Scope and Field of Application
|
The purpose of this Work Item is to provide a state of the art assessment of security and privacy issues associated with ISG CIM specifications, in particular related to the API, Data Publishing Platforms and Data Model Work Items. Recommendations shall be accompanied by pro/con information with the intent to reference as much as possible existing widely supported concepts. There are several issues that need to be addressed, including but not limited to provenance of data, assuring privacy and security between stakeholders, assuring trust, understanding how to ensure the aggregation of data does not increase the attack space or compromise privacy. The work item will investigate items such as but not limited to; what should be connected via the information model and are there any particular lifecycle constraints that may be placed on data? The scope of this work is strictly limited to the CIM scope of work, e.g. device security is excluded. Where appropriate, it references existing work, specifications and standards. Safety and reliability issues for systems relying on CIM-based APIs and architectures are out of scope but may be addressed at a later date.
|