Jericho Forum
An international cybersecurity forum that developed principles and architectures for securing organisations in a de-perimeterised, cloud-connected world.
Last updated August 25, 2026
Overview
Jericho Forum was an international cybersecurity and information-security industry group focused on de-perimeterisation: the idea that organisations could no longer rely on a clearly defined corporate network boundary as their primary security control. The forum emerged from discussions among corporate chief information security officers during the summer of 2003, following an initial meeting hosted by Cisco. David Lacey of Royal Mail was a key initiator, and the organisation was formally established in January 2004. Its founding premise was that conventional perimeter security did not adequately address mobile working, business-to-business collaboration, wireless access, outsourced services, federated identity, consumerisation of IT, and the increasing movement of information beyond the enterprise network. Rather than treating the internal network as inherently trusted and the outside world as inherently hostile, Jericho Forum promoted security principles based on protecting information, devices, identities, transactions, and relationships wherever they operated. The forum’s membership combined user members, generally representing enterprises and security practitioners, with vendor members. It initially restricted eligibility for elected positions to user members, but opened that eligibility to both user and vendor members in December 2008. Although its roots were British, the participating organisations had international responsibilities and its membership expanded across Europe, North America, and Asia-Pacific. The Open Group provided day-to-day management and later hosted the forum’s work within its broader security activities. One of Jericho Forum’s best-known contributions was the Jericho Forum Commandments, a set of principles for operating securely without assuming a dependable network perimeter. The group subsequently moved from describing the problem to developing practical models, including Collaboration-Oriented Architecture and its associated framework. These publications addressed subjects such as endpoint security, data protection, identity, device and person lifecycle management, secure protocols, privacy, risk management, and information lifecycle management. As cloud computing became a major enterprise technology trend, the forum applied its principles to collaborative cloud environments. Its Cloud Cube Model presented a way to compare cloud formations and security characteristics, while the group argued that security should be designed into cloud services rather than added after deployment. Elements of this work were transferred to the Cloud Security Alliance for use in its guidance. Identity became another major focus. The forum published its Identity Commandments in 2011 and related concepts and videos in 2012, addressing personas, trust, privacy, entities, entitlement, and the construction of a global digital identity ecosystem. Later work explored smart data, trust ecosystems, data principles, and secure business collaboration. Jericho Forum declared that it had achieved its principal objectives and sunsetted at The Open Group’s London conference on 29 October 2013. Its remaining work was transferred to successor or partner organisations: identity work continued through the Global Identity Foundation, cloud-related material influenced the Cloud Security Alliance, and other topics moved into The Open Group’s Security Forum. The Open Group subsequently described the Jericho Forum as a significant source of anticipatory thinking about security models that later became associated with zero-trust approaches. The forum was also cited in a 2025 UK government cyber-growth report as an example of early demand-led thinking that helped lay foundations for contemporary zero-trust practice.
History
Jericho Forum developed from informal conversations among corporate security leaders who believed that the established enterprise perimeter model no longer matched the way organisations used technology. Those discussions began in the summer of 2003 and followed an initial meeting hosted by Cisco. David Lacey of Royal Mail was among the central initiators. The group was formally founded in January 2004, with the aim of defining the security implications of de-perimeterisation and creating a consistent body of principles for addressing them. The forum’s central argument was that enterprise information increasingly crossed organisational, geographic, and technical boundaries. Employees worked remotely, companies exchanged data with partners, wireless devices extended access beyond offices, and outsourced and hosted services weakened the assumption that a single organisation controlled the full network path. Jericho Forum therefore challenged the distinction between a trusted internal environment and an untrusted external environment. It promoted security controls that followed information, identities, endpoints, and transactions rather than depending on a fixed network boundary. Its early work concentrated on defining the problem and articulating principles. The Jericho Forum Commandments became the group’s signature publication, setting out a collection of principles for surviving in a de-perimeterised world. Related position papers examined inherently secure protocols, VoIP, wireless security, internet filtering, endpoint security, federated identity, data privacy, information access policy, audit, and data management. The group then shifted toward solution architecture. Its Collaboration-Oriented Architecture work described how organisations could secure interactions among people, devices, applications, and information without assuming that all participants were inside a trusted perimeter. The forum produced a COA paper, process documents covering areas such as endpoint, device, person, and risk lifecycle management, and a broader COA Framework. These materials treated collaboration as a core business and security requirement rather than as an exception to an internally focused network design. Cloud computing became a natural extension of this work. Jericho Forum argued that cloud security needed to be designed into collaborative services from the beginning, not retrofitted after information and applications had moved into shared or externally operated environments. Its Cloud Cube Model offered a conceptual method for comparing cloud formations and their security implications. Elements of the cloud collaboration work were later passed to the Cloud Security Alliance for incorporation into its guidance. From 2009 onward, identity became the forum’s final major programme. The Identity Commandments, published in 2011, addressed identity principles, personas, trust, privacy, entities, entitlement, and access management. Follow-on material explained key concepts and used videos to communicate the proposed foundations of a global identity ecosystem. The Global Identity Foundation subsequently continued this strand of work, linking the principles to its Identity 3.0 initiative. In its final period, the forum also contributed to discussions about smart data, trust ecosystems, data principles, secure business collaboration, network entities, and information protection. These outputs were intended to be carried forward rather than maintained as a separate long-term organisation. Jericho Forum declared success and sunsetted at The Open Group’s London conference on 29 October 2013. In 2014 its work was merged into or transferred to The Open Group’s Security Forum and other successor initiatives. The forum’s ideas have since been associated with the broader evolution of zero-trust security, although Jericho Forum itself was a pre-existing industry forum rather than a commercial zero-trust product vendor.
- 2025Influence recognised in UK cyber policy
A UK government cyber-growth action-plan report referenced the forum’s contribution to early zero-trust thinking.
- 2014Work transferred to successor forums
Jericho Forum work moved into The Open Group Security Forum and other successor organisations.
- 2013Forum sunsets
Jericho Forum declared success and ended as a standalone group at The Open Group’s London conference on 29 October.
- 2011Identity Commandments published
The forum published principles covering identity, entitlement, and access management.
- 2010Self-Assessment Scheme published
A self-assessment approach was issued to help organisations evaluate their progress toward de-perimeterised security.
- 2009Cloud collaboration becomes a major focus
The forum applied its principles to cloud computing and published the Cloud Cube Model.
- 2008COA Framework and lifecycle papers developed
The forum expanded its architectural work with a Collaboration-Oriented Architecture framework and process guidance.
- 2006Jericho Forum Commandments published
The forum released its foundational principles for security in a de-perimeterised environment.
- 2005Visioning White Paper published
The forum issued an introductory paper explaining its purpose and the security problem it intended to address.
- 2004Jericho Forum is formally founded
The international forum was established in January, with David Lacey among its principal initiators.
- 2003Informal de-perimeterisation discussions begin
Corporate security leaders began discussing the limitations of network-perimeter security during the summer, following an initial Cisco-hosted meeting.
Products and positioning
A neutral, practitioner-led cybersecurity forum producing principles, frameworks, and position papers rather than commercial security products. Its distinctive position was that enterprise security should be based on information, identity, device, and collaboration controls instead of a presumed trusted corporate network perimeter.
Jericho Forum CommandmentsSecurity principles2006
A foundational set of principles describing how organisations can protect information and conduct business when the traditional enterprise network perimeter is no longer dependable. The commandments address decentralised security, information protection, identity, devices, access, and the need to avoid treating internal network location as proof of trust. Versions were issued in 2006 and revised in 2007.
Collaboration-Oriented Architecture (COA)Security architecture framework2008
A conceptual and practical architecture for securing collaboration among people, devices, applications, and information across organisational boundaries. The related papers and framework covered endpoint security, person and device lifecycle management, risk lifecycle management, secure protocols, enterprise information protection, and information lifecycle management.
Cloud Cube ModelCloud security model2009
A model for comparing cloud formations and assessing their implications for secure collaboration. It extended the forum’s de-perimeterisation thinking to cloud environments and encouraged organisations to consider security architecture before moving workloads or information into cloud services.
Identity CommandmentsDigital identity principles2011
A set of principles for identity, entitlement, access management, personas, privacy, and trust in a globally connected environment. The work sought to describe the components of a more interoperable digital identity ecosystem and was later continued by the Global Identity Foundation.
Jericho Forum Self-Assessment SchemeSecurity assessment guidance2010
A guidance mechanism intended to help organisations assess their adoption of de-perimeterised security principles and identify areas requiring further architectural or operational work.
Flagship businesses
- Jericho Forum Commandments
- Collaboration-Oriented Architecture (COA)
- COA Framework
- Cloud Cube Model
- Identity Commandments
- Self-Assessment Scheme
- Guidance on secure collaboration and de-perimeterised security
Brand decisions
- 2013Sunset the forum after declaring successOther
The forum had produced its principal principles and frameworks and had developed routes for continuing its remaining work.
What changed. It declared success and ended as a standalone organisation at The Open Group’s London conference on 29 October.
Aftermath. Its work moved to The Open Group Security Forum, the Cloud Security Alliance, the Global Identity Foundation, and other successor efforts.
- 2011Make identity a principal workstreamStrategy
As access became less dependent on network location, the forum identified identity, entitlement, and access management as central security concerns.
What changed. It published the Identity Commandments and later supporting concepts and educational materials.
Aftermath. The identity work continued through the Global Identity Foundation and related digital-identity initiatives.
- 2009Shift programme emphasis toward secure cloud collaborationStrategy
The growth of cloud computing created a new setting in which information and collaboration routinely crossed organisational boundaries.
What changed. The forum applied its de-perimeterisation and COA concepts to cloud security, including the Cloud Cube Model.
Aftermath. Parts of the cloud work were transferred to the Cloud Security Alliance for use in its guidance.
- 2008Broaden election eligibility to vendor membersStrategy
The forum had initially reserved election eligibility for user members, even though vendor members participated in its work.
What changed. In December 2008, eligibility was extended to both vendor and user members.
Aftermath. The change formalised a more inclusive governance model while preserving the forum’s user-led security perspective.
Leadership
| Name | Title | Tenure |
|---|---|---|
| David Lacey | Initiator and founding participantformer | 2003– |
Recent events
- 2025UK cyber-growth report highlights Jericho Forum’s influence
A UK government cyber-growth action-plan report cited the forum as an example of anticipatory thinking that helped establish foundations for zero-trust security.
Regulation - 2014Jericho Forum work merged into The Open Group security activities
The forum’s work was incorporated into The Open Group’s Security Forum and related successor initiatives.
M&A - 2013Jericho Forum sunsets after declaring success
At The Open Group’s London conference, the forum declared its principal work complete and ended as a standalone group.
Other - 2008Jericho Forum opens election eligibility to vendor members
The forum changed its membership governance so that vendor members, as well as user members, could stand for election.
Other - 2008Jericho Forum focuses on cloud security
The forum identified cloud computing and secure collaboration as a major next application of its de-perimeterisation principles.
Other - 2004Jericho Forum formally established
The loose CISO discussion group that had formed around de-perimeterisation became a formal international forum.
Other
Sources
Cite this profile: Cite the canonical profile. /brand-wiki/jericho-forum · Editorial policy · How profiles are compiled