Tag: identity security

  • Cybersecurity by Design: The Contact Initiative Approach

    The Contact Initiative treats cybersecurity as an infrastructure-level property, not an add-on, through a defined set of controls:

    • Verified, role-based identity for every user, separate from any reassignable number.
    • Zero-trust access to the resolution layer — no standing access for any relying party, vendor, or MI agent.
    • Non-enumerable, rate-limited query-response verification, preventing bulk scraping of the identity graph.
    • Mandatory DNSSEC, SPF, DKIM, and enforced DMARC on every issued domain.
    • Aliases that hide the administrative address, shrinking the target for spear-phishing.
    • Scoped, short-lived credentials for vendors and MI agents instead of raw record access.
    • Persistent, tamper-evident logging at both the institution and national-registry level.
    • Mandatory dual control for high-impact actions like bulk data export or identifier retirement overrides.
    • A public security-disclosure and bug-bounty commitment for the registry and its reference implementation.

    That vendor-focused control matters most: reported research indicates a majority of disclosed K–12 breaches trace back to a compromised vendor, not the district itself. Tokenized, scoped, short-lived vendor credentials are aimed squarely at closing that pathway.