Skip to Content.
Sympa Menu

assurance - Re: [InC Assurance] Assurance Toolkit: What's in it?

Subject: Assurance

List archive

Re: [InC Assurance] Assurance Toolkit: What's in it?


Chronological Thread 
  • From: Mark John Rank <>
  • To:
  • Subject: Re: [InC Assurance] Assurance Toolkit: What's in it?
  • Date: Thu, 4 Aug 2011 09:47:43 -0500 (CDT)



omb-0404 is good... nist approved algorithms site would be good as well

http://csrc.nist.gov/groups/ST/toolkit/secure_hashing.html#Approved%20Algorithms

Mark


------------------------------------------
Mark Rank, Middleware Architect
University Information Technology Services
UW-Milwaukee
Email:


Phn: 414-229-3706
------------------------------------------

----- Original Message -----
From: "Ann West"
<>
To:

Sent: Thursday, August 4, 2011 9:44:18 AM
Subject: Re: [InC Assurance] Assurance Toolkit: What's in it?

Yep. Good idea. I assume 800-63 would be used as background or if one wanted
to get another take on LoA? Also to understand the providence for
Bronze/Silver?


I would think OMB-0404 should be included for SPs then and that reminds me
that we'll need to include guidance for how to assess services for assurance
levels. For instance, I talked to one non-InCommon library vendor about LoA
and he thought his abstract service should probably be Silver.


Or maybe the market place will sort that out?





Ann

----- Original Message -----




links to supporting docs (NIST 800-63 for example)

Mark

------------------------------------------
Mark Rank, Middleware Architect
University Information Technology Services
UW-Milwaukee
Email:


Phn: 414-229-3706
------------------------------------------

----- Original Message -----
From: "Ann West"
<>

To:


Sent: Thursday, August 4, 2011 9:18:59 AM
Subject: [InC Assurance] Assurance Toolkit: What's in it?

Hi All,

What tools, documents, guidance would you like to see in a toolkit for
implementing assurance?


Below is a brainstormed list to get us started:






- Auditor guidance (what should be in the summary report, how long an audit
is expected to take, suggestions from peer auditors)
- Submission Templates
- Case studies on how others have satisfied the certification requirements
- Checklist for certification (includes actions and documents to submit)
- Assurance Addendum to Legal agreement


What's missing? Needs clarification?


Ann
















--
Ann West
Internet2/InCommon/Michigan Tech




office: +1.906.487.1726




Archive powered by MHonArc 2.6.16.

Top of Page