Certification. F. Genova (thanks to I. Dillo and Hervé L Hours)

Similar documents
Trust and Certification: the case for Trustworthy Digital Repositories. RDA Europe webinar, 14 February 2017 Ingrid Dillo, DANS, The Netherlands

Ensuring Proper Storage for Earth Science Data: The USGS Process to Certify Trusted Digital Repositories

GEOSS Data Management Principles: Importance and Implementation

DSA WDS Partnership Working Group Catalogue of Common Requirements

Assessing the FAIRness of Datasets in Trustworthy Digital Repositories: a 5 star scale

DSA WDS Partnership Working Group Catalogue of Common Requirements

Certification Efforts at Nestor Working Group and cooperation with Certification Efforts at RLG/OCLC to become an international ISO standard

Improving a Trustworthy Data Repository with ISO 16363

Conducting a Self-Assessment of a Long-Term Archive for Interdisciplinary Scientific Data as a Trustworthy Digital Repository

Agenda. Bibliography

Certification as a means of providing trust: the European framework. Ingrid Dillo Data Archiving and Networked Services

Indiana University Research Technology and the Research Data Alliance

European digital repository certification: the way forward

DEVELOPING, ENABLING, AND SUPPORTING DATA AND REPOSITORY CERTIFICATION

Data Curation Handbook Steps

DRI: Dr Aileen O Carroll Policy Manager Digital Repository of Ireland Royal Irish Academy

Core Trustworthy Data Repositories Extended Guidance. Core Trustworthy Data Repositories Requirements for Extended Guidance

Trusted Digital Repositories. A systems approach to determining trustworthiness using DRAMBORA

DRI: Preservation Planning Case Study Getting Started in Digital Preservation Digital Preservation Coalition November 2013 Dublin, Ireland

Trusted Digital Archives

Audit & Certification: an auditors perspective. Barbara Sierman, KB National Library of the Netherlands Royal Irish Academy, Dublin 4 june 2013

Implementation of the CoreTrustSeal

Digital Preservation Policy. Principles of digital preservation at the Data Archive for the Social Sciences

Basic Requirements for Research Infrastructures in Europe

ISO Self-Assessment at the British Library. Caylin Smith Repository

Digital Preservation Standards Using ISO for assessment

International Audit and Certification of Digital Repositories

University of British Columbia Library. Persistent Digital Collections Implementation Plan. Final project report Summary version

Large Scale Repository Auditing to ISO José Carvalho

DCH-RP Trust-Building Report

Sustainable Governance for Long-Term Stewardship of Earth Science Data

Session Two: OAIS Model & Digital Curation Lifecycle Model

FAIR-aligned Scientific Repositories: Essential Infrastructure for Open and FAIR Data

ITG. Information Security Management System Manual

Applying Archival Science to Digital Curation: Advocacy for the Archivist s Role in Implementing and Managing Trusted Digital Repositories

How FAIR am I? FAIR Principles and Interoperability of Data and Tools

Science Europe Consultation on Research Data Management

The OAIS Reference Model: current implementations

31 March 2012 Literature Review #4 Jewel H. Ward

ebooks Preservation at Scholars Portal Kate Davis & Grant Hurley Scholars Portal, Ontario Council of University Libraries

Digital Preservation: How to Plan

ILNAS/PSCQ/Pr004 Qualification of technical assessors

How can CLARIN archive and curate my resources?

The International Journal of Digital Curation Issue 1, Volume

From production to preservation to access to use: OAIS, TDR, and the FDLP OAIS TRAC / TDR

The Canadian Information Network for Research in the Social Sciences and Humanities.

UNIVERSITY OF NOTTINGHAM LIBRARIES, RESEARCH AND LEARNING RESOURCES

Computing Accreditation Commission Version 2.0 CRITERIA FOR ACCREDITING COMPUTING PROGRAMS

Registry Interchange Format: Collections and Services (RIF-CS) explained

ITG. Information Security Management System Manual

Fair data and open data: differences and consequences

Information Technology Branch Organization of Cyber Security Technical Standard

The Research Data Alliance (RDA): building global data connections CC BY-SA 4.0

_isms_27001_fnd_en_sample_set01_v2, Group A

Inge Van Nieuwerburgh OpenAIRE NOAD Belgium. Tools&Services. OpenAIRE EUDAT. can be reused under the CC BY license

UNT Libraries TRAC Audit Checklist

SCIOPS SERAD Referencing and data archiving Service

Data Management Checklist

ISO : Competence Requirements Clause 7

Conferenza GARR Moving Forward to deliver an «EOSC in Practice» by 2018

ETSI ESI and Signature Validation Services

Long-term digital preservation of UNSWorks

Data Access Policy ... WE ARE SUPPORTED BY THE UNIVERSITY OF ESSEX, THE ECONOMIC AND SOCIAL RESEARCH COUNCIL, AND JISC

Institute of Internal Auditors 2019 CONNECT WITH THE IIA CHICAGO #IIACHI

ISO/IEC ISO/IEC

Building an Assurance Foundation for 21 st Century Information Systems and Networks

NRF Open Access Statement Impact Survey

ETSI TR V1.1.1 ( )

Scientific Research Data Management Policy

ICGI Recommendations for Federal Public Websites

ISO/IEC INTERNATIONAL STANDARD. Information technology Software asset management Part 1: Processes and tiered assessment of conformance

Competency Definition

Digital Health Cyber Security Centre

eidas Workshop Return on Experience from Conformity Assessment Bodies - EY June 13, 2016 Contacts: Arvid Vermote

Emory Libraries Digital Collections Steering Committee Policy Suite

IT Governance ISO/IEC 27001:2013 ISMS Implementation. Service description. Protect Comply Thrive

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

RDMG Research Data Management Group at Freiburg University

Developing a Research Data Policy

Striving for efficiency

Welcome to the Pure International Conference. Jill Lindmeier HR, Brand and Event Manager Oct 31, 2018

EA-7/05 - EA Guidance on the Application of ISO/IEC 17021:2006 for Combined Audits

Preservation. Policy number: PP th March Table of Contents

Digital repositories as research infrastructure: a UK perspective

DataFlow and VIDaaS Workshop

SECURITY & PRIVACY DOCUMENTATION

Sparta Systems TrackWise Digital Solution

BUILDING CYBERSECURITY CAPABILITY, MATURITY, RESILIENCE

About Knowledge Convergence. e-infrastructures Austria an interdisciplinary case study concerning research resources and their management

EUDAT. A European Collaborative Data Infrastructure. Daan Broeder The Language Archive MPI for Psycholinguistics CLARIN, DASISH, EUDAT

ISO/IEC overview

Security Management Models And Practices Feb 5, 2008

OAIS: What is it and Where is it Going?

EUDAT. Towards a pan-european Collaborative Data Infrastructure

CERTIFICATE SCHEME THE MATERIAL HEALTH CERTIFICATE PROGRAM. Version 1.1. April 2015

Data publication and discovery with Globus

Architecture and Standards Development Lifecycle

Effective: 12/31/17 Last Revised: 8/28/17. Responsible University Administrator: Vice Chancellor for Information Services & CIO

Implementation of the CoreTrustSeal

An Introduction to Digital Preservation

Transcription:

Certification F. Genova (thanks to I. Dillo and Hervé L Hours)

Perhaps the biggest challenge in sharing data is trust: how do you create a system robust enough for scientists to trust that, if they share, their data won t be lost, garbled, stolen or misused? 2

What is a trustworthy repository? 3 mission to provide reliable, longterm access to managed digital resources to its designated community, now and into the future constant monitoring, planning, and maintenance understand threats to and risks within its systems regular cycle of audit and/or certification

The certification landscape 4 4 certification standards available DIN 31644 ISO 16363

European certification framework 5 Basic Certification is granted to repositories which obtain DSA certification ICSU-WDS at the same level Extended Certification is granted to Basic Certification repositories which in addition perform a structured, externally reviewed and publicly available self-audit based on DIN 31644/nestorSeal Formal Certification is granted to repositories which in addition to Basic Certification obtain full external audit and certification based on ISO 16363

Why a formal audit/certification? 6 Yes, why, when our users trust us? The example of CDS Trusted by users, data providers and agencies CDS underwent basic certification in the WDS and DSA contexts An in-depth work on our procedures when checking the criteria A very interesting team work Finally no change in our process but an end-to-end description, clarification of licensing aspects, etc Very positive reaction from our authorities, the journal we work with, etc It was worth it

OAIS-like description of our services Pérennisation des données scientifiques, Toulouse, F. Genova, CDS 7

Basic certification 8 Real interest for the data providers But What to do in practice when you are a data provider? An important topic to tackle within the RDA RDA established partnership with WDS on that topic (and others): a common Interest Group WDS + DSA : RDA/CDS Certification of digital repositories WG

Certification WG background 9 Data Seal of Approval and World Data System both lightweight mechanisms for repository assessment Self-assessment, no on-site visit Peer-reviewed assessment supervised by the DSA Board and the WDS Scientific Committee DSA began in social science and humanities, WDS in natural and physical sciences but both expanding in scope Over past years, both groups began to see synergies Common members! DSA/WDS Certification WG

WG Goals, which were achieved 10 Develop common catalog of criteria for basic repository assessment Develop common procedures for assessment Implement a shared testbed for assessment i.e. alignment For a later stage : Ultimately, create a shared framework for certification that includes other standards as well, including Nestor and ISO 16363/TRAC

Common requirements 11 16 common criteria Each criterion comes with guidance and self assessment level Context: an essential element. The trustworthiness evaluation depends on the data repository mission! Three topics addressed Organisational infrastructure Digital object management Technology List of criteria in annex at the end of the talk

Strong message 12 Very useful for self-assessment even if not submitted for external review! All criteria come with guidance and self-assessment of compliance level (not to be used by the external reviewers but here to help the applicants)

The Certification Working Group 13 https://rd-alliance.org/groups/repository-audit-andcertification-dsa%e2%80%93wds-partnership-wg.html

The WG Recommendations are on line 14 https://rdalliance.org/group/re pository-audit-andcertificationdsa%e2%80%93wds -partnershipwg/outcomes/dsawds-partership

Organisational infrastructure 15 Mission/scope Licenses Continuity of access Confidentiality/Ethics Organisational infrastructure Expert guidance

Digital object management 16 Data Integrity and authenticity Appraisal Documented storage procedure Preservation plan Data quality Workflows Data discovery and identification Data reuse

Technology 17 Technical infrastructure Security

Common catalogue 18 R0 Context Please provide context for your repository R1 Mission/Scope Organizational Infrastructure The repository has an explicit mission to provide access to and preserve data in its domain R2 Licenses Organizational Infrastructure The repository maintains all applicable licenses covering data access and use and monitors compliance

Common catalogue 19 R3 Continuity of access Organizational infrastructure The repository has a continuity plan to ensure ongoing access to and preservation of its holdings R4 Confidentiality/ethics Organizational Infrastructure The repository ensures, to the extent possible, that data are created, curated, accessed, and used in compliance with disciplinary and ethical norms R5 Organizational infrastructure Organizational Infrastructure The repository has adequate funding and sufficient numbers of qualified staff managed through a clear system of governance to effectively carry out the mission

Common catalogue 20 R6 Expert guidance Organizational Infrastructure The repository adopts mechanism(s) to secure ongoing expert guidance and feedback (either in-house, or external, including scientific guidance, if relevant) R7 Data integrity and authenticity Digital Object Management The repository guarantees the integrity and authenticity of the data R8 Appraisal Digital Object Management The repository accepts data and metadata based on defined criteria to ensure relevance and understandabilityfor data users

Common catalogue 21 R9 Documented storage procedures Digital Object Management The repository applies documented processes and procedures in managing archival storage of the data R10 Preservation plan Digital Object Management The repository assumes responsibility for long-term preservation and manages this function in a planned and documented way R11 Data quality Digital Object Management The repository has appropriate expertise to address technical data and metadata quality and ensures that sufficient information is available for end users to make quality-related evaluations

Common Catalogue 22 R12 Workflows Digital Object Management Archiving takes place according to defined workflows from ingest to dissemination R13Data discovery and identification Digital Object Management The repository enables users to discover the data and refer to them in a persistent way through proper citation R14Data reuse Digital Object Management The repository enables reuse of the data over time, ensuring that appropriate metadata are available to support the understanding and use of the data

Common Catalogue 23 R15 Technical infrastructure Technology The repository functions on well-supported operating systems and other core infrastructural software and is using hardware and software technologies appropriate to the services it provides to its Designated Community R16 Security Technology The technical infrastructure of the repository provides for protection of the facility and its data, products, services, and users