UPDATE ......Confluence has now been updated to version 9.2.6. Please see following page for details and feedback about changes:
Updates
...
- Stronger Security and Trust
Wallets holding academic degrees, research access credentials, or institutional identifiers would be certified under a high-assurance standard—boosting trust among education institutions and researchers. - Cross-Border Interoperability
Certification harmonisation across EU countries allows students, researchers, and academic staff to use their credentials seamlessly across different Member States' institutions and services. - Data Protection and Privacy Safeguards
These wallets must adhere to data protection rules (e.g., GDPR), offering users better control over sharing personal data like student IDs or research affiliations. - Secure Cryptographic Infrastructure
Research-sensitive credentials—like access to labs or e-signatories—will be protected by certified cryptographic technologies, including WSCDs, promoting both security and compliance. - Risk Management and Lifecycle Oversight
Certification schemes will require robust incident handling and updates for educational wallets—important for vulnerability-prone tools used in academia and research. - Future European Standards Alignment
In time, education and research wallets will benefit from the upcoming EU-wide certification scheme and peer collaboration with ENISA, supporting scalability and mutual recognition across sectors.
Related Standards
- EN ISO/IEC 15408-3:2022 (AVA_VAN.5)
Mentioned in Annex IV for vulnerability assessment of the Wallet Secure Cryptographic Device (WSCD), requiring evaluation at this specific level. [1] - EN ISO/IEC 30111:2019
Referred to in the context of vulnerability management processes that certificate holders must establish. - Regulation (EU) 2015/1502
Cited as the implementing regulation defining the "high" assurance level requirements applicable to wallet solutions. [1] - Regulation (EU) 2019/881 (EUCC – European Common Criteria Certification Scheme)
Mentioned as the voluntary cybersecurity certification scheme to be referred to when available and relevant. [1]
...
[3] european-accreditation.org
اگر می خواهید متن اصلی این آیین نامه را با بخش های کلیدی برجسته بررسی کنید ، لطفاً این پرونده را ببینید.