ConsumerDataStandardsAustralia / future-plan

Repository of future demand for work by the DSB. Used to manage demand and prioritisation for up to twelve months ahead.
1 stars 0 forks source link

DSB Item - FAPI 2.0 Profile Transition #47

Closed CDR-API-Stream closed 1 year ago

CDR-API-Stream commented 2 years ago

Problem Statement

In Decision 182, the Data Standards Chair approved four recommendations. This Future Plan item covers Recommendation 2 and the targeted consultation to migrate the Data Standards from FAPI 1.0 to FAPI 2.0.

The OpenID Foundation (OIDF)—which governs the FAPI specifications—has developed the second version of their FAPI profile (FAPI 2.0). FAPI 2.0 applies key lessons from the implementation of FAPI 1.0 globally and makes improvements to security whilst as the same time simplifying the complexity and cost of implementation.

This recommendation is the target state after transition to FAPI 1.0. This recommendation is a mandatory target state prior to the introduction of Action Initiation within the CDR provided data holders and vendors can achieve the required timeframes before the obligation dates for introducing Action Initiation within the CDR.

Adoption should be in line with the requirements of the CDR and any appropriate security controls currently defined.

This includes the family of standards defined in the FAPI 2.0 profile including, but not limited to:

Beyond FAPI 2.0, data standards to be consulted upon include:

Key Future Directions Recommendations

JamesMBligh commented 2 years ago

Significant planning on this item has been conducted but it has been shifted to Q1 2022 for ongoing work.

FAPI 1 planning is complete but a DP still remains to be created for FAPI 2