...
Quorum | Status |
---|
colour | Yellow |
---|
title | not quorate |
---|
|
|
---|
Notes-Status | Status |
---|
colour | Blue |
---|
title | draftingReady for review |
---|
|
|
---|
Approved-Link | TBD |
---|
Info |
---|
The meeting status metadata table is used for summary reports - copy the status macros from the table in these instructions: Quorum: Status |
---|
colour | Yellow |
---|
title | not quorate |
---|
|
Notes-Status: Status |
---|
colour | Blue |
---|
title | Ready for review |
---|
|
Approved-Link: Insert a link to the Meeting Notes page holding the approval decision for this notes page |
Agenda
Administration:
Roll call, determination of quorum. The meeting was not quorate.
Minutes approval
Kantara Updates
Assurance Updates
IAWG Actions/Reminders/Updates:
ISO 17065 Discussion Items
Group Discussion:
AOB
\uD83D\uDC65 Attendees
Voting: Jimmy Jung, Michael Magrath, Andrew Hughes, Yehoshua Silberstein, Richard Wilsher, Vladimir Stojkovski
Regrets: Mark King
...
Non-voting:
Staff: Amanda Gay, Kay Chopard, Carol Buttle
Guests:
Quorum determination
Meeting is quorate when 50% + 1 of voting participants attend
There are <<nn>> <<7>> voters as of <<YYYY<<2024-MM11-DD>>07>>
Approval of Prior Minutes
...
\uD83D\uDDE3 Discussion topics
Time | Item | Presenter | Notes |
---|
| | Group | Last meeting recap: Group consensus that the unobservable/unassessable criteria do pose some risk and there should be something in place Clear direction/statement/risk based approach is needed to handle these things posed rev. 4/rev 3 Supplement.
Mike M: reports NIST got over 2K comments to work through. Carol: notes continued inconsistencies in language that could be problematic. Agrees on a risk-based approach but clarity from NIST regarding an acceptable level of risk would be needed for assessment purposes. Andrew H: Considers the risk related to the unobservable criteria to be between the CSP and federal agencies, what can we ask the CSP to have in place to identify/accept that risk? Include something in the agreement/terms of service? Richard: Proposes a notice referencing the affected criteria and the unobservable nature/unassessability of such criteria and how the applicability of that criteria will be recorded. It would be easier to change/modify notices and criteria as things move forward with NIST guidance. Carol: Notices can be a really useful functional tool in clarifying what’s in/out of scope. Kantara may need a more formalized/detailed approach to notices with references included in TSL, SoCA, etc. Notice could include recommendation(s) to CSPs for how to proceed. Goal would be a single source, easily accessible document.
Group consensus on notice/SoCA approach for handling syncable authenticators. Richard’s note in chat: Notice 2024-01: Accommodation of Passkeys Use of Passkeys presents difficulties when Kantara assessments are confronted with criteria for which the CSP is unable to provide evidence of conformity because the referenced functions are beyond their control or even awareness because the related functions are within the Passkey implementation fabric. Consequently KI’s Assessors are therefore unable to determine meaningful findings with regard to such criteria. Furthermore, industry is faced with widespread adoption of Passkeys and their very ubiquity establishes them as an established practice that they cannot be ignored. Accordingly, CSPs which deploy Passkeys shall mark the criteria listed below as having the following applicability: “In scope – Not applicable Refer to KI Notice 2024-01”
Also needed: List of affected criteria Notice is the path to take. ACTIONS: Additional work: Richard: still sees errors on TSL (definitions); Carol will be working on soon. Some nonmaterial things still need publication and further breakdown of acceptable combinations of evidence. Andrew/Carol to discuss.
|
| | | |
| | | |
✅ Open Action items
- Richard W: Consolidate list of affected criteria and propose notice language
- Andrew/Staff: Review/Develop a Kantara process for managing/publishing notices.
Info |
---|
Action items may be created inline on any page. This block shows all open action items from all meeting notes. |
...