Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SP 800 63-3 Comment 5 #1

Open
TLSrUS opened this issue Mar 30, 2017 · 0 comments
Open

SP 800 63-3 Comment 5 #1

TLSrUS opened this issue Mar 30, 2017 · 0 comments

Comments

@TLSrUS
Copy link
Owner

TLSrUS commented Mar 30, 2017

Org
USAF AFLCMC/HNCEI

Section
2.2

Comment
These guidelines do not address cloud with respect to possible considerations for authenticating to cloud services from outside or from within cloud boundaries.

Rationale
Such guidance is needed as assets increasingly are moving to cloud hosted environments. Current cloud security guidance is notably missing when it comes to authentication to numerous cloud services where multiple identities are involved.

Suggested Change
Incorporate language that addresses Cloud Computing Reference Architecture (ISO/IEC 17788 and 17789) terms and concepts such as cloud service customer, partner, and provider, and how authentication will take place as a security service supporting these roles.

Resolution
Modify

Explanation
With IAL, AAL, FAL, does a cloud computing environment matter? Is there anything in cloud computing ref arch that can't be traced to existing document? How would we map NIST 800-63-3 terminology to cloud computing use cases? Is this obvious? Would we need to? Nate will look into it.

@TLSrUS TLSrUS changed the title SP 800 63-3x comments from DoD SP 800 63-3 Comment 5 Mar 30, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant