-
Notifications
You must be signed in to change notification settings - Fork 697
[Initiative]: Identity and Access Management #1617
Copy link
Copy link
Open
Labels
kind/docsDocs related changes or updatesDocs related changes or updateskind/initiativeAn initiative or an item related to imitative processesAn initiative or an item related to imitative processestag/security-and-complianceTAG Security and ComplianceTAG Security and Compliancetoctoc specific issuetoc specific issuetriage/validIssue or PR is valid with enough information to be actionableIssue or PR is valid with enough information to be actionable
Metadata
Metadata
Labels
kind/docsDocs related changes or updatesDocs related changes or updateskind/initiativeAn initiative or an item related to imitative processesAn initiative or an item related to imitative processestag/security-and-complianceTAG Security and ComplianceTAG Security and Compliancetoctoc specific issuetoc specific issuetriage/validIssue or PR is valid with enough information to be actionableIssue or PR is valid with enough information to be actionable
Type
Projects
Status
New
Status
status/in-progress
Status
In Progress
Name
Identity and Access Management
Short description
Writing Identity and Access Management Whitepaper.
Responsible group
TAG Security and Compliance
Does the initiative belong to a subproject?
No
Subproject name
Identity and Access Management
Primary contact
@y-tabata
Additional contacts
@eddie-knight
Initiative description
This is an initiative to write the Identity and Access Management Whitepaper, which we have been carrying out at TAG Security since last year.
cncf/tag-security#1332
Description:
Authentication and authorization are the most important security considerations in the cloud-native ecosystem, as evidenced by their high ranking in the OWASP Top 10 and OWASP Top 10 API Security Risks.
On the other hand, authentication and authorization frameworks have a wide range of related specifications, including OAuth and OpenID Connect, and it can be difficult for implementers to implement the frameworks, so it would be beneficial to publish best practices for identity and access management.
Deliverable(s) or exit criteria
The deliverable is the Identity and Access Management whitepaper.