Security SIG Meeting - October 8th, 2021
kinlane opened this issue · 1 comments
kinlane commented
Here are my notes from today's security SIG, providing some overview of what occurred during the recurring discussion:
- Jeremy's Proposal - Everyone should review. Phillippe did.
- Who are the targets of changes?
- Producer?
- Consumer?
- Security?
- Auditor? Compliance? Regulatory?
- Why are we doing this?
- What is require?
- Where it goes?
- What are we focusing on?
- FAPI
- OAuth
- JWT
- SAML
- Industries
- Banking - Make this work.
- Healthcare - SmartOn FHIR - HumanAPI - Heart
Extensibility - Review SAML for their extensibility approach
We seem to come out of it with a focus on taking Jeremy's spec and applying to FAPI to think through all of this end to end.
kinlane commented
I have republished Jeremy's original proposal within the security SIG, and copied the conversation thread from here over to an issue. We are going to work on the proposal over there in the security SIG repo, and when ready republish here as a formal proposal.