The Security Committee supports the security and integrity of the 1EdTech standards ecosystem. The committee conducts an annual security audit of existing specifications, including LTI, Caliper, OneRoster, Edu-API, QTI, CASE, CLR, and Open Badges.
The committee also maintains and revises the 1EdTech Security Framework, which addresses areas such as OAuth 2.0 patterns, token revocation, JSON Web Tokens (JWTs), and dynamic client registration. In addition, members respond to reported vulnerabilities and other security incidents and advise Product Steering Committees and workgroups on incorporating consistent security practices into new and evolving standards.
Participants can contribute security expertise, implementation experience, and insight into emerging threats, vulnerabilities, and risk-mitigation practices.
Meetings: Monthly on the first Tuesday of each month at 11:00 a.m. EDT and the Third Tuesday of each month starting in November.
Contact: membersuccess@1edtech.org