Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL

Slides:



Advertisements
Similar presentations
Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Advertisements

Grid Security Policy David Kelsey (RAL) 1 July 2009 UK HEP SYSMAN Security workshop david.kelsey at stfc.ac.uk.
Grid Security Users, VOs, Sites OSG Collaboration Meeting University of Washington Bob Cowles August 23, 2006 Work supported.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group Summary EGI TF David Kelsey 6/28/
3 Dec 2003Market Operations Standing Committee1 Market Rule and Change Management Consultation Process John MacKenzie / Darren Finkbeiner / Ella Kokotsis,
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
Operational Security Working Group Topics Incident Handling Process –OSG Document Review & Comments:
Second expert group meeting on Draft fiche on delegated act on the European code of conduct on partnership (ECCP) Cohesion Policy
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
JSPG: User-level Accounting Data Policy David Kelsey, CCLRC/RAL, UK LCG GDB Meeting, Rome, 5 April 2006.
NMWG GGF13 Seoul March 2005 R. Hughes-Jones Manchester Network Measurements Working Group Discussion: Current Work & Milestones Richard Hughes-Jones NM-WG.
Draft Model Manufacturer Agreement Medicare Coverage Gap Discount Program Public Meeting June 1, 2010.
INFSO-RI Enabling Grids for E-sciencE EGEE/LCG Joint Security Policy Group David Kelsey, CCLRC/RAL, UK EGEE.
10-Jun-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 10 June 2003 David Kelsey CCLRC/RAL, UK
13-Jul-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint LCG/EGEE Security Group) CERN 13 July 2004 David Kelsey CCLRC/RAL,
Madrid, 15th June rd SG Meeting South Gas Regional Initiative.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
9-Sep-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) CERN, 9 September 2003 David Kelsey CCLRC/RAL, UK
8-Jul-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) RAL, 8 July 2003 David Kelsey CCLRC/RAL, UK
Security Vulnerabilities Linda Cornwall, GridPP15, RAL, 11 th January 2006
3-Jul-02D.P.Kelsey, Security1 Security meetings Report to EDG PTB 3 Jul 2002 David Kelsey CLRC/RAL, UK
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks JSPG Status and plans EGEE’06 Conference.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 November 2007.
Mtivity Client Support System Quick start guide. Mtivity Client Support System We are very pleased to announce the launch of a new Client Support System.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
Grid Operations Centre LCG SLAs and Site Audits Trevor Daniels, John Gordon GDB 8 Mar 2004.
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Grid Security Vulnerability Group Linda Cornwall, GDB, CERN 7 th September 2005
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
RMDSRMDS Retail Market Design Services 1 IGG Agenda – March 8 th 2007 Minutes from last IGG meeting10.00 – Review of Action Items10.10.
2-Sep-02D.P.Kelsey, WP6 CA, Budapest1 WP6 CA report Budapest 2 Sep 2002 David Kelsey CLRC/RAL, UK
DTI Mission – 29 June LCG Security Ian Neilson LCG Security Officer Grid Deployment Group CERN.
Due Process – ISSAIs and INTOSAI GOVs Roberto José Domínguez Moro Superior Audit Office of Mexico INTOSAI Working Group on Public Debt June 14, 2010.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
Advocacy and Legal Advice Centre - Internal procedures -
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
LCG User Level Accounting John Gordon CCLRC-RAL LCG Grid Deployment Board October 2006.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
Security EGEE/SA1 ROC Managers ARM-3 meeting Lyon, 17 March 2005 David Kelsey CCLRC/RAL, UK
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
12-Jun-03D.P.Kelsey, CA meeting1 CA meeting Minimum Requirements CERN, 12 June 2003 David Kelsey CCLRC/RAL, UK
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.
Planning for LCG Emergencies HEPiX, Fall 2005 SLAC, 13 October 2005 David Kelsey CCLRC/RAL, UK
Last update 13/03/ :11 LCG 1Maria Dimou- cern-it-gd Maria Dimou IT/GD Status of the Task Force for User Registration of LHC Experiment Users
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
7-May-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Issues and Planning or Report from the Security Group CERN, 8 May 2003 David Kelsey CCLRC/RAL, UK.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI VOMS Proxy Lifetime UCB 21 Aug 2012 David Kelsey STFC.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
15-Jun-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) CERN 15 June 2004 David Kelsey CCLRC/RAL, UK
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
Implementation Review Team Meeting
David Kelsey CCLRC/RAL, UK
Open Science Grid Consortium Meeting
Global Grid Forum GridForge
David Kelsey CCLRC/RAL, UK
David Kelsey CCLRC/RAL, UK
Outcome TFCS-11// February Washington DC
OFFICE OF THE CITY CLERK SEPTEMBER 22, 2014 CITY COUNCIL MEETING RESCIND RESOLUTION NO AND ADOPT A RESOLUTION ESTABLISHING THE RULES GOVERNING.
Mark S. Orloff, MD Regional Councillor
Update - Security Policies
Elizabeth A. Pomfret, MD, PhD Regional Councillor
Wealth Management Meeting Asset Management Execution
Presentation transcript:

Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL

4 Apr 2007JSPG - D Kelsey2 Overview JSPG meeting was held at CERN on 13/14 March 07 –Discussed many things including these docs … Grid Site Operations Policy Grid Security Policy –top-level document “Logged Information” Policy –Accounting privacy issues Other documents –Security Audit Requirements –VO Operations Policy

4 Apr 2007JSPG - D Kelsey3 Grid Site Operations –Draft V1.3, 31 Mar 2007 Document with a long history (JSPG started June 06) –Mentioned in at least four GDB meetings! –Discussed at length on several lists Since Feb 07 GDB –Reworded point 4 (Need to apply patches) –Added point on dispute resolution –Several other changes to wording Bob Jones (EGEE) has just raised issue of IPR –Sites need to agree that IPR remains with the VO Or is this in some other document?

4 Apr 2007JSPG - D Kelsey4 Some of the points 4. When notified by the Grid of software patches and updates required for security and stability, you shall, as soon as reasonably possible in the circumstances, apply these to your systems. Other patches and updates should be applied following best practice. 10. Disputes resulting from your participation in the Grid will be resolved according to the Grid escalation procedures.

4 Apr 2007JSPG - D Kelsey5 Site Policy (2) We also need –Covering paper per Grid explaining all the terms of the policy and pointers to policy docs etc –This also explains how JSPG maintains policy, how stakeholders are consulted and how the policy is approved and adopted –Draft for EGEE exists (see same EDMS link) Only makes sense to ask Sites to sign this document when new top-level policy is approved and adopted BUT, we are seeking approval ~NOW for the general common wording (OSG, EGEE, NDGF)

4 Apr 2007JSPG - D Kelsey6 Grid Security Policy New top-level document –To replace very out of date LCG-specific version See V5.4 (11 Dec 2006) –Distributed at that time –Very little feedback to date (but OSG happy) V5.5 nearly ready (following JSPG March meeting) –Reworked definitions section More consistent use of “defined terms” (italics) –Reordered section 2 (Roles and Responsibilities) –Many other minor changes Aim for approval in May 07

4 Apr 2007JSPG - D Kelsey7 Consistency, duplication of words, plans for future… JSPG sees –Duplication of descriptions between top-level document and sub-documents –Inconsistencies between top-level wording and sub- documents and between sub-documents –Top-level document is still too long BUT… Replacing the very out of date version is urgent –Also needed for sites and VO’s to “sign” Decided –V5.5 should be good enough for approval as is –Will then work over next year on better consistency EGEE-III aim will be to take policy forward into the National Grid world (many NGI’s)

4 Apr 2007JSPG - D Kelsey8 “Logged Information” Policy Long overdue policy document to allow collection and handling of user-level accounting information Issues have been discussed at length last year JSPG decided to have one document covering all types of operational data: audit logs, accounting, monitoring, debug, etc Data classification agreed at the JSPG meeting Not sure of the exact title –But “Logged information” are the words used in the Grid AUP and Site Policy Rough draft exists –Not yet in EDMS Aiming for next GDB meeting

4 Apr 2007JSPG - D Kelsey9 Logged Information classification Private –Contains sensitive personal data –Grid Operations does not create, store or handle such data Personal –Name, Institute, address, X.509 DN Non-public –To be kept confidential within site and/or VO Security considerations, confidentiality Public –World readable – no stipulations Grid needs to have policy for two in red VO’s and applications are responsible for their own data handling –i.e. application data (e.g. bio-medical) –This document will not address this

4 Apr 2007JSPG - D Kelsey10 Other topics Audit Policy –Current document is very out of date –A new draft (short and simple policy) is being worked on Implementation details will be available from a Grid- specific web New VO Policy document –An agreement that VO’s sign during registration Similar to the Site Operations policy –Draft now exists (thanks to OSG) Not yet in EDMS Discussion has started

4 Apr 2007JSPG - D Kelsey11 Requests to GDB Please approve the Grid Site Operations Policy (V1.3) –Document is in “final call” Not expecting any major changes (except IPR?) –I propose I send an to all the lists Giving a 3 week deadline for final comments Please comment on new policy documents –Grid Security Policy –Logged Information Policy –Plan to send both to GDB (and EGEE, OSG etc) two weeks before the next meeting (i.e. on 18 April)

4 Apr 2007JSPG - D Kelsey12 JSPG Meetings, Web etc Meetings - Agenda, presentations, minutes etc JSPG Web site Membership of the JSPG mail list is closed, BUT –Requests to join stating reasons to D Kelsey –Volunteers to work with us are always welcome! Policy documents at