[NCSG-PC] [NCSG EPDP] draft comments on the EPDP final report
Stephanie E Perrin
stephanie at digitaldiscretion.ca
Tue Mar 30 02:45:57 EEST 2021
Ok I have added bits as requested....I did not accept your rejection of
the premise that the accreditation body cost estimate may be low. This
is not based on my opinions alone, it is is based on all the work done
in private by the EWG....we looked at the possible options for
accreditation of entities, and it was considered by all to be a
nightmare and potentially expensive. I also worked on this, including
with respect to cross border data sharing in my capacity of DG Risk
Management when I was at Service Canada....managing credentials for
users of a global system is extremely expensive. I used the term "may"
so we are not making a fact assertion, but I will be stunned if they can
do this for that kind of budget. Remember that permitting the wrong
users eg criminals into the system would be the cause of a major data
breach, which comes with big $$$ penalties. If there are no further
comments I will go in , accept your additions, and turn it over to
Tomslin to submit. (what day is it for you Tomslin? ) we have approx
24 hours to the deadline.
cheers and thanks for the comments Milton! I don't necessarily agree
with totally downpedalling the cost issues but am willing to compromise
on it, we have signalled strongly that this is a new payer and you left
that in.
Steph
On 2021-03-29 2:25 p.m., Mueller, Milton L wrote:
> Stephanie:
> Really appreciate the work involved in the first draft.
> I am commenting on the doc and I want to alert everyone in NCSG that I think it is a major strategic error for our comments to reinforce the IPC/BC's attacks on the financial viability of the SSAD. The SSAD is viable if the users (e.g., Facebook, Markmonitor, etc) pay for it. When the surveillance caucus says it is too costly they are just angling for free access and our having registrars and registrants pay for it. When you reinforce the false argument that this will be too expensive, you are advancing their agenda. Not deliberately, of course, but you seem to be unaware of how your argument shoots us in the foot.
>
> During the negotiations over the SSAD, NCSG's position was that users pay for their own accreditation costs, and that usage of the system should be tiered to differentiate between light and heavy users. Also, the existence of an SSAD helps us argue for keeping the private data redacted.
>
> So I have suggested various changes and deletions in the comments to reflect this perspective.
>
> --MM
>
>
> -----Original Message-----
> From: EPDP <epdp-bounces at lists.ncsg.is> On Behalf Of Stephanie E Perrin
> Sent: Thursday, March 25, 2021 4:20 PM
> To: NCSG PC <ncsg-pc at lists.ncsg.is>; 'epdp (epdp at lists.ncsg.is)' <epdp at lists.ncsg.is>; kathy at dnrc.tech
> Subject: [NCSG EPDP] draft comments on the EPDP final report
>
> Here is the link to the draft comment
> https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.google.com%2Fdocument%2Fd%2F1AEQv0knS3fI_AaCNWAr3Y4H1sf1BlUgani4dqcBQZ48%2Fedit%3Fusp%3Dsharing&data=04%7C01%7Cmilton%40gatech.edu%7Ca6ce1b2a2bbf4f35e41f08d8efcb5633%7C482198bbae7b4b258b7a6d7f32faa083%7C0%7C0%7C637523004364133736%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=a4Ynu4ypaEqf%2BlpL6BQykzPkInixeCFof%2BKQVapNces%3D&reserved=0
>
> Please let me know if you have trouble editing
>
> cheers Stephanie Perrin
>
> _______________________________________________
> EPDP mailing list
> EPDP at lists.ncsg.is
> https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.ncsg.is%2Fmailman%2Flistinfo%2Fepdp&data=04%7C01%7Cmilton%40gatech.edu%7Ca6ce1b2a2bbf4f35e41f08d8efcb5633%7C482198bbae7b4b258b7a6d7f32faa083%7C0%7C0%7C637523004364133736%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&sdata=CqqohHcA2A1lEe5KhmARjJz8ufSLhSQvjqhWrjjmNiA%3D&reserved=0
> _______________________________________________
> NCSG-PC mailing list
> NCSG-PC at lists.ncsg.is
> https://lists.ncsg.is/mailman/listinfo/ncsg-pc
More information about the NCSG-PC
mailing list