<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0cm;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:Consolas;
mso-fareast-language:EN-GB;}
span.EmailStyle22
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;
mso-fareast-language:EN-US;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-GB link=blue vlink=purple style='word-wrap:break-word'><div class=WordSection1><p class=MsoNormal><span style='mso-fareast-language:EN-US'>Something to add to the agenda today.<o:p></o:p></span></p><p class=MsoNormal><span style='mso-fareast-language:EN-US'><o:p> </o:p></span></p><p class=MsoNormal><span style='mso-fareast-language:EN-US'>You may remember that we are concerned that finalising documents in CCSDS would mean that if we get ISO comments that require changes then we would have inconsistent CCSDS and ISO versions, which we certainly would not want, so we would have to go through CCSDS again with Pink pages etc. to make the two versions consistent. But I think there is no real risk with ISO 16919.<o:p></o:p></span></p><p class=MsoNormal><span style='mso-fareast-language:EN-US'><o:p> </o:p></span></p><p class=MsoNormal><span style='mso-fareast-language:EN-US'>Anyway, we should resolve these issues. <o:p></o:p></span></p><p class=MsoNormal><span style='mso-fareast-language:EN-US'><o:p> </o:p></span></p><p class=MsoNormal><span style='mso-fareast-language:EN-US'>To make a start I’ve put some thoughts below.<o:p></o:p></span></p><p class=MsoNormal><span style='mso-fareast-language:EN-US'><o:p> </o:p></span></p><p class=MsoNormal><span style='mso-fareast-language:EN-US'>..David<o:p></o:p></span></p><p class=MsoNormal style='margin-left:36.0pt'><span style='mso-fareast-language:EN-US'><o:p> </o:p></span></p><div style='border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm 0cm 0cm'><p class=MsoNormal style='margin-left:36.0pt'><b><span lang=EN-US>From:</span></b><span lang=EN-US> Mario.Merri@esa.int <Mario.Merri@esa.int> <br><b>Sent:</b> 27 July 2021 09:23<br><b>To:</b> david@giaretta.org; garrett@his.com<br><b>Cc:</b> Duhaze Marc <Marc.Duhaze@cnes.fr><br><b>Subject:</b> Conditions on CCSDS 652.1<o:p></o:p></span></p></div><p class=MsoNormal style='margin-left:36.0pt'><o:p> </o:p></p><p class=MsoNormal style='margin-left:36.0pt'><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>Dear both,</span> <br><br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>I recall that you have CESG conditions to resolve on CCSDS 652.1-P-2.1, Requirements for Bodies Providing Audit and Certification of Candidate Trustworthy Digital Repositories:</span> <br><br><b><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>Ignacio Aguilar Sanchez (Approve with Conditions): </span></b> <br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>The following paragraph includes the word 'security' at the end. "B4 CONSEQUENCES OF NOT APPLYING SECURITY TO THE TECHNOLOGY If adequate steps are not taken to </span><br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>address security issues then the information held by the repository may be put at risk, in particular risking confidentiality and security."</span> <br><br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>That word should be replaced by either 'integrity' or 'authenticity', which is like 'confidentiality', a specific security feature to be highlighted.</span> <o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>This is ISO 16919.<o:p></o:p></p><p class=MsoNormal>The current text is:<o:p></o:p></p><p class=MsoNormal><i>B4 CONSEQUENCES OF NOT APPLYING SECURITY TO THE TECHNOLOGY<o:p></o:p></i></p><p class=MsoNormal><i>If adequate steps are not taken to address security issues then the information held by the repository may be put at risk, in particular risking confidentiality and security.<o:p></o:p></i></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>I think it would be useful to ADD “integrity” i.e. “risking confidentiality, integrity and security” but I think confidentiality is different from integrity in that if someone deleted a file then the collection’s integrity is destroyed but if one just takes a copy of a file with names and addresses then confidentiality is destroyed.<o:p></o:p></p><p class=MsoNormal style='margin-left:36.0pt'><br><br><b><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>Jonathan Wilmot (Approve Unconditionally): </span></b> <br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>Reference format is not consistent. It is listed as reference [1] " ISO 16363" . another time it's "CCSDS 652.0-M-1/ISO 16363" , and other times it's just reference [1 ]</span> <br><br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>Please move your document through the process.</span> <br><br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>Also, in your report to MOIMS the title is wrong as it reads "Guidelines ..." and not "Requirements ...". Please make sure that next time you make it consistent. </span><br><br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>Best regards,</span> <br><br><span style='font-size:12.0pt;font-family:"Arial",sans-serif'>__Mario</span> <o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal>We should make the references consistent, and be consistent in using the name.<o:p></o:p></p><p class=MsoNormal style='margin-left:36.0pt'><br><br><br><o:p></o:p></p><pre style='margin-left:36.0pt'><o:p> </o:p></pre></div></body></html>