You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 58 Next »

Practical steps to getting started with Policies for a Research Collaboration


Note: we are missing DP CoCo from these steps


  1. Define a unique name for your collaboration (recommend DNS) 
  2. Identify a governance body to make policy decisions
  3. Define the purpose of your collaboration (this will be used for your AUP) 
  4. We strongly suggest (although this is out of scope here) 
    1. Identifying your primary assets
    2. Completing a risk assessment
    3. Defining your rules of participation and the escalation procedure in case of non-compliance
    4. Any additional legal and regulatory compliance necessary
  5. Define, or agree to adopt as is, the following 6 documents and seek endorsement from the governance body
  6. Review the AEGIS endorsed policy guidelines required for AARC compliance and ensure their technical implementation
    1. Identify your assurance requirements following https://aarc-community.org/guidelines/aarc-g031/ 
    2. Identify suitable token lifetimes
  7. Ensure that the policies are presented to and accepted by the relevant audiences
  8. Publish your documents and responsible parties at a suitable location 



DocumentAARC template for interoperabilityExamples where no template is recommended for interoperability purposes
Membership managementMembership Management
AUPWISE AUP
Privacy Policy
REFEDS privacy notice
AAOPSAttribute Authority Operational Security
Security Operational BaselineSecurity Operational Baseline
Incident response procedure EOSC, UK-IRIS, AARC federated incident response procedure



-------

Full Trust Framework links


An analysis of the improvements required on PDK v1 is included in https://doi.org/10.5281/zenodo.15506826 







  • No labels