Despite all potential differences between user communities, research infrastructures, federations, identity providers, and e-Infrastructures, they all work towards a common goal. And they are sufficiently alike that they might share some common policy frameworks. While it is always tempting to make ad-hoc policies, an open research commons benefits hugely from mutual understanding based on set of a harmonized policy frameworks and ways to compare the various best practice aspects.
The Policy and Best Practice Harmonisation activity works on operational and security aspects and policies to complement the technical research work carried out in the architecture and the infrastructures, and delivers a set of recommendations and good practices to implement a scaleable and cost-effective policy and operational framework driven by the use cases from the AARC Community. Policy harmonisation produces both generic guidelines (such as on operational security and traceability for proxies, acceptable use policy matching, and trust and assurance models) as well as specific guidelines for communities that are implementing the Blueprint Architecture.
In-person meeting: PMA+ October 2026 meeting
In-person AARC Policy Coordination meeting (remote participation possible of course) at the joint AARC/IGTF/EOSC/GN-EnCo+ Ljubljana meeting, October 19-21 2026.
Policy Development Kit
The AARC Research Collaboration model is both the set of technical guidelines and interfaces in the AARC Blueprint Architecture (BPA) as well as the trust framework that helps research collaboration bridge across domains, sectors, and borders: the guidelines for end-to-end trust across the components for collaboration management, user privacy, identity assurance, and operational security. This Policy Development Kit (PDK) helps new and existing collaborations to build those trust relationships into their AAI and benefit from the combined experience of the infrastructures, collaborations, researchers and research managers, and trust and security engineers to quickly build that trust in our AARC connected world.
- Policy Development Kit 2026 Online
- Sirtfi, the Security Incident Response Trust Framework for Federated Identity
- Snctfi: organised trusted proxies though verifiable (peer-reviewable) assessment
Work items
Recently completed documents and guidelines
- AARC-G084 - Security Operational Baseline (public page: https://aarc-community.org/guidelines/aarc-g084/)
- AARC-G083 - Guidance for Notice Management by Proxies
- AARC-I082 - Trust framework for proxies and Snctfi research services
- EU Identity Wallets (VCs) and assurance step-up
Policy activities are continuously evolving
- Security Incident Response in federated environments
- including guidelines on how to property protect your community attribute system
- and how to prepare and what to do in case of incidents
- traceability of events through a (network of) AARC BPA Proxies
- Service- and Infrastructure-centric policy support, including
- e-Researcher centric policies,
- simplified policy development kit also for smaller and mid-sized communities
- alignment of Acceptable Use Policies
- Assurance Level baseline and differentiated assurance profiles (alongside a self-assessment tool) including the use of government e-ID for step-up of assurance
- untangling identity assurance framework complexity
- novel federation models and trust paths (e.g. in OpenID Connect Federation)
- Engagement and coordination with FIM4R and the global community
- Support for Infrastructures and Communities with the Policy Development Kit (PDK)
Lastly, it is imperative that any policies are agreed to in a scalable way: bi-lateral agreements do not work in a multi-stakeholder environment. The work on scalable policy negotiation addresses this issue by exploring ways of expressing and agreeing policy in a federated world: Snctfi.
| Take the slide tour, or read our whitepapers and guidelines |
|---|