Welcome to IDtrust XML.org.

This is the official community gathering place and information resource for identity and trusted infrastructure standards. The site is hosted by the OASIS IDtrust Member Section, a group that encourages new participation from developers and users. This is an open, vendor-neutral community-driven site, and the public is encouraged to contribute content. See more about this site.

Oasis' open Enterprise Key Management Infrastructure initiative promises less-complex encryption. But will vendors get on board?

Information security pros do put stock in encryption--it was named the third-most-effective security practice in our most recent Strategic Security Survey, behind only firewalls and antivirus products. However, there have been obstacles along the path to ubiquitous encryption of data, including weak ciphers, deployment and integration issues, and, perhaps most notably, key management.

Public key infrastructure, or PKI, systems alone have simply failed to address the challenge of keeping encryption keys in order.

Read more

Uses of Social Security Numbers in the Private Sector: Why SSNs Are Not Appropriate for Authentication

The Privacy Rights Clearinghouse (PRC) is a nonprofit consumer advocacy organization, based in San Diego, California, and established in 1992. The PRC invites individuals’ questions and complaints via e-mail and telephone, and we operate much like a “Dear Abby” of privacy.

Read more

Information Card Foundation launched

A group including Equifax, Google, Microsoft, Novell, Oracle, and
PayPal, plus nine leaders in the technology community announced on
Monday the creation of the Information Card Foundation (ICF) with the
goal of increasing awareness of the use of electronic ID cards on the
Internet, and encouraging interoperability in business around new
standards.

Read more

2008 Data Breach Investigations Report

Four Years of Forensic Research. More than 500 Cases -- One Comprehensive Report

Read more

Preparation Key to Managing Data Breaches

Officials from financial institutions offer advice on preventing and managing intrusions.

BALTIMORE—In this era of Internet connectivity, businesses must prepare for what is becoming the almost-inevitable data breach, according to a pair of chief privacy officers for major financial institutions. By Darryl Taft - eWeek

Read more

XML.org Focus Areas: BPEL | DITA | ebXML | IDtrust | OpenDocument | SAML | UBL | UDDI
OASIS sites: OASIS | Cover Pages | XML.org | AMQP | CGM Open | eGov | Emergency | IDtrust | LegalXML | Open CSA | OSLC | WS-I