Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Attendees:

...

Minutes approval:    Andrew reminded everyone to please carefully review this summer’s meeting minutes to review what has been discussed around the assurance program updates. Discussions around the assurance program started at the June 9 meeting.

Martin Smith moved to approve the draft minutes from the August 11 IAWG meeting. Maria Vachino seconded the motion. Motion carried with no objections.

General Updates: n/a

Assurance Updates:

...

Lynzie will send a separate email calling for volunteers interested in leading this project. It will consist more of collecting comments and compiling a response in the timeframe provided. At our September 1 meeting, we will have a brief discussion to determine whether we move forward with submitting comments or not. Denny mentioned his colleagues already have comments. Andrew shared that those comments can be routed through Kantara or submitted directly from their organization. That determination can be made internally.

63b SoCA Proposal63B SoCA Proposal

Lynzie and Richard reviewed the proposed changes to 63B#0650, #0660, and #0670 and the analysis of current CSPs that would be impacted by the change being made. The group agreed that these are non-material changes.

Motion:
Andrew moved that IAWG has determined that the modification to criteria 63B#0650, #0660, and #0670 related to hashing and salting of secrets is non-material and therefore can take the accelerated route to publish. Jimmy seconded the motion. Motion carried with no objections. 

Richard reviewed the proposed change to 63B#1820. In re-reading the NIST text, Kantara is asking CSPs to reestablish authentication under any circumstance when actually NIST recognizes this only when the claimed identity was established at IAL3. It needs clarified. This will not impact any current CSPs because nobody currently is approved at IAL3. There was a discussion whether it was a material change or not. Jimmy believes it is just a correction. It was agreed that it is not material.

Motion:
Andrew moved that we accept the proposed changes to criteria 63B#1820 (all parts) clarifying the requirements to reestablish proofing for IAL3 cases and accept this as a non-material change for the accelerated process. Jimmy seconded the motion. Motion carried with no objections. 

SAC Update

With these final updates being passed by IAWG and not needing to go through the full public comment period and all-member ballot, Lynzie intends to have all new SAC sets published by 8/31/2022. Kantara policy states new criteria are effective on the first day of the fourth month after publication, making these effective on December 1, though it is encouraged to adopt as soon as possible. An email will go out to all assessors and current CSPs letting them know updates were made and the new versions will need to be used in their next assessment cycle.

...

Due to IAWG leadership travel, September 8 and 29 meetings are cancelled.

IAWG leadership keeps an action item list.
All IAWG participants should be aware that the spreadsheet exists and it lists everything we think the IAWG is working on or planning to work on. Please feel free to review it and correct it if needed - it is not our intent to overlook something!

...