Cybersecurity/Network and Information security

Available (171)

Showing 133 - 144 per page



STIX(TM) Version 2.0

The OASIS Cyber Threat Intelligence (CTI) TC was chartered to define a set of information representations and protocols to address the need to model, analyze, and share cyber threat intelligence. In the initial phase of TC work, three specifications will be transitioned from the US Department of Homeland Security (DHS) for development and standardization under the OASIS open standards process: STIX (Structured Threat Information Expression), TAXII (Trusted Automated Exchange of Indicator Information), and CybOX (Cyber Observable Expression).

Authentication Step-Up Protocol and Metadata Version 1.0

The OASIS Trust Elevation TC works to define a set of standardized protocols that service providers may use to elevate the trust in an electronic identity credential presented to them for authentication. The Trust Elevation TC is intended to respond to suggestions from the public sector, including the U.S. National Strategy for Trusted Identities in Cyberspace (NSTIC). The Trust Elevation TC promotes interoperability among multiple identity providers--and among multiple identity federations and frameworks--by facilitating clear communication about common and comparable operations to present, evaluate and apply identity [data/assertions] to sets of declared authorization levels.

Electronic Identity Credential Trust Elevation Framework Version 1.0

The OASIS Trust Elevation TC works to define a set of standardized protocols that service providers may use to elevate the trust in an electronic identity credential presented to them for authentication. The Trust Elevation TC is intended to respond to suggestions from the public sector, including the U.S. National Strategy for Trusted Identities in Cyberspace (NSTIC). The Trust Elevation TC promotes interoperability among multiple identity providers--and among multiple identity federations and frameworks--by facilitating clear communication about common and comparable operations to present, evaluate and apply identity [data/assertions] to sets of declared authorization levels.

KMIP Opaque Managed Object Store Profile v1.0

The OASIS KMIP TC works to define a single, comprehensive protocol for communication between encryption systems and a broad range of new and legacy enterprise applications, including email, databases, and storage devices. By removing redundant, incompatible key management processes, KMIP will provide better data security while at the same time reducing expenditures on multiple products.

KMIP Suite B Profile v1.0

The OASIS KMIP TC works to define a single, comprehensive protocol for communication between encryption systems and a broad range of new and legacy enterprise applications, including email, databases, and storage devices. By removing redundant, incompatible key management processes, KMIP will provide better data security while at the same time reducing expenditures on multiple products.

KMIP Tape Library Profile v1.0

The OASIS KMIP TC works to define a single, comprehensive protocol for communication between encryption systems and a broad range of new and legacy enterprise applications, including email, databases, and storage devices. By removing redundant, incompatible key management processes, KMIP will provide better data security while at the same time reducing expenditures on multiple products.

KMIP Symmetric Key Foundry for FIPS 140-2 Profile v1.0

The OASIS KMIP TC works to define a single, comprehensive protocol for communication between encryption systems and a broad range of new and legacy enterprise applications, including email, databases, and storage devices. By removing redundant, incompatible key management processes, KMIP will provide better data security while at the same time reducing expenditures on multiple products.

KMIP Cryptographic Services Profile v1.0

The OASIS KMIP TC works to define a single, comprehensive protocol for communication between encryption systems and a broad range of new and legacy enterprise applications, including email, databases, and storage devices. By removing redundant, incompatible key management processes, KMIP will provide better data security while at the same time reducing expenditures on multiple products.

Security Assertion Markup Language (SAML) v2.0

The Security Assertion Markup Language (SAML), developed by the Security Services Technical Committee of OASIS, is an XML-based framework for communicating user authentication, entitlement, and attribute information. As its name suggests, SAML allows business entities to make assertions regarding the identity, attributes, and entitlements of a subject (an entity that is often a human user) to other entities, such as a partner company or another enterprise application.

Jean-Pierre Quémard

Description of Activities

In this fellowship the original objective is to start to prepare a NWI to address the age approriate topic and start the standard development. The aim is to improve the benefits and reduce the risks in the digital world for young users up to the age of 18. The solution is to adapt the content delivered by online products and services according to the age of users. Moreover, the process requires establishing the age/capacity of users, including age verification and age estimation. The CWA does NOT define age estimation and verification processes (Out of scope) but requires to select an appropriate age assurance tools/approach in conformity with established standards and official guidance.

Fellow's country
Impact on society (7th Open Call)
Need for an EN: Many organizations engage with children intentionally; others engage with children in the course of their general activities. In each case the organization has a responsibility to that child to provide an age-appropriate service. This is not a marginal market, as one in three users is under 18.
The target stakeholders of this standard are society-wide: governments and policymakers; international institutions and civil society organizations; business and tech sector especially digital service providers; parents, teachers, and children.
The protection of children in the ICT world is a key issue and three domains are to develop complementary; including, age appropriate this work item, Age Assurance and Age verification. The two last topics are managed at ISO/IEC/JTC1/SC27/WG5 level the delineation between the three topics is important
Open Call
Organisation type
Organization
Kuzul An Traezehnn
Portrait Picture
Jean-Pierre Quémard
Proposal Title (7th Open Call)
Age appropriate standardisation
Role in SDO
Standards Development Organisation
StandICT.eu Year
2026
Year

Gill Whitney

Description of Activities

 

The standards being developed should cover the requirements of the full range of stakeholders (including users, affected bystanders and manufacturers etc) over the complete lifetime of the product.

 

Fellow's country
Impact on SMEs (9th Open Call)
My contribution impacts in SMEs in a small but important way. The requirements of consumers with respect to how security information (such as updates or warnings) needs to be presented to end users in a clear, easy to understand and timely manner, without the use of unnecessary, unfamiliar terminology. Many SMEs will have access to or employ Cyber Security experts. They will therefore have similar requirements for information to be presented in a clear, useable, timely and concise way. I have referred to the issue of information to be presented in a useable way in a number of meetings. This is particularly relevant with respect to information impacting purchasing decisions or with reference to security updates.
Impact on society (6th Open Call)
Cybersecurity standards have traditionally focused on the operation of the hardware, software and firmware of the systems. The needs of the human elements have often not been fully considered and negative viewpoints are sometimes heard in cybersecurity standards meeting with respect to untrained and/or vulnerable consumers/end users. By considering and supporting the `human element’ in products with digital elements (an essential element), it is hoped to reduce the potential for harm to the system and also to reduce the harm to the end user. In particular improved communication should reduce the physiological harm caused to the end user when something goes wrong and they think it is their fault. Cybersecurity standards for digital systems can thus be seen to support vulnerable users and to acknowledge that all end users can be vulnerable in specific circumstances
Impact on society (9th Open Call)
My work supports ICT accessibility and digital skills. It did this by promoting the requirements of end users when these people were acting as part of a system involving the use of products with digital elements. These end users will include vulnerable end users. In these systems the end users will be involved in a range of set up and management activities with respect to the digital elements including choosing the products and their application, selecting and maintaining levels of Cybersecurity and making decisions on when the product has reached its end of life.
Products with digital elements include health monitoring and quality of life products which can improve the life and health of the end user, if they fail or become unsafe, they may impact the physical, sensory or cognitive health of the end user. If their operation becomes uncertain, they may cause stress, which impacts the cognitive health of the end user.
By supporting the end users to make sensible decisions when selecting or maintaining a product with digital elements, the followers of the relevant CRA standard will increase the digital skills of the end users. This can be achieved by enabling standards writers to create standards which consider the needs of all end users. The aim of this project was to assist the standard writers to do this.
Open Call
Organisation type
Organization
Independent Expert
Portrait Picture
Gill Whitney
Proposal Title (6th Open Call)
Contribution to the modification of standards to facilitate their use by manufacturers and writers of associated vertical standards
Proposal Title (9th Open Call)
Using accessibility standards to increase the cybersecurity of the full range of consumers
Standards Development Organisation
StandICT.eu Year
2026
Year