Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

GSA (home agency for FICAM) has joined InCommon, Looks like   GSA will likely be the focal point for other agencies.

...

  • In addition to the FICAM-based Bronze and Silver profiles, there are community needs, such as for an MFA profile.
  • Ability to assert Multi Factorness to a provider like Workday, would be triggered based on a need to access a financial record.
  • Also need to replace the POP approach of "Post your Practices" and have baseline practices

Steve Devoti, AAC chair, reported

  • The AAC is working to revise its charter to do more than manage the assurance process for certification. This does not expand a lot the AACs charge. But it is broader than managing a process.
  • The AAC is looking at what needs to be modified to increase trust within the federation. This does not expand a lot the AACs charge. But it is broader than managing a processThe goal is to get people on the road to higher trust and higher assurance.
  • We have received lots of feedback (from our SP partners) on the lack of usefulness of the POP and the lack of Compliancecompliance. Some InCommon participants are not updating their POPs.
  • We have talked about decomposing the assurance profiles into trust marks to drive incremental progress within the federation.The goal is to get people on the road to higher trust and higher assurance.
  • There is work at GA Tech on Trust Marks https://trustmark.gtri.gatech.edu/the-pilot/

...

https://www.ietf.org/mail-archive/web/ietf-announce/current/msg13215.html

  The UC system is are is taking a similar approach in standards, for incremental progress short of silver.

...