Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Attendees:

...

  1. Administration:
    • Roll call, determination of quorum
    • Agenda confirmation
    • Minutes approval - 2021-09-23 DRAFT Minutes and 2021-10-07 DRAFT Minutes
    • Staff reports and updates
    • International liaisons updates
    • LC reports and updates
    • Call for Tweet-worthy items to feed (@KantaraNews)

  2.  Discussion: 
    • Update on open issues regarding the pending package of proposed criteria changes
    • Initial discussion on component services

  3. Any Other Business and Next Meeting Date

Meeting notes 

Administrative Items:

IAWG Chair Ken Dagg called the meeting to order at 1:04PM (US Eastern).  Roll was called. Meeting was quorate. Distributed agenda was confirmed. 

Minutes approval:  Martin   Martin Smith moved approval of the draft Minutes of the IAWG meetings of September of September 23 and October 7. Mark Hapner seconded. The minutes as distributed were approved unanimously.

Staff Reports and Updates:

Lynzie reported the first organization seeking FAL certification has reached hr out. They are still a few months out from getting started but wanted to begin learning more. Numerous other organizations have been reaching out with interest in Kantara certification - including companies from Korea, Japan, and India who are looking to get into the US market and believe a Kantara certification can assist them with that. 

...

  • OSIA (France):  They are not looking for a new assurance program, it's a much smaller scale project. Conversations are continuing of how we can fit into their future. 
  • UK:  Had a meeting regarding certification and seemed positive. They are interested in Kantara pursuing certification - allows Kantara to be a certifying body in the UK. Similar to Kantara/GSA, but more formalized. Mark King asked if Kantara is part of the International Accreditation Forum. It's relevant for international collaboration. Nobody was sure at the moment but we will revisit. Mark King shared the link: https://iaf.nu/en/home/ 
  • New Zealand:  They requested a meeting but this has not occurred yet. 
  • Australia:  Continued discussions are occurring with Jonathan Thorpe. Mark King reviewed Australia's Draft Law document and it seems much we said was not taken into consideration nor was there a response as to why much of this was overlooked. Ken asked to send IAWG's apologies that we were not able to address the latest request. 

Ken requested adding this new 'international liaisons updates' standing agenda item becausegiven the amount of work we've done in the past for other governments. We tend to get involved in a lot of these things and it is part of the mandate of IAWG to know what is going on around the world and aide them. 

LC Reports and Updates:

A new working group, "Privacy Enhancing Mobile Credentials" is being set up. John Wunderlich is the chair. If you'd like to join, reach out to Ken and/or John.

...

The ARB shared concerns with the IAWG how the assessment views component services, particularly what requirements are the responsibility of the full service and what is the responsibility of the component service. This raised the general question - What kind of requirements do we place on a full service and what do we place on a component service? ARB feels a general review of criteria to consider how it works with a component service could be beneficial. Ken was unsure if a review of criteria in scope of a supportive such a review has occurred. Jimmy worries it could be a complicated lift to address this

Martin suggested we address the question that if a component service is being addressed what does the contract say it is responsible for? Ken wants to consider a need for a contract between the parties that clarifies the relative responsibilities. Have we addressed what the contract has to cover when a component service is in use? Ken will review the CO_SAC to consider this and it may be a good starting pointfor any contractual obligations already listed and see if this is a place we could clarify

Ken asked everyone to think on it more and we will address at further on the next call. 

Other Business:

Eric requested any feedback asked if anyone heard any updates or any movement on NIST 800-64-4? Currently we have noneWe submitted feedback on the last call for feedback. Nobody has heard anything further at this point. Kay will ask David Temoshok if there are any updates besides what NIST has already published. 

...