Improving a Trustworthy Data Repository with ISO 16363

Similar documents
Conducting a Self-Assessment of a Long-Term Archive for Interdisciplinary Scientific Data as a Trustworthy Digital Repository

Trust and Certification: the case for Trustworthy Digital Repositories. RDA Europe webinar, 14 February 2017 Ingrid Dillo, DANS, The Netherlands

Trusted Digital Repositories. A systems approach to determining trustworthiness using DRAMBORA

DEVELOPING, ENABLING, AND SUPPORTING DATA AND REPOSITORY CERTIFICATION

University of British Columbia Library. Persistent Digital Collections Implementation Plan. Final project report Summary version

Certification Efforts at Nestor Working Group and cooperation with Certification Efforts at RLG/OCLC to become an international ISO standard

Certification. F. Genova (thanks to I. Dillo and Hervé L Hours)

GEOSS Data Management Principles: Importance and Implementation

Agenda. Bibliography

Audit & Certification: an auditors perspective. Barbara Sierman, KB National Library of the Netherlands Royal Irish Academy, Dublin 4 june 2013

International Audit and Certification of Digital Repositories

European digital repository certification: the way forward

From production to preservation to access to use: OAIS, TDR, and the FDLP OAIS TRAC / TDR

OAIS: What is it and Where is it Going?

DCH-RP Trust-Building Report

Sustainable Governance for Long-Term Stewardship of Earth Science Data

31 March 2012 Literature Review #4 Jewel H. Ward

DSA WDS Partnership Working Group Catalogue of Common Requirements

The Research Data Alliance (RDA): building global data connections CC BY-SA 4.0

Digital Preservation Standards Using ISO for assessment

Applying Archival Science to Digital Curation: Advocacy for the Archivist s Role in Implementing and Managing Trusted Digital Repositories

The OAIS Reference Model: current implementations

An overview of the OAIS and Representation Information

MAPPING STANDARDS! FOR RICHER ASSESSMENTS. Bertram Lyons AVPreserve Digital Preservation 2014 Washington, DC

Large Scale Repository Auditing to ISO José Carvalho

Science Europe Consultation on Research Data Management

Summary of Contents LIST OF FIGURES LIST OF TABLES

Indiana University Research Technology and the Research Data Alliance

ebooks Preservation at Scholars Portal Kate Davis & Grant Hurley Scholars Portal, Ontario Council of University Libraries

DSA WDS Partnership Working Group Catalogue of Common Requirements

Ensuring Proper Storage for Earth Science Data: The USGS Process to Certify Trusted Digital Repositories

Certification as a means of providing trust: the European framework. Ingrid Dillo Data Archiving and Networked Services

Academic Program Review at Illinois State University PROGRAM REVIEW OVERVIEW

Document Title Ingest Guide for University Electronic Records

Establishing Trust in Data Curation: OAIS and TRAC applied to a Data Staging Repository (DataStaR)

Core Trustworthy Data Repositories Extended Guidance. Core Trustworthy Data Repositories Requirements for Extended Guidance

University of Maryland Libraries: Digital Preservation Policy

<goals> 10/15/11% From production to preservation to access to use: OAIS, TDR, and the FDLP

MetaArchive Cooperative TRAC Audit Checklist

Information and documentation Records management. Part 1: Concepts and principles AS ISO :2017 ISO :2016

Growing Variety and Volume of Remote Sensing and In Situ Data

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

RADAR Project. Data Archival and Publication as a Service. Matthias Razum FIZ Karlsruhe RESEARCH DATA REPOSITORIUM. Zurich, December 15, 2014

Guide to the implementation and auditing of ISMS controls based on ISO/IEC 27001

UNT Libraries TRAC Audit Checklist

CoSA & Preservica Practical Digital Preservation 2015/16. Achieving ISO Standards for your Digital Archive October 27, :00-15:00 EDT

COSO Enterprise Risk Management

Transferring vital e-records to a trusted digital repository in Catalan public universities (the iarxiu platform)

Long-term digital preservation of UNSWorks

ISO/IEC/ IEEE Systems and software engineering Content of life-cycle information items (documentation)

Report on compliance validation

Selecting an Electronic Records Repository Platform

The International Journal of Digital Curation Issue 1, Volume

Systems and software engineering Requirements for managers of information for users of systems, software, and services

Building an Assurance Foundation for 21 st Century Information Systems and Networks

An Audit Checklist for the Certification of Trusted Digital Repositories DRAFT FOR PUBLIC COMMENT

The Data Management Plan: Putting policy into practice Suzanne Clarke Director, Information Resources

Assessing the FAIRness of Datasets in Trustworthy Digital Repositories: a 5 star scale

Data Curation Handbook Steps

This document is a preview generated by EVS

WEB ACCESSIBILITY. I. Policy Section Information Technology. Policy Subsection Web Accessibility Policy.

An introduction to Repository Assessement and DRAMBORA

AS/NZS ISO 13008:2014

ISO Self-Assessment at the British Library. Caylin Smith Repository

IASM Support for FISMA

Preservation of digital IG at the ICGC. Dolors Barrot, J. Luis Colomer, Anna Lleopart, Carme Montaner, Maria Pla

Preserving the H-Net Academic Electronic Mail Lists

ISO/IEC/ IEEE INTERNATIONAL STANDARD

Standards Designation and Organization Manual

KENYA SCHOOL OF GOVERNMENT EMPLOYMENT OPORTUNITY (EXTERNAL ADVERTISEMENT)

NSF Data Management Plan Template Duke University Libraries Data and GIS Services

Meredith Lichtenstein Cone, MPH Manager, Surveillance and Informatics Program May 8, 2018

Tools for Reusing Earth Science Software

Technology Competence Initiative

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Code of practice for information security management

U.S. Japan Internet Economy Industry Forum Joint Statement October 2013 Keidanren The American Chamber of Commerce in Japan

Information technology Security techniques Application security. Part 5: Protocols and application security controls data structure

Resolution adopted by the General Assembly. [on the report of the Second Committee (A/56/561/Add.2)]

Information Security Management System (ISMS) ISO/IEC 27001:2013

Research Data Edinburgh: MANTRA & Edinburgh DataShare. Stuart Macdonald EDINA & Data Library University of Edinburgh

ISO/IEC/ IEEE INTERNATIONAL STANDARD

FISMAand the Risk Management Framework

DataFlow and VIDaaS Workshop

DirectTrust Governmental Trust Anchor Bundle Standard Operating Procedure

Making Sense of Data: What You Need to know about Persistent Identifiers, Best Practices, and Funder Requirements

Security Management Models And Practices Feb 5, 2008

A Model for Managing Digital Pictures of the National Archives of Iran Based on the Open Archival Information System Reference Model

This document is a preview generated by EVS

DIGITAL ARCHIVES & PRESERVATION SYSTEMS

e-infrastructures and Data Management

Trusted Digital Archives

ISEB Practitioner Certificate in IT Service Management: Specialising in Release and Control

ISO/IEC Software Engineering Lifecycle profiles for Very Small Entities (VSEs) Part 2-1: Framework and taxonomy

DRI: Preservation Planning Case Study Getting Started in Digital Preservation Digital Preservation Coalition November 2013 Dublin, Ireland

ISO9001:2015 LEAD IMPLEMENTER & LEAD AUDITOR

Session Two: OAIS Model & Digital Curation Lifecycle Model

Guidelines for Depositors

Digital Preservation with Special Reference to the Open Archival Information System (OAIS) Reference Model: An Overview

Position Description IT Auditor

Measuring the effectiveness of your ISMS implementations based on ISO/IEC 27001

Transcription:

Improving a Trustworthy Data Repository with ISO 16363 Robert R. Downs 1 1 rdowns@ciesin.columbia.edu NASA Socioeconomic Data and Applications Center (SEDAC) Center for International Earth Science Information Network (CIESIN) The Earth Institute, Columbia University Research Data Alliance (RDA) 10 th Plenary Session: IG RDA/WDS Certification of Digital Repositories Thursday, 21 September 2017; 9:00 a.m. - 10:30 a.m. Copyright 2017. The Trustees of Columbia University in the City of New York.

ISO 16363 ISO 16363:2012 Space Data and Information Transfer Systems Audit and Certification of Trustworthy Digital Repositories Published by the International Organization for Standardization (ISO) Developed by the Consultative Committee for Space Data Systems as CCSDS 652.0-M-1 Under review by the CCSDS Data Archive Interoperability (DAI) WG Being reviewed in conjunction with review of the Open Archival Information System (OAIS) Reference Model (ISO 14721:2012) Proposed revisions will be reviewed simultaneously by CCSDS and ISO Freely available from ccsds.org: https://public.ccsds.org/pubs/652x0m1.pdf 2

Impetus of ISO 16363 Need for criteria to assess OAIS compliance OAIS is a reference model and does not address implementation issues Many repositories self-reported as OAIS compliant without evidence OAIS Reference Model published as ISO 14721:2003 & ISO 14721:2012 Need for an international standard for digital repositories Digital resources, including research data, recognized as being at risk Various digital repositories established with limited guidance Guidance needed for [depositors, staff, funders] to select a digital repository 3

ISO 16363 Development Initiated in 2007 within CCSDS Repository Audit and Certification (RAC) Working Group Reference documents: Open Archival Information System (OAIS) Reference Model (ISO 14721:2003) Trustworthy Repositories Audit & Certification: Criteria and Checklist (TRAC) Catalogue of Criteria for Trusted Digital Repositories (Nestor Working Group) Digital Repository Audit Method Based on Risk Assessment (DRAMBORA) OECD Guidelines for the Security of Information Systems and Networks Reviews CCSDS and ISO communities comments received and revisions applied Test Audits Conducted at 6 repositories (3 in Europe, 3 in US) ISO 16363:2012 Published 4

Organization of ISO 16363 Organizational Infrastructure Governance and Organizational Viability Organizational Structure and Staffing Procedural Accountability and Preservation Policy Framework Financial Sustainability Contracts, Licenses, and Liabilities Digital Object Management Ingest: Acquisition of Content Ingest: Creation of the AIP Preservation Planning AIP Preservation Information Management Access Management Infrastructure and Security Risk Management Technical Infrastructure Risk Management Security Risk Management Based on: Consultative Committee for Space Data Systems (2011) Audit and Certification of Trustworthy Digital Repositories: Recommended Practice. Magenta Book, Issue 1. Available: http://public.ccsds.org/publications/archive/652x0m1.pdf 5

Adoption and Use of ISO 16363:2012 Endorsement by the Society of American Archivists Council August 6, 2012 Used for self-assessments and preparation Data centers, institutional repositories, government agencies Used by professional development services Training courses, workshops, presentations, consulting, and guidance Audience: data creators, curators, repository managers, funders, consultants Used for Audits by PTAB Conducted test audits of 6 repositories using draft ISO 16363 (2011) Accredited for ISO 16363:2012 audit and certification (2017) Offers training, conducts audits, reviews applications, and answers inquiries 6

SEDAC Assessment: Path to WDS Certification ICSU World Data System Regular Member Application 2014-2015 NASA ESDIS Data Archive Risk Analysis 2011-2012 ISO 16363 (draft) External Test Audit by PTAB (2011) ISO 16363 (draft) Self-Assessment (2010-2011) Trusted Repository Audit Checklist (TRAC) Self-Assessment (2008-2009) NASA Security Audits (regular and continuing) Derived from: Downs, Chen, and de Sherbinin. 2017. https://doi.org/10.6084/m9.figshare.5258041.v1 7

Selected Improvements at SEDAC based on ISO 16363, WDS Certification, and other Resources Dissemination Information Packages derived from Archival Information Packages Improvement of data review process and procedures Assignment of DOIs for disseminated data products and documentation Conducting tests for data transfer Standardization of rights declaration statements Portfolio approach to sustainability CC By license applied to data sets developed internally Data Documentation Template Open Data Policy 8

SEDAC Documentation Template Documentation for <Dataset Title> <Documentation Publication Date> <Authors> Abstract Data set citation Suggested citation for documentation Contact to provide feedback on documentation Table of Contents I. Introduction II. Data and Methodology III. Data Set Description(s) IV. How to Use the Data V. Potential Use Cases VI. Limitations VII. Acknowledgments VIII. Disclaimer IX. Use Constraints X. Recommended Citation(s) XI. Source Code XII. References XIII. Documentation Copyright and License Appendix 1. Contributing Authors & Documentation Revision History Appendix 2. Data Revision History 9

SEDAC Continuous Improvement Image Credit: Downs & Chen 2012 Improving the Trustworthiness of an Interdisciplinary Scientific Data Archive 10

ISO 16363 CoreTrustSeal Relationship Complementary messages to increase awareness of instruments Informing diverse communities on requirements for trustworthy repositories Mutually-informed development of instruments Both instruments based on OAIS framework Self-Assessments for Repository Preparation ISO 16363 Self-Assessment to prepare for CoreTrustSeal Certification CoreTrustSeal Certification to prepare for ISO 16363 Audit Shared pathway for improving repository practices CoreTrustSeal Certification -> ISO ISO16363 Certification Improvement of certification processes Experiences conducting audits can inform auditing practices Improvement of Requirements Experiences with audit instruments can inform improvement of instruments 11