<?xml version="1.0" encoding="UTF-8"?>
<PerformancePlanOrReport xmlns="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"

 xsi:schemaLocation="urn:ISO:std:iso:17469:tech:xsd:PerformancePlanOrReport http://stratml.us/references/PerformancePlanOrReport20160216.xsd" Type="Strategic_Plan"><Name>About the Coalition for Content Provenance and Authenticity</Name><Description>An open technical standard providing publishers, creators, and consumers the ability to trace the origin of different types of media.</Description><OtherInformation>C2PA unifies the efforts of the Adobe-led Content Authenticity Initiative (CAI) which focuses on systems to provide context and history for digital media, and Project Origin, a Microsoft- and BBC-led initiative that tackles disinformation in the digital news ecosystem.</OtherInformation><StrategicPlanCore><Organization><Name>Coalition for Content Provenance and Authenticity</Name><Acronym>C2PA</Acronym><Identifier>_ced00980-0b65-11ec-b840-3bab2c83ea00</Identifier><Description>The Coalition for Content Provenance and Authenticity (C2PA) addresses the prevalence of misleading information online through the development of technical standards for certifying the source and history (or provenance) of media content.</Description><Stakeholder StakeholderTypeType="Organization"><Name>Joint Development Foundation</Name><Description>C2PA is a Joint Development Foundation project, formed through an alliance between Adobe, Arm, Intel, Microsoft and Truepic.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>C2PA Steering Committee</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Adobe</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Arm</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>BBC</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Intel</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Microsoft</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Truepic</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>C2PA General Members</Name><Description>Are you interested in joining C2PA to develop open standards that certify the source and provenance of online content? Please complete the membership application ...</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>FRANCEtv</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Numbers Protocol</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>RIAA</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Society Library</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>WITNESS</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Contributor Members</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Akamai</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>CBC</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>CLink</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Dalet</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Digimarc</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Fastly</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Melcher Systems</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Ravnur</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>SafeCast Limited</Name><Description>



</Description></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Serelay</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Serum of Truth</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Steg AI</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>The New York Times</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Organization"><Name>Web Commodore</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>C2PA Users</Name><Description>While not intended to limit consideration of other interested parties, C2PA’s users can be broadly understood as:</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Content Creators</Name><Description>Content creators, who wish to assert information about content they’ve produced in a way that can be trusted. Common examples include:</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Creative Professionals</Name><Description>Knowledge workers</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Journalists</Name><Description>Journalists and news media organizations:
* Including both professional and citizen journalists
* Including those operating in high-risk environments
</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>News Media Organizations</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Human-Rights Defenders</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Amateur News Producers</Name><Description>Amateur producers of news media content</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Content Publishers</Name><Description>Content publishers, who wish to have better information on which to make decisions about what content to trust. Common examples include:</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>News Media Organizations</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Social Media Platforms</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Content Distribution Networks</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Content Consumers</Name><Description>Content consumers, who wish to understand the process by which the content was created. Common examples include:</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Legal Systems</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>News Media Consumers</Name><Description>Consumers of news media and social media sites</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Social Media Consumers</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Vendors</Name><Description>Vendors and implementors, who wish to build software or hardware tools to create, persist, exchange, or consume C2PA provenance data in a way that is interoperable with other C2PA-enabled systems.</Description></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Implementors</Name><Description/></Stakeholder></Organization><Vision><Description>The provenance of media is traceable</Description><Identifier>_ced00a84-0b65-11ec-b840-3bab2c83ea00</Identifier></Vision><Mission><Description>To enable tracing of the origin of different types of media</Description><Identifier>_ced00b4c-0b65-11ec-b840-3bab2c83ea00</Identifier></Mission><Value><Name>Principles</Name><Description>Guiding Principles for C2PA Designs and Specifications ~ These principles are intended to guide C2PA initiative-wide specifications and designs.</Description></Value><Value><Name>Verification</Name><Description>C2PA specifications SHOULD provide a mechanism for the producers and custodians of any given content to assert, in a verifiable manner, any information they wish to disclose about the creation of that content and any actions taken since the asset’s creation. We refer to such information collectively as provenance.</Description></Value><Value><Name>Integrity</Name><Description>C2PA specifications SHOULD NOT provide value judgments about whether a given set of provenance data is “good” or “bad,” merely whether the assertions included within can be verified as associated with the underlying asset, correctly formed, and free from tampering.</Description></Value><Value><Name>Balance</Name><Description>C2PA specifications SHOULD take into account and strike a reasonable balance for the needs of any individual or organization that uses content to make decisions.</Description></Value><Value><Name>Privacy</Name><Description>C2PA specifications MUST respect the common privacy concerns of each of the target users ~ 
Details:
* C2PA specifications MUST allow for flexibility in whether C2PA data is stored directly in asset files or hosted in cloud-accessible storage.
* C2PA specifications MUST allow content creators, editors, and publishers to remove sensitive information before sharing with others. Subsequent participants must be made aware of such removal.
* C2PA specifications MUST allow certain information to be marked as not removable by C2PA-compliant tools. C2PA-compliant tools MUST refuse to validate any asset with a non-conforming removal.
* C2PA specifications MUST NOT rely on display-time filtering of content to achieve privacy. When use cases demand that authenticity data be removed, it should be permanently removed.
* C2PA specifications MUST allow for digital signatures to be created either on-device or on server, as fits the business and operating constraints of each implementor. Which option was chosen SHOULD be documented in any resulting data.
* C2PA specifications MUST NOT require identity of the person or organization making any assertion or claim about an asset to be documented. The specifications MAY allow that information to be represented, provided that representation is optional.
* C2PA-aware tools MUST disclose the nature of information that will be captured, recorded, and/or stored on users' behalf and MUST obtain informed consent from their users before doing so. Such tools SHOULD aim to present this information in a manner that concisely and accurately reflects the tradeoffs the user is making.
* C2PA specifications MUST be compatible with varying points of view and legal requirements with regard to data sovereignty and custody from file-only to primarily in cloud.
* C2PA-aware tools MUST allow their users control over what identity, if any, is used when generating C2PA-compliant metadata.</Description></Value><Value><Name>Accessibility</Name><Description>C2PA specifications MUST take into consideration the needs of interested users throughout the world. ~ 
Details:
* It MUST be possible to implement C2PA specifications on the computing platforms in widespread use in both developed and developing regions, specifically including lower-cost and older mobile devices.
* C2PA tool implementors SHOULD strive to communicate about C2PA-provided data in a way that maximizes comprehension across all levels of language and digital literacy.
* C2PA-aware tools, especially those for content consumers, SHOULD conform to Web Content Accessibility Guidelines. This will make C2PA information accessible to a wide range of people with disabilities, including accommodations for blindness and low vision, deafness and hearing loss, limited movement, speech disabilities, photosensitivity, and combinations of these, and some accommodation for learning disabilities and cognitive limitations; but will not address every user need for people with these disabilities.
* C2PA-aware tools SHOULD be accessible to users with limited or high-cost access to Internet services.</Description></Value><Value><Name>Interoperability</Name><Description>C2PA specifications SHOULD result in an ecosystem of tools for each of the above classes of target users which inter-operate successfully to maintain and display provenance information about assets. ~ 
Details: 
* A piece of content encoded with one C2PA-compliant tool MUST be readable by another C2PA-complaint tool.</Description></Value><Value><Name>Workflows</Name><Description>Fit with Existing Workflows | C2PA specifications MUST fit into the existing workflows of each of the target users named earlier, typically through incremental additions to existing tools. ~ 
Details:
* C2PA specifications MUST support all common asset and content file formats.
* C2PA specifications SHOULD build upon existing metadata standards (e.g. XMP) where feasible. C2PA specifications MAY take advantage of specific mechanisms available in specific formats (e.g. ISO BMFF) when appropriate.
* C2PA specifications SHOULD NOT require specific asset management or hosting strategies.
* C2PA specifications SHOULD allow for workflows that include authoring/editing tools that are not C2PA-compliant. Such gaps in understanding MUST be detected and documented.</Description></Value><Value><Name>Performance</Name><Description>C2PA specifications SHOULD avoid unreasonable performance characteristics for implementors. ~ 
Details: 
* C2PA specifications SHOULD consider performance characteristics across a variety of platforms, specifically including IoT devices, camera hardware, low-cost mobile devices, and server platforms.
* C2PA specifications SHOULD consider performance and size characteristics across a variety of content types, specifically including still imagery, documents, video, and audio.</Description></Value><Value><Name>Simplicity</Name><Description>Simplicity and Cost Burden | C2PA specifications SHOULD avoid unreasonable technical complexity and cost burden for implementors. ~ 
Details:
* C2PA specifications MUST NOT require implementors to provide cloud hosting of C2PA data.
* C2PA specifications SHOULD allow implementors to provide cloud hosting of C2PA data when the implementor feels it is appropriate.</Description></Value><Value><Name>Extensibility</Name><Description>C2PA specifications SHOULD provide extensibility to allow for extension and evolution of authenticity data. ~ 
Details: 
* C2PA specifications SHOULD describe a standard set of data that can be verifiably documented about an asset.
* C2PA specifications SHOULD allow for that standard set of data to evolve in a backward-compatible manner.
* C2PA specifications SHOULD allow for individual implementors to add vendor-specific information in a verifiably documented manner.
* C2PA specifications MUST describe the required “standard set of information about an asset” without the use of vendor-specific data types.</Description></Value><Value><Name>Usage</Name><Description>Misuse | C2PA specifications MUST be reviewed with a critical eye toward potential abuse and misuse of the framework. ~ 
Details:</Description></Value><Value><Name>Security</Name><Description>* C2PA specifications MUST be reviewed by security experts prior to public implementation.</Description></Value><Value><Name>Human Rights</Name><Description>* C2PA specifications MUST be reviewed for the ability to be abused and cause unintended harms, threats to human rights, or disproportionate risks to vulnerable groups globally.</Description></Value><Goal><Name>Specifications</Name><Description>Develop technical specifications for establishing content provenance and authenticity.</Description><Identifier>_ced00c5a-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>With the digital transformation of information sharing, the ability to trace the provenance of media has become critical. To address this issue at scale for publishers, creators and consumers, the Consortium will develop technical specifications for establishing content provenance and authenticity. The specifications will be informed by scenarios, workflows and requirements gathered from industry experts and partner organizations, including the Project Origin Alliance and the Content Authenticity Initiative (CAI.)

The Consortium Steering Committee will approve the formation and planned activities of technical working groups. Work will include:</OtherInformation><Objective><Name>Workflows</Name><Description>Document industry workflow requirements, informed by subject matter experts and partner organizations such as Project Origin and CAI</Description><Identifier>_ced00d2c-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>1.1</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Provenance</Name><Description>Apply those requirements to the development of content provenance specifications</Description><Identifier>_ced00e08-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>1.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Practices &amp; Designs</Name><Description>Develop best practices and reference designs for applying those standards to the targeted industry workflows</Description><Identifier>_ced00ee4-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>1.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Privacy, Control &amp; Tools</Name><Description>Ensure that the specifications can be used in ways that respect privacy and personal control of data, and promote tool availability for a wide range of organizations</Description><Identifier>_ced00fc0-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>1.4</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Security</Name><Description>Ensure that specifications meet appropriate security requirements</Description><Identifier>_ced01092-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>1.5</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Standardization</Name><Description>Promote selected specifications to become global standards</Description><Identifier>_ced014b6-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>1.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal><Goal><Name>Guidelines</Name><Description>Develop guidelines that address issues pertinent to the use of content provenance methods</Description><Identifier>_ced015a6-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation>In addition to identifying target industries, establishing technical working groups and working with partner organizations as appropriate, the Steering Committee will develop guidelines that address issues pertinent to the use of content provenance methods, including but not limited to:</OtherInformation><Objective><Name>Education</Name><Description>Educate creators, publishers, media consumers, regulatory bodies, and governmental agencies</Description><Identifier>_ced0168c-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>2.1</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Creators</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Publishers</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Media Consumers</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Regulatory Bodies</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Governmental Agencies</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Ecosystem</Name><Description>Establish a rich ecosystem of digital provenance enabled applications</Description><Identifier>_ced018d0-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>2.2</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Provenance</Name><Description>Facilitate the global adoption of digital provenance techniques by target industry devices, systems, and services</Description><Identifier>_ced019ca-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>2.3</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Specifications</Name><Description>Facilitate adoption of the Consortium’s specifications by social media and messaging platforms</Description><Identifier>_ced01ab0-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>2.4</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Social Media</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Messaging Platforms</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Data &amp; Privacy</Name><Description>Address the privacy and data concerns of creators, publishers, and consumers</Description><Identifier>_ced01baa-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>2.5</SequenceIndicator><Stakeholder StakeholderTypeType="Generic_Group"><Name>Creators</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Publishers</Name><Description/></Stakeholder><Stakeholder StakeholderTypeType="Generic_Group"><Name>Consumers</Name><Description/></Stakeholder><OtherInformation/></Objective><Objective><Name>Accessibility</Name><Description>Ensure that content accessibility is not negatively impacted by digital provenance techniques</Description><Identifier>_ced01c9a-0b65-11ec-b840-3bab2c83ea00</Identifier><SequenceIndicator>2.6</SequenceIndicator><Stakeholder><Name/><Description/></Stakeholder><OtherInformation/></Objective></Goal></StrategicPlanCore><AdministrativeInformation><StartDate/><EndDate/><PublicationDate>2021-09-01</PublicationDate><Source>https://c2pa.org/</Source><Submitter><GivenName>Owen</GivenName><Surname>Ambur</Surname><PhoneNumber/><EmailAddress>Owen.Ambur@verizon.net</EmailAddress></Submitter></AdministrativeInformation></PerformancePlanOrReport>