The Security and Identity Committee will develop a Security Framework, which is a body of security-related knowledge within the context of the VoiceXML space.
| End Date | 24 November 2011 |
| Champion | Valene Skerpac (iBiometrics) (chair) |
| IP Policy | RAND |
The committee is formed in recognition of the increasing need for VoiceXML applications to play an important role in critical applications, including those that provide authentication and secure access to applications and system resources. The growing number and continual evolution of security attacks require industry and organizational use of established security methodologies that include process-oriented and technical approaches. The regulatory environment also drives the need for secure VoiceXML.
The committee will use established security approaches to perform a VoiceXML risk assessment for a collection of use cases. The exploratory committee identified ANSI X9.84-2010, Biometric Information Management and Security, as a basis of its security framework and risk assessment of the VoiceXML environment.
The committee has a single deliverable: a VoiceXML Risk Assessment. This risk assessment will analyze the impact of security threats in the VoiceXML environment. The assessment will include a threat analysis that will identify security weaknesses and associated controls needed to protect assets and functions. The risk assessment will be developed through the following activities:
The draft of the risk assessment will be reviewed quarterly. The document delivered at the end date of the committee will be complete, but it will also be a "living" document, as new threats can materialize. The risk assessment document can be used as a basis for future activities, which will include periodically revisiting the risk assessment.
There are several external efforts that may influence the security framework.
The committee will have weekly conference calls. In addition, the committee will hold quarterly reviews of the draft documents by a larger group of members knowledgeable in application use cases, Speaker Identification and Verification (SIV), security, VoiceXML, and related standards.
Committee members who can participate weekly will spend 1-3 hours per week and reviewers will spend 5 to 10 hours in a given quarter. Invited expert Dan Burnett will participate.
This charter was approved under the 01 Nov 2010 operating policies of the VoiceXML Forum. The terms of those operating policies apply.
Copyright © 2010, VoiceXML Forum. All rights reserved.