Your Voice in Trust and Assurance
The Community Trust and Assurance Board (CTAB) serves as the steward of InCommon’s trust and assurance programs. Originally established as the Assurance Advisory Committee (AAC) and renamed in 2018, CTAB represents your interests in developing and maintaining the standards that keep our federation secure and trustworthy.
CTAB is advisory to the InCommon Steering Committee and plays a critical role in facilitating community consensus on trust frameworks, leading dispute resolution processes, and ensuring that baseline expectations evolve to meet emerging security challenges.
What CTAB Does for the Community
CTAB’s work directly impacts every participant in the InCommon Federation, establishing the foundation of trust that enables seamless collaboration.
Core Responsibilities:
1. Baseline Expectations Stewardship
Leading the development, implementation, and evolution of Baseline Expectations for Trust in Federation—the common practices that all participants must meet
2. Community Consensus Facilitation
Guiding open discussions to reach agreement on trust frameworks, security practices, and operational standards
Dispute Resolution Leadership
Managing the community dispute resolution process when questions arise about compliance or interpretation of standards
Trust Framework Development
Creating and maintaining cross-institutional trust frameworks that enable secure academic collaboration
Baseline Expectations for Trust in Federation
Baseline Expectations are the cornerstone of trust in InCommon. These community-developed standards ensure that all federation participants meet fundamental requirements for security, interoperability, and operational excellence.
Current Requirements (BE2):
- Secure Endpoints: All service endpoints must use current, trusted TLS encryption
- SIRTFI Compliance: Participants must comply with the Security Incident Response Trust Framework
- Error URL Inclusion: Identity providers must include error URLs in metadata for troubleshooting
- Accurate Metadata: All participants must maintain complete and accurate federation metadata
View Full Baseline Expectations
Measurable Trust Improvements
CTAB’s leadership in establishing and implementing Baseline Expectations has delivered tangible security improvements across the federation.
Key Achievements:
- 100% Compliance: All InCommon participants met original Baseline Expectations by 2019
- Enhanced Security: Over 80% of services now score “A” or better in TLS encryption tests (up from 58% in 2021)
- Growing Federation: Successfully scaled trust frameworks from 4,910 to over 6,200 registered entities
- Rapid Adoption: 80% of organizations met BE2 requirements within first implementation year
Forward Progress: CTAB continues to work with the community to identify emerging trust challenges and develop appropriate responses that balance security with operational flexibility.
CTAB Process
Collaborative Governance in Action
CTAB operates through transparent, community-driven processes that ensure all voices are heard and considered.
Operating Structure:
- Regular Meetings: Bi-weekly meetings open to community observers
- Public Minutes: All meeting minutes and decisions publicly documented
- Community Input: Regular consultations and feedback periods
- Advisory Role: Reports to InCommon Steering Committee
Meeting Schedule: Every other Tuesday, 1-2 PM ET
Charter: The official CTAB charter defines our scope, responsibilities, and operating procedures.
Building Agreement Together
CTAB facilitates structured community discussions to reach consensus on trust and assurance matters affecting the federation.
The Consensus Process:
- Topic Initiation: CTAB identifies issues requiring community input
- Position Statement: Clear problem statement published for discussion
- Open Discussion: Community members contribute via moderated forums
- Synthesis: CTAB synthesizes input and proposes solutions
- Final Position: Consensus position documented and implemented
Recent Consensus Topics:
- Multi-factor authentication requirements
- Cloud service provider integration standards
- Privacy-preserving attribute release policies
Fair and Transparent Resolution
When questions arise about baseline expectations compliance or interpretation, CTAB leads a structured dispute resolution process that seeks collaborative solutions.
Resolution Process:
- Initial Review: CTAB evaluates concerns raised by community members
- Collaborative Resolution: Work directly with participants to address issues
- Remediation Support: Provide guidance and resources for compliance
- Final Determination: If needed, make recommendations to Steering Committee
Guiding Principles:
- Transparency in all proceedings
- Fair representation of all parties
- Focus on education and improvement
- Escalation only when necessary
Join CTAB’s Mission
CTAB welcomes community participation in our trust and assurance initiatives. There are multiple ways to contribute to this important work.
Participation Options:
- Attend Open Meetings: Join bi-weekly calls as an observer
- Office Hours: Participate in regular office hours for Q&A
- Provide Feedback: Comment during consultation periods
- Join CTAB: Nominations open annually for board positions
Current Members: [Link to member list on InCommon website]
Contact CTAB: For questions or to get involved, contact us through the InCommon community liaison.
CTAB Resources & Documentation
Access the tools and information you need to understand and meet baseline expectations.
Key Resources:
- Baseline Expectations Documentation – Official requirements and implementation guides
- Meeting Minutes Archive – Historical CTAB decisions and discussions
- Implementation Tools – Self-assessment checklists and compliance guides
- SIRTFI Framework – Security incident response requirements
- TLS Testing Tools – Resources for endpoint security validation
- Error URL Guidelines – Best practices for metadata configuration
Looking Ahead: Future Trust Initiatives
CTAB continuously evaluates emerging trust and security challenges to keep the InCommon Federation at the forefront of secure collaboration.
On the Horizon:
- Multi-Factor Authentication Standards – Systematic signaling and use of MFA across the federation
- Zero Trust Architecture – Adapting baseline expectations for zero trust models
- Cloud Integration Security – Trust frameworks for cloud service providers
- Privacy Enhancement – Strengthening privacy-preserving practices
- International Alignment – Harmonizing with global trust frameworks
Join the Discussion: Help shape these future initiatives by participating in CTAB consultations and working groups.