Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk.

Slides:



Advertisements
Similar presentations
Grid Security Policy GridPP18, Glasgow David Kelsey 21sr March 2007.
Advertisements

Grid Security Policy David Kelsey (RAL) 1 July 2009 UK HEP SYSMAN Security workshop david.kelsey at stfc.ac.uk.
Authorization WG Update David Kelsey EU Grid PMA, Copenhagen 27 May 2008.
INFSO-RI Enabling Grids for E-sciencE Update on LCG/EGEE Security Policy and Procedures David Kelsey, CCLRC/RAL, UK
Proposal for a Constitution for MICE A Plan for Discussion P Dornan G Gregoire Y Nagashima A Sessler.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group Summary EGI TF David Kelsey 6/28/
HEPiX IPv6 Working Group David Kelsey (STFC-RAL, UK) 4 May 2011 HEPiX, GSI, Darmstadt david.kelsey at stfc.ac.uk.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
EGI: A European Distributed Computing Infrastructure Steven Newhouse Interim EGI.eu Director.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI Security Policy Group EGI Technical Forum Sep 2010 David Kelsey.
EGI: SA1 Operations John Gordon EGEE09 Barcelona September 2009.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
Security Update WLCG GDB CERN, 12 June 2013 David Kelsey STFC/RAL.
Towards the new EGI governance model Arjen van Rijn (Nikhef) Chair Organizational Taskforce (EGI_DS and Local Host)
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
Overview & Status of the Middleware & EGI Core Proposals Steven Newhouse Interim EGI Director EGEE Technical Director 26/05/2016 Status of EGI & Middleware.
WLCG Security: A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) CHEP2013, Amsterdam 17 Oct 2013.
Security Policy Update LCG GDB Prague, 4 Apr 2007 David Kelsey CCLRC/RAL
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks David Kelsey RAL/STFC,
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE-EGI Grid Operations Transition Maite.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Bob Jones EGEE project director CERN.
LCG/EGEE Security Operations HEPiX, Fall 2004 BNL, 22 October 2004 David Kelsey CCLRC/RAL, UK
15-Dec-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the Joint Security Policy Group) CERN 15 December 2004 David Kelsey CCLRC/RAL,
9-Oct-03D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security (Report from the LCG Security Group) FNAL 9 October 2003 David Kelsey CCLRC/RAL, UK
Summary of AAAA Information David Kelsey Infrastructure Policy Group, Singapore, 15 Sep 2008.
EGI-Engage Recent Experiences in Operational Security: Incident prevention and incident handling in the EGI and WLCG infrastructure.
EGEE-III-INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE-III All Activity Meeting Brussels,
Security Policy Update David Kelsey UK HEP Sysman, RAL 1 Jul 2011.
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) 1 st WISE, Barcelona 20 Oct 2015.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGI Operations Tiziana Ferrari EGEE User.
EGI-InSPIRE Steven Newhouse Interim EGI.eu Director EGI-InSPIRE Project Director Technical Director EGEE-III 1GDB - December 2009.
Ian Bird GDB CERN, 9 th September Sept 2015
Security Operations David Kelsey GridPP Deployment Board 3 Mar 2005
A Trust Framework for Security Collaboration among Infrastructures David Kelsey (STFC-RAL, UK) WLCG GDB, CERN 10 Jul 2013.
EGEE-III INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks Robin McConnell NA3 Activity Manager 02.
Security Policy: From EGEE to EGI David Kelsey (STFC-RAL) 21 Sep 2009 EGEE’09, Barcelona david.kelsey at stfc.ac.uk.
WLCG Laura Perini1 EGI Operation Scenarios Introduction to panel discussion.
Security Policy Update WLCG GDB CERN, 14 May 2008 David Kelsey STFC/RAL
EGI-InSPIRE RI EGI EGI-InSPIRE RI Service Operations Security Policy the new generalised site operations security policy.
PIC port d’informació científica EGEE – EGI Transition for WLCG in Spain M. Delfino, G. Merino, PIC Spanish Tier-1 WLCG CB 13-Nov-2009.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI SPG future work EGI Technical Forum Lyon, 21 Sep 2011 David Kelsey, STFC/RAL.
EGEE-II INFSO-RI Enabling Grids for E-sciencE EGEE and gLite are registered trademarks EGEE and JSPG activities David Kelsey CCLRC/RAL.
JSPG Update David Kelsey MWSG, Zurich 31 Mar 2009.
18-May-04D.P.Kelsey, LCG-GDB-Security1 LCG/GDB Security Update (Report from the LCG Security Group) Barcelona 18 May 2004 David Kelsey CCLRC/RAL, UK
Planning for LCG Emergencies HEPiX, Fall 2005 SLAC, 13 October 2005 David Kelsey CCLRC/RAL, UK
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Draft Security Virtualisation Policy (for Romain Wartel – CERN) EGI Technical.
INFSO-RI Enabling Grids for E-sciencE Joint Security Policy Group David Kelsey, CCLRC/RAL, UK 3 rd EGEE Project.
LCG User, Site & VO Registration in EGEE/LCG Bob Cowles OSG Technical Meeting Dec 15-17, 2004 UCSD.
LCG Pilot Jobs + glexec John Gordon, STFC-RAL GDB 7 December 2007.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Policy Development in EGI.eu/EGI-InSPIRE Damir Marinovic (EGI.eu)
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI Plans for PY2 Steven Newhouse Project Director, EGI.eu 30/05/2011 Future.
EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI VOMS Proxy Lifetime UCB 21 Aug 2012 David Kelsey STFC.
EGI-InSPIRE RI EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI EGI-InSPIRE EGI-InSPIRE RI
EGI-InSPIRE RI SPG Tasks for Year 2011 Jan 2011 Kelsey/Security Policy Group1.
EGI-InSPIRE RI SPG Tasks for Year 2011 Jan 2011 Kelsey/Security Policy Group1.
EGI-InSPIRE Project Overview1 EGI-InSPIRE Overview Activities and operations boards Tiziana Ferrari, EGI.eu Operations Unit Tiziana.Ferrari at egi.eu 1.
Grid Security Policy: EGEE to EGI David Kelsey (RAL) 16 Sep 2009 JSPG meeting, DFN Berlin david.kelsey at stfc.ac.uk.
EGI InSPIRE Report to the EGI Council Steven Newhouse On behalf of the Editorial Board.
Ian Bird LCG Project Leader Summary of EGI workshop.
Cloud Security Session: Introduction 25 Sep 2014Cloud Security, Kelsey1 David Kelsey (STFC-RAL) EGI-Geant Symposium Amsterdam 25 Sep 2014.
Security Policy Update WLCG GDB CERN, 11 June 2008 David Kelsey STFC/RAL
Ian Bird, CERN WLCG Project Leader Amsterdam, 24 th January 2012.
David Kelsey STFC-RAL 4th WISE workshop, Nikhef 27 March 2017
David Kelsey CCLRC/RAL, UK
Global Grid Forum GridForge
David Kelsey CCLRC/RAL, UK
David Kelsey STFC-RAL 2nd WISE workshop, XSEDE16, Miami 18 July 2016
NA3: User Community Support Team
David Kelsey CCLRC/RAL, UK
Input on Sustainability
Presentation transcript:

Security Policy Update WLCG GDB CERN, 8 Dec 2010 David Kelsey STFC/RAL david.kelsey AT stfc.ac.uk

Overview Security Policy work in EGI WLCG Security meeting at FNAL (8 Nov 2010) 8 Dec 20102Sec Policy - D Kelsey

EGI SPG Terms of Reference See... SPG Purpose and Responsibilities Develop and maintain Security Policy –For use by EGI and NGIs –Defines expected behaviour of NGIs, Sites, Users and others –To facilitate the operation of a secure and trustworthy DCI 8 Dec 20103Sec Policy - D Kelsey

Terms of Ref (2) Where possible SPG should prepare simple and general policies –Of use to other Grids and DCIs (global) –Adoption of common policies eases interoperability SPG does not formally approve policy –EGI.eu Executive Board –And management bodies of NGIs 8 Dec 20104Sec Policy - D Kelsey

Terms of Ref (3) SPG Membership Each NGI and EIRO member of EGI.eu is entitled to appoint one voting member In addition, SPG should aim to include expertise in its deliberations from other stakeholders –Site security officers, Site sys admins, operations experts, middleware experts, VRCs, other DCIs... –These are determined by Chair in consultation with EGI management 8 Dec 20105Sec Policy - D Kelsey

ToR (4) SPG Meetings As often as the work requires At least twice per year –Once during Technical Forum Face to face or phone/video –Face to face at least once per year To define future plans and discuss policy Editorial sub-groups created as required to work on policy documents –Leader of this to decide how this meets 8 Dec 20106Sec Policy - D Kelsey

SPG Procedures To produce a new/revised policy (EGI-InSPIRE MS209) Tasks: –Write internal draft (editorial team) –Discuss within SPG –Prepared updated external draft –Consult stakeholders –Prepare updated final call draft –SPG agrees version for approval –Policy approval 8 Dec 20107Sec Policy - D Kelsey

Consultation Important to consult widely and take all feedback into account SPG will distribute external draft for comment to: –SPG itself (members to distribute on) –EGI-CSIRT –VRC contacts –NGI contacts (NGI distributes to Sites) Or should we distibute to all Security Contacts –All EGI Boards 8 Dec 20108Sec Policy - D Kelsey

WLCG Security Meeting FNAL 8 Nov 2010 OSG and EGI Agenda –Update to Grid AUP –JSPG evolution in the post-EGEE era –New security policy framework - standards for collaborating Grids, e.g. OSG, TeraGrid and EGI –Security Incident Response standards in the new framework. 8 Dec 2010Sec Policy - D Kelsey9

More details Grid (User) AUP –New version EGEE/WLCG in April/May 2010 – –OSG will consider adopting this not just for WLCG users JSPG evolution –Presented the status and plans of EGI SPG 8 Dec 2010Sec Policy - D Kelsey10

Details (2) For global collaboration on security policies –Work towards a framework of standards JSPG used to be good location for this work –EGI SPG is more EGI-focussed Start with WLCG work on Incident Response Policy standards –Work will start early in 2011 More general collaboration via the Infrastructure Policy Group (meets at OGF meetings) s.ipg/wiki/HomePagehttp://forge.gridforum.org/sf/wiki/do/viewPage/project s.ipg/wiki/HomePage 8 Dec 2010Sec Policy - D Kelsey11