ad-assurance - Re: [AD-Assurance] Applying FISMA to 800-63
Subject: Meeting the InCommon Assurance profile criteria using Active Directory
List archive
- From: David Walker <>
- To:
- Subject: Re: [AD-Assurance] Applying FISMA to 800-63
- Date: Tue, 30 Apr 2013 14:00:54 -0700
- Authentication-results: sfpop-ironport01.merit.edu; dkim=pass (signature verified)
We've been getting into a lot of details recently, and I'm afraid we may lose our way. Stepping back a level or two, here's where I think we are:
Applying this thinking to the "requirements and gaps" matrix on the wiki ( https://spaces.internet2.edu/x/BA8wAg ), I think we need to address the following issues:
Sound reasonable? It's fascinating to dive into all these standards documents in such detail, but I fear it may be distracting from our purpose. (I do think, though, that we need to do some detail-level due diligence with Microsoft. I'll send a separate note about that.) David On Tue, 2013-04-30 at 16:57 +0000, Eric Goodman wrote: I was calling out that the Kantara Specs, while looser, are just as vague as InCommon’s or 800-63 as it applies to the definition of “equivalent” algorithms. From: [mailto:] On Behalf Of Ann West All, Kantara spec is technically comparable to ours and 800-63 and has been reviewed by FICAM as well. If they interpret things a bit looser in the requirements, it's a big clue that we can follow suit. ------- I do note that this is a little looser than what we’ve been discussing, as it only applies to intra-IdP-service communication over public and unsecured networks. |
- RE: [AD-Assurance] Applying FISMA to 800-63, (continued)
- RE: [AD-Assurance] Applying FISMA to 800-63, Eric Goodman, 04/26/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/25/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/25/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/25/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, Ann West, 04/29/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Rank, Mark, 04/29/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Eric Goodman, 04/29/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Rank, Mark, 04/30/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, Ann West, 04/30/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Eric Goodman, 04/30/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/30/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/30/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/30/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Rank, Mark, 04/29/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, Ann West, 04/29/2013
- RE: [AD-Assurance] Applying FISMA to 800-63, Capehart,Jeffrey D, 04/25/2013
- Re: [AD-Assurance] Applying FISMA to 800-63, David Walker, 04/25/2013
Archive powered by MHonArc 2.6.16.