Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Expand
titleDefine, or adopt as-is, the basic set of policy documents for collaboration - and seek endorsement by your governance body

Why? This basic set of 6 documents helps get a sufficient set of collaboration guidelines quickly - you can always adapt them later

Recommendation: these are the documents you surely need - or you need to ask from your AAI provider:

  • Membership Management
  • Privacy policy
  • Attribute Authority operational security (AAOPS)
  • Security Operational Baseline
  • An incident response procedure
Expand
titleReview the AEGIS endorsed policy guidelines required for AARC compliance and ensure their technical implementation

...

Why? Assurance means both knowing if the person on the other side is indeed the same user that you know, but also includes identity assurance, verifying that the person is indeed the one they claim to be: name and affiliation being the most visible elements. How strong that assurance needs to be depends on the type of research and the collaboration risk assessment. 
And for how long do you trust that the activity is still the intended one, and from the same user? 

Recommendation: review the technical and policy guidelines endorsed by the AAI providers and infrastructures in AEGIS, the AARC Engagement Group for Infrastructures:

  • Identify your assurance requirements, following AARC-G031 "evaluation and combination of the assurance of external identities".
  • Identify suitable token lifetimes, using AARC-G081 "Recommendations for Token Lifetimes" 

Applicable guidance: Assurance Requirements, AARC-G031 evaluation and combination of the assurance of external identities, AARC-G081 "Recommendations for Token Lifetimes"

Expand
title

...

Ensure that the policies are presented to and accepted by the relevant audiences


Expand
titlePublish your documents and responsible parties at a suitable location


Your entry point into collaboration policy and good practice

...