Who would be willing help evaluate software for members and/or use for internal purposes? We also need some standard practices, procedures, and tools for this purpose. There are lots of informative resources for using FOSS as components in other projects, which is not exactly right for Chattanooga.Digital since we primarily deploy off-the-shelf FOSS (although one aspect of this is how to evaluate custom or special purpose apps for members, which would be a fee-based service). The "grand-daddy" seems to be https://dwheeler.com/oss_fs_eval.html from 2011. The author includes lots of good resources although a few seem to be outdated. The Concise Guide for Evaluating Open Source Software <https://best.openssf.org/Concise-Guide-for-Evaluating-Open-Source-Software.h...> by the Open Source Security Foundation is really good. Another one I like is https://leaddev.com/software-quality/12-things-consider-when-assessing-open-... because it seems practical and thorough. Let's combine key elements from these to create a review protocol and scoresheet. At the same time, we need to look at identify and access management (IAM) software. I suggest we use this to hammer out the process, etc. The key missing element with the frameworks is "why." What is the purpose for and requirements of the software? A related element is the user, specifically the "sponsor" that requires the software. For IAM, the sponsor is us, the cooperative, including all members. The basic purpose, as the term implies, is to manage members' access to resources, including and via a digital identity. Our digital identities are a collection of attributes, credentials, data, and devices that represent us. As mentioned in a prior email, the fundamental purpose of Chattanooga.Digital is to give members complete control and full ownership of our digital assets, including our digital identities. More practically, we need: * Authentication via passkeys, passwords, and other factors for single sign-on to as many of our apps/systems as possible. * Authorization for access to apps, data, files, etc., with permissions in various roles. * Automation of user account management as needs for authentication and authorization change. * Governance and monitoring of access, including all of the above, for accounting, compliance, planning, and security purposes. * Via standard methods and protocols: OAuth, OIDC, SAML, etc. Beyond that, we need to position Chattanooga.Digital as a digital identity provider (IdP) for members to access other systems and own data about that access. The main things about this is (a) complementing/replacing centralized digital IDs (b) with a trusted source and (c) supporting decentralized self-sovereign IDs. See https://www.cloudflare.com/learning/access-management/what-is-an-identity-pr..., https://www.corbado.com/blog/digital-identity-guide, and https://www.imperva.com/learn/data-security/identity-providers-idps/ for background on this. Please chime in with your thoughts about evaluation approach, methods, process, etc., and how to apply all of that to IAM. Thanks! -- GL