...
- Define a unique name for your collaboration (we recommend a DNS name to avoid collisions)
- Identify a governance body to make policy decisions
- Define the purpose of your collaboration (this will be used for your AUP)
- We strongly suggest
- Identifying your primary assets
- Completing a risk assessment
- Defining your rules of participation and the escalation procedure in case of non-compliance
- Identifying any additional legal and regulatory compliance necessary
- Define the following documents and seek endorsement from your governance body
Document
AARC Template
Example (where no template is recommended)
Attribute Authority Operational Security Policy
Acceptable Use Policy
Incident response procedure
Membership management
Privacy Policy
Security Operational Baseline
- Review the AEGIS endorsed policy guidelines required for AARC compliance and ensure their technical implementation such as
- Identify your assurance requirements following AARC-G031
- Identify suitable token lifetimes following AARC-G081
- Ensure that the policies are presented to and accepted by the relevant audiences (e.g. service operators, end users)
- Publish your documents and responsible parties at a suitable location
| Info | ||
|---|---|---|
| ||
The steps above will be elaborated in a future version of the AARC Policy Development Kit to be released in January. We strongly suggest leveraging this work for the following reasons:
|