Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.

Draft Ongoing draft available at 

Preliminary version (2018-07-31, as a pdf) of the AARC Policy Development Kit.

Table of Contents



  • PI/Membership Manager (including Security Contact) 
  • Proxy Operator
  • Users
  • Service Management (including Security Contact)
  • Infrastructure Management (including Security Contact)

Next Steps

  1. Excel of Training Course 
  2. Document of content 
  3. Slides pending

Which policies do we need?


Reword "Research Community" to Infrastructure
IR Procedure Template, cross check with CTSC & EGI, add internal part
AUP Template, should be a reasonable version
Membership Management Template
CoCov2 Privacy Policy Template
Check whether CoCov2 can be our "policy"
Send an update to Irina
Consider DPIA
Put on AARC Website/Moodle in a modular format
Irina & Consultant
Ask David about RAF and Assurance Profiles


Move frameworks before policies
Top Level Policy, check whether it really covers things
Add "Other things you may want to think about"
Add diagram
Send invitation
Disseminate invitation
Acceptable Authentication Assurance improve
Put on slides and give to Irina
Insert "top" Data Protection Policy (for Infra), in comparison per Service
Update AUP to reflect recent changes (2018-07-31)

titlePrevious Notes

Notes & Thoughts 

Objective: Provide new or evolving Research Communities  and Infrastructures with the guidance they need to develop a complete policy suite supporting Federated Identity Management

Audience: Operational Management of Research Communities and their respective infrastructures 

Relevant questions:

  • We’re worried that we will have legal issues receiving federated identities, which policies do we need?

  • What is a reasonable expectation of assurance of incoming identities? 

  • How can I ensure that all my users are covered by an incident response capability?

  • What checks and measures should I put in place when managing the users of my community services, or members of virtual organisations? 

Introductory Content:

  • Make clear why these policies should be adopted, where they have come from and examples of how they help

Policy Areas:

(Would be good to have actionable points as well as dry document examples)

(Can we encourage people to be in the right mindset to make their own decisions about timelines for policy decisions etc)

Snctfi (top level)  -- for scalable, bounded communities

Data Protection & Privacy

Membership management & AUP

  • Can cover Users, Communities and contributing services

  • Attribute request/release

  • AUP - Acceptable Use Policy 

  • Accounting, logging, monitoring policies

  • LoA (What is the acceptable level? Is step up required?)

Security Incident Response 

  • Sirtfi (Able to assert for RC? Require it for incoming federated users? Is step up required?)

  • AARC deliverable template

  • Security policies e.g. EGI

Sources of input:

  • EGI security and community policies

  • AARC templates

  • CoCo work

  • WLCG policies

  • ELIXIR AAI strategy Appendix A: Acceptable Usage Policy, Appendix B: Policy for Relying Parties, Appendix C: Requirements for ELIXIR AAI operators

Also, maybe we can re-use the EGI work (Security and Community policies)

Crazy ideas for how this could work...

  • Moodle course walking people through decisions for each policy aspect

  • Website static pages (bit dull) 

  • Recorded video snippets for each aspect (Uros and Hannah can do a double act of questions and answers!)

  • “Click in” style website 

  • Road show

  • Face-to-face session where we split the room into sections and ask for questions on specific policies 

  • Recorded interviews with experts on specific topics, e.g. GDPR, Security Incident Response

Key Ideas for each topic:

  • What is this policy for?

  • Sub policies

  • Does my RC/Infrastructure need it? 

  • What do I need to do? 

  • Who needs to agree to the policy and where should it live?

  • Template

Could group as:

  • General Policies

  • Audience Specific 

See e.g.!master/navigator/project?P:1412060393:1412060393:subDocs