first step Solution More communications challenges Instantly available tooling and defined role for all parties. And: pick a coordinator Challenges IdP appears outside the service’ security mandate Lack of contact, or lack of trust in IdP which is an unknown party IdP fails to inform other affected SPs, fear of leaking data, of reputation, or just lack of interest No established channels of communication, esp. not to federations themselves!

Guidance for research and generic Infrastructures Impact of GDPR and risk assessment guidance Protection of aggregations of accounting data by (user) communities Develop traceability and accounting data-collection policy framework based on SCI e.g. why SCI & peer review may more appropriate than trying 27k and audits for Infrastructures? construct (‘service’ part of) a Policy Development Kit for Infrastructures Do I Need A DPIA Risk Assessment a guide for communities

Guidance for research communities in the Infrastructure ecosystem commonality between acceptable use policies using a layered approach through assurance profiles REFEDS RAF, but also cross Infrastructure: Cappuccino, Espresso BIRCH and DOGWOOD Assam (social-ID authenticator assurance) support community management, also to ease use of the generic e-Infrastructures can you support trustworthy community operations? How should a community collaborate in the Infra ecosystem, now that we have very ‘powerful’ communities?

Policy guidance: generic and community-targeted

Engagement and coordination with the global community Co-develop Through WISE, SCI REFEDS IGTF Or drive requirements in FIM4R /Guidelines In your Community, use Unique non-reassigned identifiers Snctfi policy structures ‘Community First’ Attributes backed with Self- assessment and peer review methods Snctfi Scalable Negotiator for a Community Trust Framework in Federated Infrastructures Derived from SCI, the framework on Security for Collaboration in Infrastructures Basis for policy development kit – identify gaps in policy suite and leverage AARC templates https://igtf.net/snctfi

davidg@nikhef.nl