Token Trust & Traceability WG
Fortnightly for the risk assessment season.
Warning: room 513/R-068 has NOT been booked for this occurrence!
https://codimd.web.cern.ch/BhP_ao9iScqXEtusew0u7Q?view
# TTT 24/2/26
Attending: Matt, Maarten, Linda, DaveK, Donald, Mischa, DaveD
Apologies: Luna
## Actions, Last meeting
Last time we reviewed all of Luna's revisions and approved of the results. Saw a need to revisit all the numbers one last time.
## Risk Assessment v0.9
the <2 in TR 11 needs to go. Should be the next goal.
Maarten notes that when we go through the whole thing again in the act of writing up, so probably don't need one more go. This could reveal any "indefencible" results.
Starting assessment of TR-11 from scratch
Some discussion of likelhoods, not identical to TR10 (but some parity).
Discussion of mitigations
Lots of descrepency in impact.
Discussion of who the audience is for the risk assessment.
ML - Considering the Worst case, so no conflict with TR10 being VO centric, TR11 being site-centric
Should explicitly point this out in the document.
Definitely a risk to include in the spotlight.
Power users are a problem!
## Next Steps
Start copying into the word document now. ML, MD and Luna will work on it.
Will want fleshing out of points, and Executive summary + table.
## Thoughts for inputs "beyond" the risk assessment?
Recent developments involving cilogon/amazon certs and arc CEs
For next time.
## Next meeting
Do we want to maintain the fortnightly cadance? If so suggest the 10th and the 24th of March, 15.00 CET (with the 24th being the usual monthly meeting date)
OTF on the 24th, so could move to the 31st.
Definitely pencil one in for the 10th.