Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...


InCommon BaselineeduGAIN BaselineOther BaselineActions or Controls
SecuritySP01. Controls are in place to reasonably secure information and maintain user privacyCoCo? Sirtfi?

SecuritySP02. Information received from IdPs is not shared with third parties without permission and is stored only when necessary for SP’s purpose
GDPR
SecuritySP03. Generally-accepted security practices are applied to the SPSirtfi?

ComplianceSP04. Federation metadata is accurate, complete, and includes site technical, admin, and security contacts, MDUI information, and privacy policy URL

Required by eduGAIN:
 - technical contact (eduGAIN SAML Profile).
SHOULD:
 - mdui. 

RECOMMENDED:
 - privacy policy in CoCo.
 - security contacts in Sirtfi

Federation-specific requirements (as documented by the federation)
ComplianceSP05. Unless governed by an applicable contract, attributes required to obtain service are appropriate and made known publiclyonly via CoCo and R&SAAF (and others): Publish attribute requirements in metadata as RequestedAttribute elements of the AttributeConsumingService.

...