Proposed changes to eduGAIN SAML Profile - #6
Conversation
|
Hi, thanks for this. I do agree with the proposed change, though I think the requirement for a Privacy Notice needs a change as currently it is marked as a SHOULD, while in order to be really useful we need a MUST for it, as we are currently doing for the other two requirements. |
The concrete use people (can) make of that element is quite different, depending on whether it's for SPs or IDPs, no? For SPs, the referenced document needs to be publicly available (i.e., without prior authentication or IP-based restrictions) so that IDPs can render the For IDPs, we have not made available any templates or other suggestions regarding the content — I'm guessing most IDP orgs will already have some data protection policy document published somewhere on their website, but that may only cover the processing done for their web site(s), of course. |
updated to include MUST for privacy notice
|
Currently updated to be a MUST for SPs and a SHOULD for IdPs - happy for more feedback on this one |
Do you have a reference handy for the reasoning to mandate |
The only relevant thing I can think of is that it would be an additional verification of the statement in the RAF to support the statement "You apply security practices to protect user information, safeguard transaction integrity, and ensure timely incident response" but there's no definitive link or requirement between the two. Otherwise I would consider it a "nice to have" and general good practice. |
|
I see, that statement comes from RAF 2.0, 3. Conformance Criteria, item 4, which in turn is a direct quote of So unless we'll find other (or additional, on top of your |
In this proposed change the following issues have been added: