WISE, SCI & policy templates David Kelsey (STFC-RAL, UK Research and Innovation) FIM4R & TIIME, Vienna, 11 February 2019.

Slides:



Advertisements
Similar presentations
Grid Security Users, VOs, Sites OSG Collaboration Meeting University of Washington Bob Cowles August 23, 2006 Work supported.
Advertisements

INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
Federated Identity Management for Research Communities (FIM4R) David Kelsey (STFC-RAL) EGI TF, AAI workshop 19 Sep 2012.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 and now abbreviated.
Trust and Security for FIM (Sirtfi/SCI) David Kelsey (STFC-RAL) FIM4R at CERN 4 Feb 2015.
AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef.
Moving Forward With the African Dialogue Cross-Border Principles By Mary Gurure Manager, Legal Services and Compliance COMESA Competition Commission Lilongwe,
WLCG Security: A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) CHEP2013, Amsterdam 17 Oct 2013.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Milan And mechanisms NA3 Task 4 – Scalable.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Federated Identity Management for HEP David Kelsey HEPiX, IHEP Beijing 18 Oct 2012.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
June 6, 2006OSG - Draft VO AUP1 Open Science Grid Trust as a Foundation June 6, 2006 Keith Chadwick.
Additional Services: Security and IPv6 David Kelsey STFC-RAL.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
Federated Identity Management for Scientific Collaborations The Common Vision David Kelsey (STFC) 3 Nov 2011.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
SEE-GRID The SEE-GRID initiative is co-funded by the European Commission under the FP6 Research Infrastructures contract no SEE-GRID.
The EU General Data Protection Regulation Frank Rankin.
Security Bob Cowles
Who doesn’t need to be WISE? Bringing into reality global information security collaboration Alessandra Scicchitano GÉANT - Project Development Officer.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
Authentication and Authorisation for Research and Collaboration David Kelsey AARC AHM Utrecht NA3 Task 4 – Scalable Policy Negotiation.
Authentication and Authorisation for Research and Collaboration Taipei - Taiwan Mechanisms of Interfederation 13th March 2016 Alessandra.
Cloud Security Session: Introduction 25 Sep 2014Cloud Security, Kelsey1 David Kelsey (STFC-RAL) EGI-Geant Symposium Amsterdam 25 Sep 2014.
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
Security in the wider world David Kelsey (STFC-RAL) GridPP37 – Ambleside 2 Sep 2016.
SCI & Sirtfi David Kelsey (STFC-RAL) EGI Conference, Lisbon 19 May 2015.
Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014.
WISE Information Security for Collaborating E-Infrastructures
Introduction to AAI Services
Security Management Geant SIG-SIM – Alf Moens
WISE 2016 WISE: a global trust community where security experts share information and work together, creating collaboration among different e- infrastructures.
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
Boosting AAI for research and collaboration
The Policy Puzzle Many groups and (proposed) policies, but leaving many open issues AARC “NA3” is tackling a sub-set of these “Levels of Assurance” –
Open Science Grid Consortium Meeting
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
Federated Identity Management for Researchers (FIM4R)
EGI Security Policy Update
Update on FIM4R David Kelsey
Boosting AAI for research and collaboration
Federated Identity Management for Scientific Collaborations
Bringing Harmonized Policy and Best Practice
Towards hamonized policies and best practices
The AARC Project Licia Florio AARC Coordinator GÉANT
Frameworks for harmonized policies and practices
Policy in harmony: our best practice
Thursday pilot session: 7-minutes
Information Governance
Towards hamonized policies and best practices
Policy and Best Practice … in practice
Updated (VO) Community Security Policies
Update - Security Policies
AARC Blueprint Architecture and Pilots
Supporting communities with harmonized policy
EUGridPMA Status and Current Trends and some IGTF topics March 2018 APGridPMA ISGC Meeting David Groep, Nikhef & EUGridPMA.
OIDC Federation for Infrastructures
David Kelsey (STFC-RAL)
WP3: Policy and Best Practice Harmonisation
David Groep for the entire AARC Policy Team I2TechEX18 meeting
David Groep for the entire AARC Policy Team AARC2 AHM4 meeting
WISE Information Security for collaborating e-Infrastructures David Kelsey (STFC-RAL, UK Research and Innovation) ISGC2019, Taipei, 2 April 2019 In collaboration.
Federated Incident Response
Future GridPP Security
Presentation transcript:

WISE, SCI & policy templates David Kelsey (STFC-RAL, UK Research and Innovation) FIM4R & TIIME, Vienna, 11 February 2019

Contents The WISE community Security for Collaborating Infrastructures (SCI) AARC2 Policy Development Kit AARC2/WISE Baseline AUP Kelsey/WISE/SCI Trust Framework 11 Feb 2019

The WISE Community & Security for Collaborating Infrastructures (SCI) Note: WISE has several different activities – not just SCI For example Risk Assessment working group has published draft risk assessment spreadsheets for use by others, see https://wise-community.org/risk-assessment-template/ The WISE Community & Security for Collaborating Infrastructures (SCI) The SCI activity was a co-founder, together with TERENA/GEANT SIG-ISM (2015) More details on SCI: Trusted CI Webinar – D Kelsey (24 Sep 2018) https://trustedci.org/webinars/ Next WISE Community meeting – Kaunas, Lithuania, 16-18 April 2019 – all welcome! https://wise-community.org/events/ Kelsey/WISE/SCI Trust Framework 11 Feb 2019

WISE meetings (Oct 2015, Feb & Aug 2018) – others not shown! Barcelona, Spain Abingdon, UK Alexandria, VA, USA Kelsey/WISE/SCI Trust Framework 11 Feb 2019

Security for Collaborating Infrastructures (SCI) A collaborative activity of information security officers from large- scale infrastructures EGI, OSG, PRACE, EUDAT, CHAIN, WLCG, XSEDE, … Grew out of JSPG(EGEE/EGI/WLCG) and IGTF – from the ground up (2011-13) We developed a Trust framework Enable interoperation (security teams) Manage cross-infrastructure security risks Develop policy standards Especially where not able to share identical security policies Kelsey/WISE/SCI Trust Framework 11 Feb 2019

SCI version 1 (2013) - children Both separate derivatives of SCI version 1 REFEDS Sirtfi - The Security Incident Response Trust Framework for Federated Identity requirement in FIM4R version 1 paper https://refeds.org/sirtfi AARC/IGTF Snctfi – The Scalable Negotiator for a Community Trust Framework in Federated Infrastructures For scalable policy – Research Services behind a SP/IdP proxy https://www.igtf.net/snctfi/ Kelsey/WISE/SCI Trust Framework 11 Feb 2019

WISE SCI Version 2 Aims SCI Version 2 was published on 31 May 2017 Involve wider range of stakeholders GEANT, NRENS, Identity federations, … Address any conflicts in version 1 for new stakeholders Add new topics/areas if needed (and indeed remove topics) Revise all wording of requirements Simplify! SCI Version 2 was published on 31 May 2017 https://wise-community.org/sci/ Kelsey/WISE/SCI Trust Framework 11 Feb 2019

SCI Version 2 – published 31 May 2017 Kelsey/WISE/SCI Trust Framework 11 Feb 2019

Endorsement of SCI Version 2 at TNC17 (Linz) 1st June 2017 Infrastructures endorse the governing principles and approach of SCI, as produced by WISE, as a medium of building trust between infrastructures, to facilitate the exchange of security information in the event of a cross-infrastructure incident, and the collaboration of e-Infrastructures to support the process. These Infrastructures welcome the development of an information security community for the Infrastructures, and underline that the present activities by the research and e-Infrastructures should be continued and reinforced Endorsements have been received from the following infrastructures; EGI, EUDAT, GEANT, GridPP, MYREN, PRACE, SURF, WLCG, XSEDE, HBP https://www.geant.org/News_and_Events/Pages/supporting-security-for-collaborating- infrastructures.aspx Kelsey/WISE/SCI Trust Framework 11 Feb 2019

SCI–WG in 2018/19 (Nearly) complete Joint work AARC2/EOSC-hub on Policy Development Kit Produce WISE Baseline AUP v1.0 (Prepared by AARC2) Work in progress Maturity (self) Assessments against SCI v2 Assessment spreadsheet/FAQ/Guidelines – how to satisfy SCI V2? Kelsey/WISE/SCI Trust Framework 11 Feb 2019

AARC2 (Uros Stevanovic & NA3 policy team) Policy development kit Establishing an Infrastructure (or Community) requires clear rules for security, membership management, data protection, etc. Rules  Policies Policies provide: Trust Manage and govern Infrastructure Legal compliance AARC (and WISE) providing templates, instructions, trainings https://aarc-project.eu/policies/policy-development-kit/

Which policies? SCI paper (A Trust Framework for Security Collaboration among Infrastructures) SNCTFI (Scalable Negotiator for a Community Trust Framework in Federated Infrastructures) Top level policy Operational Security Membership management Data protection Consider current best practices (EGI, CERN, ELIXIR, TrustedCI, etc.) Policies start from EGI versions Some other policies (Infrastructure-related) will need to be handled by WISE/EOSC-hub

Slides of Ian Neilson - A common AUP - motivation To make a recommendation for the content of an Acceptable Use Policy (AUP) to act as a baseline policy (or template) for adoption by research communities To facilitate - a more rapid community infrastructure ‘bootstrap’ ease the trust of users across infrastructures provide a consistent and more understandable enrolment for users. Adoption of a policy preferred to template

2018 study of existing AUPs AARC2 NA3 policy (Ian Neilson) For details see: https://wiki.geant.org/pages/viewpage.action?pageId=86736956 Looked at AUPs from 11 infrastructures Then considered clause by clause in a spreadsheet: https://docs.google.com/spreadsheets/d/1bg5I9n_DM7QcXdnja_7r0OEpTfjrb72ftq7- xHQxfxM/edit#gid=822235717 Kelsey/WISE/SCI Trust Framework 11 Feb 2019

How will this Baseline AUP used? Forms part of the information shown to a user during registration with his/her community AUP provides information on expected behaviour and restrictions "baseline" text can, optionally, be augmented with additional, community or infrastructure specific, clauses as required, but the numbered clauses should not be changed The registration point where the user is presented with the AUP may be operated directly by the user's research community or by a third party on the community's behalf Other information shown to user during registration Privacy Notice - information about the processing of their personal data together with their rights under law regarding this processing Service Level Agreements - information about what the user can expect from the service in terms of quality such as reliability and availability (Optional) Terms of Service Kelsey/WISE/SCI Trust Framework 11 Feb 2019

WISE Baseline Acceptable Use Policy & Conditions of Use Has been sent to WISE steering committee for approval (n.b. consultation has ended) The 10 AUP policy statements are: You shall only use the Services in a manner consistent with the purposes and limitations described above; you shall show consideration towards other users including by not causing harm to the Services; you have an obligation to collaborate in the resolution of issues arising from your use of the Services. You shall only use the Services for lawful purposes and not breach, attempt to breach, nor circumvent administrative or security controls. You shall respect intellectual property and confidentiality agreements. You shall protect your access credentials (e.g. passwords, private keys or multi-factor tokens); no intentional sharing is permitted. You shall keep your registered information correct and up to date. You shall promptly report known or suspected security breaches, credential compromise, or misuse to the security contact stated below; and report any compromised credentials to the relevant issuing authorities. Reliance on the Services shall only be to the extent specified by any applicable service level agreements listed below. Use without such agreements is at your own risk. Your personal data will be processed in accordance with the privacy statements referenced below. Your use of the Services may be restricted or suspended, for administrative, operational, or security reasons, without prior notice and without compensation. If you violate these rules, you may be liable for the consequences, which may include your account being suspended and a report being made to your home organisation or to law enforcement.

Questions? And discussion …. Kelsey/WISE/SCI Trust Framework 11 Feb 2019