...
- Define a unique name for your collaboration (recommend DNS)
- Identify a governance body to make policy decisions
- Define the purpose of your collaboration (this will be used for your AUP)
- We strongly suggest (although this is out of scope here)
- Identifying your primary assets
- Completing a risk assessment
- Adopting the REFEDS Data Protection Code of Conduct if it is suitable for your research collaboration
- Defining your rules of participation and the escalation procedure in case of non-compliance
- Any additional legal and regulatory compliance necessary
- Define, or agree to adopt as is, the following 6 documents and seek endorsement from the governance body
- Review the AEGIS endorsed policy guidelines required for AARC compliance and ensure their technical implementation
- Identify your assurance requirements following https://aarc-community.org/guidelines/aarc-g031/
- Identify suitable token lifetimes
- Ensure that the policies are presented to and accepted by the relevant audiences
- Publish your documents and responsible parties at a suitable location
...
The AARC PDK consists of templates - documents where the core content is either highly determined or should be treated as 'immutable' for better interoperability - and guidelines - helping research collaboration, infrastructures, and service providers with their own procedures and practices, where adopting good practices rather than the exact wording of a policy or procedure is the key value for interoperability. A quick overview of all templates and guidance documents is given here below.
| Document | AARC template for interoperability | Examples where no template is recommended for interoperability purposes |
|---|---|---|
| Membership management | Membership Management | |
| AUP | WISE AUP | |
| Privacy Policy | REFEDS privacy notice, UK-IRIS | |
| AAOPS | Attribute Authority Operational Security | |
| Security Operational Baseline | Security Operational Baseline | |
| Incident response procedure | EOSC, UK-IRIS, AARC federated incident response procedure |
Snctfi, operational policies, and AAI service providers
...