The OASIS Cross-Enterprise Security and Privacy Authorization (XSPA) Technical Committee has submitted two profiles for public review. The XSPA Profile of the Security Assertion Markup Language (SAML) for Healthcare 1.0 describes a framework in which SAML is encompassed by XSPA to satisfy requirements pertaining to information-centric security within the healthcare community. The XSPA Profile of the eXtensible Access Control Markup Language (XACML) supports cross-enterprise security and privacy authorization.
News
News lets the community share announcements, press releases, and recommended news articles relevant to IDTrust. (Educational materials that are not time-sensitive are listed at Articles and white papers.)
Public reviews begin for XSPA Profiles of SAML and XACML
WS-Federation 1.2 public review begins
Members of the OASIS Web Services Federation (WSFED) Technical Committee have released an approved draft of WS-Federation version 1.2 for public review. The specification defines mechanisms to allow different security realms to federate, such that authorized access to resources managed in one realm can be provided to security principals whose identities are managed in other realms.This includes mechanisms for brokering of identity, attribute, authentication and authorization assertions between realms, and privacy of federated claims. The public review ends 12 Feb 2009.
New Year’s Resolution: Let’s Talk More about SPML
Jackson Shaw and James McGovern have been blogging recently about one of my favorite topics: Service Provisioning Markup Language (SPML). I’d like to contribute to the discussion.
Blogger: Mark Diodati - Burton Group
Single Sign-On and Social Networks
authentication -- letting users sign on to the Internet once and securely
access network resources anywhere has been one of the industry's enduring
quests. While numerous standards efforts have steadily pursued this
capability, most have been back-end technologies of which users are
mostly unaware. Periodically, however, something brings these efforts
to the foreground. Recent developments surrounding the open source OpenID
SC World Congress: Commission on cybersecurity releases recommendations
Cybersecurity control should be taken away from the U.S. Department of Homeland Security placed under the White House's purview, a panel of government and industry leaders are urging President-elect Barack Obama.
The Commission on Cybersecurity for the 44th Presidency, which released its recommendations on Monday in a 63-page report, said an executive White House office should be charged with cybercrime coordination.