Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  1. Define a unique name for your collaboration (recommend DNS) 
  2. Identify a governance body to make policy decisions
  3. We strongly suggest (although this is out of scope here) 
    1. Identifying your primary assets
    2. Completing a risk assessment
    3. Defining your rules of participation and the escalation procedure in case of non-compliance
    4. Any additional legal and regulatory compliance 
  4. Define the purpose of your collaboration → this will be used for your AUP
  5. Define the following 6 policies and seek endorsement from the governance body
  6. Ensure that the policies are presented to and accepted by the relevant audiences



DocumentAARC TemplateExamples
Membership Management PolicyWIP
AUPWISE AUP
Privacy Policy
X Y Z 
AAOPSAttribute Authority Operational Security
Security Operational BaselineSecurity Operational Baseline
Incident response procedure X Y Z