Policy Development Kit
Hannah Short (CERN)�WISE and SIG-ISM, Virtual 2021
Today
2
Introduction
3
Policy Development Kit - Background
4
Policy Development Kit - Process
5
Policy Development Kit - Considerations
Policy pack must be:
Implications:
6
Policy Development Kit - Content
7
Policy Development Kit - Content
The policies presented are relevant for an Infrastructure operating a Service Provider Proxy that represents the bound set of services in an identity federation. The policies are to be adopted by the Infrastructure itself and, where appropriate, additional policies are suggested for Infrastructure participants such as Services, User Community Management or Users. The Infrastructure may be for the sole use of a single Research Community, or may provide computing services to multiple Research Communities; the policies presented are designed to be flexible.
8
Actually, the policies can be applied much more broadly as we will see...
Policy Development Kit - Content
9
Policy Development Kit - Content
10
Policy Development Kit - Use
11
Evolution
12
Evolution
13
Infrastructure | Changes | Comment | Link |
HIFIS (previously HDF) | Initial users (and one of main contributors) | | |
ELIXIR | Added Terms of Use | Focused on the AAI only rather than the entire Infra. Dropped Top Level | |
IRIS | Significantly modified Top Level policy and Service Operations Security Policy | Emphasis on standalone, short policies | |
EOSC | Built from IRIS’s Service Operations Security Policy | Much more loosely coupled infrastructure than anticipated by PDK |
Comparison table
14
Current work
15
Questions & Feedback
16
Working Session
17
Today, focus on the Secure Service Operations Policy
18