As the very first move forward with security arrangement we need to establish proper communication channels with the eduGAIN participants. As agreed by the eduGAIN SC, we will require that Federations provide their security contacts and make them available for security matters in eduGAIN. We'll continue further with policies and procedures, however in this phase we only aim at very light and flexible arrangement to prove the essential security baseline. We have re-used SIRFTI requirements as much as possible.
The security contact shall respect the following base requirements:
Respond to requests for assistance with a security incident from the eduGAIN CSIRT or other eduGAIN Participants in a timely manner. The recommended response time is half business day.
Respect the Traffic Light Protocol [TLP] information disclosure policy and use it during incident response communications (ref. https://www.first.org/tlp).
TODO: add how to update the information (solicited and unsolicited).
[eduGAIN-CSIRT] https://edugain.org/edugain-security/
[eduGAIN-SIRH] https://wiki.refeds.org/download/attachments/44958353/eduGAIN%20Security%20Incident%20Response%20Handbook%20v1.0.pdf