Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Hello everyone 

This is the running update from the Executive Director. Have questions or comments? Suggest some added information or edits? Contact Colin at kantarainitiative dot org.

...

This Director's Corner for September comes a few days late, such is the level of activity in Kantara in recent weeks.  Some of it has been announced but there is another major announcement scheduled for this week with more beyond.    

Last month I mentioned how governments around the world are announcing intention to bring in legislation regarding digital identity, within a few weeks (even days!) of each other. So when I was asked by Think Digital Partners to write a piece as part of my role there on its Advisory Board, I chose to write about this topic. It is quite intriguing in one sense given just how close these announcements are to each other. But in another sense it is kind of understandable, and I go on to talk about why that might be, as well as share the scope of legislation to the extent that I am aware of it. My observations are broadly restricted to the 'five nations' common law countries because I am most familiar with them but also three of the five are Kantara members. You'll hear more on that this coming week! 

I do think that there is a pattern emerging .. Kantara has a highly reputable, globally recognized assurance program fr accrediting assessors and approving applicant service providers' solutions to be conformant with a given standard - NIST 800-63-3 being most sought after in recent times. COVID-19 has put the spotlight on the need for more digital interaction with government by its citizens and consumers more broadly. Digital identity is fundamental to addressing those interactions especially if they are higher risk transactions for payments and such like from Government. Ergo, public sector interest in Kantara.  

Remember that the Assurance Program uses the open and transparent structure of the IAWG to develop the assessment criteria, comprised as it is, with experts from the private, public and Higher Ed sectors as well as individuals. And all the working groups have the potential to act as steward for the frameworks and the assessment criteria for conformance to standards within those frameworks, just as the IAWG does for the Identity Assurance Framework.  Alongside developing submissions to calls for contributions on digital identity-related matters as part of its global civic duty as an international commons unimpeded by barriers to participation as most non profit industry associations are, it also develops the assessment criteria needed for the accredited assessors as a group to consistently assess and report their findings for applicant service provider solutions. To these dual ends, the IAWG has had a huge few months. Firstly, it the IAWG developed the level 3 criteria for N800-63-3 IAL3, AAL3 and FAL3 that are coming to the end of their All Member Ballot period. (NOTE BENE: If you are the primary representative of your organization or an individual member, please do your duty to the community by casting your vote on this important work). Secondly, last week it the IAWG completed and submitted its input to the open public consultation is on the European Union's eIDAS regulation. Thank you individual contributor member Mark King leading the active and animated discussion at meetings and on the list regarding this, and to Staff (Ruth) who took it down on the final straight towards submission from (appropriately) from Kantara Initiative Europe. 

Last month I mentioned that material progress had been made on the long-waited Kantara mDL Discussion Group, with Kantara Individual Contributor member , and globally acknowledged privacy expert, John Wunderlich did just that. Juggling his client work, along with a stint temporary stint as Chair of the ISI-WG, John also put his hand up to spin up the much anticipated Kantara mDL Discussion Group. This DG successfully proposing a Charter to the Leadership Council. This DG - actually called the 'Privacy & Identity Protection in mobile driving license ecosystems' , the PImDL DG)  will focus on rounding out the ISO 18013-5 mDL standard's privacy and security recommendations in Annex E - a critically essential success factor to enable the development of the fledgling global mDL ecosystem.  Some of you may have seen and heard John (and Kantara President Matt) speaking on Secure Technology Alliance's Webinar #3 (note that there were some technical issues impacting this session but it is being re-recorded). Our collective hats off to you John Wunderlich. We applaud your quiet resolve and magnanimity. Give John, and the Leadership Council, a few weeks to get the Charter approved and for Staff to build the wiki space and we will let you know when the site is up and the GPA ready for you to acknowledge.   The IAWG also completed work sponsored by ID.ME to develop Service Assessment Criteria (SAC) at Assurance Level 3 for Identity Assurance (IAL3), Authentication Assurance (AAL3), and Federation Assurance (FAL3) of NIST’s SP 800-63 Revision 3.  These SAC are currently undergoing Public and IPR Review. Thanks to ID.ME for its support in developing this important part of Kantara’s Identity Assurance Framework.          Staff are building the wiki space as you read this, so stand by for the official announcement and the link to acknowledge the Group Participation Agreement later this week.    

Kantara Europe was busy as usual coaching existing NGI_Trust projects and, as mentioned last month, working with a large consortium on a new funding bid for 2021. It‘S project name is Demoiselle with a focus on Long Term Security of Systems, Systems of Systems and Organizations & Societies all through policy, process and technology planes.  This is more IoT oriented than Kantara's traditionally known core capabilities but, with IDoT becoming so relevant now and having the global reach to expertise that we do, the consortium sought out Kantara to fill this much needed gap in its enviable line-up of partners.    

...

Program, Work Group and Discussion Group Updates:

  • You can always keep up with the latest news from the Work and Discussion Groups directly on the Leadership Council's Blog. See the list of public groups here.

...