• About
  • Terminology
  • Links

Securing the Realm

~ UK Government Cyber Security

Securing the Realm

Tag Archives: GPG

Identity Assurance: Enabling Trusted Transactions

14 Monday May 2012

Posted by Andy in Information Assurance

≈ Leave a Comment

Tags

GPG, GPG43, GPG44, GPG45, ID assurance

The Cabinet Office have released a new set of Good Practice Guides (GPG’s) on enabling trusted transactions via ID assurance.

Being able to prove your identity online easily, quickly and safely is recognised as a key enabler of internet use by the government, its agencies and its citizens. Providers of public services such as national and local governments, major internet companies, online retailers, banks and others are having to address business issues such as identity fraud (and the financial implications) and the administrative burden around username/password fallibility and related issues around proof of identity.

The Identity Assurance Programme is a core element of the ‘digital by default’ policy pursued by the Government Digital Service within the Cabinet Office. The Programme is facilitating the development of identity assurance schemes in the UK, by which citizens, business and devices will be able to assert identity safely and securely online in order to better access and transact with public services.

One widely accepted solution to providing identity online is the development of ‘identity assurance’ using a federated trust ‘framework’, or trust ‘ecosystem’. Basically, this requires an industry-agreed set of protocols, standards and certification under which organisations can collaborate to allow citizens to use assets they own to validate and verify their identity to ‘relying parties’.

Our preferred solution suggests the use of ‘hubs’ (technical intersections) which allow identities to be authenticated by contracted private sector organisations without an individual’s data being centrally stored or privacy being breached by unnecessary data and details of the user being openly ‘shared’ with either transacting party.

For full article and links to the GPG’s click here

GPG Listing

01 Saturday Oct 2011

Posted by Andy in Information Assurance

≈ Leave a Comment

Tags

GPG

The following is a list of the GPG’s available (or superseded).

  • No. 1   – Superseded with parts of IS4 *
  • No. 2   – Superseded with parts of IS4 *
  • No. 3   – Securing Bulk Data Transfers *
  • No. 4   – Remote Access to PROTECT Data *
  • No. 5   – Securing Data At Rest On Laptops *
  • No. 6   – Off-shoring: Managing the Security Risks
  • No. 7   – Protection from Malicious Code
  • No. 8   – Protecting External Connections to the Internet
  • No. 9   – Taking Account of the Aggregation of Information
  • No. 10 – Remote Working * 
  • No. 11 – KVM Switches
  • No. 12 – Use of Virtualisation for Data Separation: Managing the Security Risks
  • No. 13 – Protective Monitoring for HMG ICT Systems
  • No. 14 – UK Requirements for TEMPEST Countermeasures *
  • No. 15 – Auditing Compliance with HMG IAS No. 6
  • No. 16 – Taking Cryptographic Items overseas *
  • No. 17 – Client System Security
  • No. 18 – Forensic Readiness
  • No. 19 – Managing Accreditation – Governance, Structure & Culture
  • No. 20 – ICT Service Management – Security Considerations
  • No. 21 – Video Conferencing
  • No. 23 – Assessing the Threat of Technical Attack Against ICT Systems
  • No. 24 – Security Incident Management
  • No. 27 – Online Social Networking
  • No. 28 – Improving Information Assurance at the Enterprise Level
  • No. 29 – ICT Security Aspects of Collaborative Working
  • No. 35 – Protecting an Internal ICT Network

* denotes controlled material.

♣ Facebook

♣ Categories

  • ComSec
  • Education & Certification
  • Information Assurance
  • ISO27K ISMS
  • Papers & Presentations
  • PSN, GCN & G-Cloud
  • Standards & Policy
  • University

♣ Twitter

  • Maybe 'The Art of Deception' - another @kevinmitnick book.. again, in audio book :) - anyone read/listened to this book? what do you think? 1 day ago
  • Finished listening to the Ghost in the Wires by @kevinmitnick - great book, loved it so much now what am I going to listen to? #needanewbook 1 day ago
  • Government reveals PSN framework suppliers - information-age.com/channels/comms… #PSN 3 days ago
  • Great video explaining the Public Services Network (PSN) from @Level3 - level3.com/en/resource-li… 5 days ago
Follow @SecureTheRealm

♣

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 69 other followers

Popular Topics

#AccreditCamp Accreditation CCP CESG CIRT CLAS CloudStore comsec Crypto CSIRT Cyber Security Event G-Cloud G-Hosting Government Body Government Security GPG GPG43 GPG44 GPG45 HIPS HMG certification HMG IA HMG IA Course HMG IA Training ID assurance Incident Response Information Security Governance ISG ISO27001 ISO27002 Malware Password PSN training UK Cyber Security Strategy

Blog at WordPress.com. Theme: Chateau by Ignacio Ricci.