<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
<channel>
<title>P325 - Open Identity Summit 2022</title>
<link>http://dl.gi.de/handle/20.500.12116/38695</link>
<description/>
<pubDate>Tue, 21 Jul 2026 13:28:32 GMT</pubDate>
<dc:date>2026-07-21T13:28:32Z</dc:date>
<image>
<title>P325 - Open Identity Summit 2022</title>
<url>http://dl.gi.de:80/bitstream/id/62b31cc1-96a3-4b08-b970-b7c3638626c5/</url>
<link>http://dl.gi.de/handle/20.500.12116/38695</link>
</image>
<item>
<title>Risk variance: Towards a definition of varying outcomes of IT security risk assessment</title>
<link>http://dl.gi.de/handle/20.500.12116/38708</link>
<description>Risk variance: Towards a definition of varying outcomes of IT security risk assessment
Kurowski, Sebastian; Schunck, Christian H.
Roßnagel, Heiko; Schunck, Christian H.; Mödersheim, Sebastian
Assessing IT-security risks in order to achieve adequate and efficient protection measures has become the core idea of various industry practices and regulatory frameworks in the last five years. Some research however suggests that the practice of assessing IT security risks may be subject to varying outcomes depending on personal, situational and contextual factors. In this contribution we first provide a definition of risk variance as the variation of risk assessment outcomes due to individual traits, the processual environment, the domain of the assessor, and possibly the target of the assessed risk. We then present the outcome of an interview series with 9 decision makers from different companies that aimed at discussing whether risk variance is an issue in their risk assessment procedures. Finally, we elaborate on the generalizability of the concept of risk variance, despite the low sample size in light of varying risk assessment procedures discussed in the interviews. We find that risk variance could be a general problem of current risk assessment procedures.
</description>
<pubDate>Sat, 01 Jan 2022 00:00:00 GMT</pubDate>
<guid isPermaLink="false">http://dl.gi.de/handle/20.500.12116/38708</guid>
<dc:date>2022-01-01T00:00:00Z</dc:date>
</item>
<item>
<title>A user-centric approach to IT-security risk analysis for an identity management solution</title>
<link>http://dl.gi.de/handle/20.500.12116/38709</link>
<description>A user-centric approach to IT-security risk analysis for an identity management solution
Fähnrich, Nicolas; Winterstetter, Matthias; Kubach, Michael
Roßnagel, Heiko; Schunck, Christian H.; Mödersheim, Sebastian
In order to build identity management (IdM) solutions that are secure in the practical application context, a holistic approach their IT-security risk analysis is required. This complements the indispensable technical, and crypto-focused analysis of risks and vulnerabilities with an approach that puts another important vector for security in the center: the users and their usage of the technology over the whole lifecycle. In our short paper we focus exclusively on the user-centric approach and present an IT-security risk analysis that is structured around the IdM lifecycle.
</description>
<pubDate>Sat, 01 Jan 2022 00:00:00 GMT</pubDate>
<guid isPermaLink="false">http://dl.gi.de/handle/20.500.12116/38709</guid>
<dc:date>2022-01-01T00:00:00Z</dc:date>
</item>
<item>
<title>eIDAS 2.0: Challenges, perspectives and proposals to avoid contradictions between eIDAS 2.0 and SSI</title>
<link>http://dl.gi.de/handle/20.500.12116/38705</link>
<description>eIDAS 2.0: Challenges, perspectives and proposals to avoid contradictions between eIDAS 2.0 and SSI
Schwalm, Steffen; Albrecht, Daria; Alamillo, Ignacio
Roßnagel, Heiko; Schunck, Christian H.; Mödersheim, Sebastian
The proposal for review of the eIDAS Regulation from 2021 has opened strong expectations for a deep change in traditional identity models. The user-centric identity model proposed starts with the creation of European Digital Identity Wallets that will enable citizens’ control over their data in identification and authentication processes without control by entities providing the identification services. Likewise, with the proposed legal rules for giving legal certainty to electronic ledgers and blockchains, [eIDAS2]opens possibilities to decentralization, especially for the provision and management of user’s attributes. The implementation of qualified trust services for attestations or electronic ledgers limits decentralization by requirement of a trusted 3rd party. Standardization will be key in assuring interoperability at the EU level. What are the challenges and opportunities of eIDAS 2.0? And what are the main focuses and needs of (European) standardization? These and other questions will be analysed and discussed in the paper.
</description>
<pubDate>Sat, 01 Jan 2022 00:00:00 GMT</pubDate>
<guid isPermaLink="false">http://dl.gi.de/handle/20.500.12116/38705</guid>
<dc:date>2022-01-01T00:00:00Z</dc:date>
</item>
<item>
<title>Corporate Digital Responsibility and the current Corporate Social Responsibility standard: An analysis of applicability</title>
<link>http://dl.gi.de/handle/20.500.12116/38706</link>
<description>Corporate Digital Responsibility and the current Corporate Social Responsibility standard: An analysis of applicability
Carl, K. Valerie; Zilcher, Timothy M. C.; Hinz, Oliver
Roßnagel, Heiko; Schunck, Christian H.; Mödersheim, Sebastian
Corporate Digital Responsibility (CDR) takes a key role in developing, deploying, and managing digital technologies, products, and services responsibly and ethically. New technologies offer new chances but also expose new threats, especially related to privacy and data security that managers need to cope with. CDR puts privacy and data security attempts in a broader context to provide a more holistic approach to Corporate Responsibilities and to strengthen consumer trust in corporate activities. However, managers still face a lack of CDR guidelines that support the implementation of CDR activities. Existing guidelines related to Corporate Responsibilities, like the ISO standard 26000, provide guidance on Corporate Social Responsibility (CSR) addressing socially responsible and sustainable behaviour. However, current standards do not cover CDR directly. As such, the purpose of this contribution is to evaluate the applicability of the existing CSR standard to CDR to pave the way for CDR standardization in the future
</description>
<pubDate>Sat, 01 Jan 2022 00:00:00 GMT</pubDate>
<guid isPermaLink="false">http://dl.gi.de/handle/20.500.12116/38706</guid>
<dc:date>2022-01-01T00:00:00Z</dc:date>
</item>
</channel>
</rss>
