<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Interop_Req_6</id>
	<title>Interop Req 6 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Interop_Req_6"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Interop_Req_6&amp;action=history"/>
	<updated>2026-05-06T10:00:03Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=Interop_Req_6&amp;diff=4072&amp;oldid=prev</id>
		<title>Omaerz: 16 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Interop_Req_6&amp;diff=4072&amp;oldid=prev"/>
		<updated>2018-06-28T04:01:54Z</updated>

		<summary type="html">&lt;p&gt;16 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;lt;&amp;lt; Back to [[Baseline_Functional_Requirements_v1.0|Baseline Functional Requirements Index]]&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== INTEROP-6.    THIRD-PARTY COMPLIANCE ==&lt;br /&gt;
Entities that act as [[IDEF Glossary THIRD PARTIES|THIRD-PARTY]] service providers for another entity, in conducting [[IDEF Glossary DIGITAL IDENTITY MANAGEMENT FUNCTIONS|digital identity management functions]], must comply with each of the applicable [[Baseline Functional Requirements v1.0|IDESG Baseline Requirements]] that apply to that other entity and those relevant functions.&lt;br /&gt;
&lt;br /&gt;
=== SUPPLEMENTAL GUIDANCE ===&lt;br /&gt;
This Requirement applies to outsourcing or delegation of [[IDEF Glossary DIGITAL IDENTITY MANAGEMENT FUNCTIONS|digital identity management functions]] or transactions to [[IDEF Glossary THIRD PARTIES|THIRD-PARTIES]]. An entity assessing its compliance with the applicable IDESG Baseline Requirements must also apply them to the functions or transactions carried out on its behalf by a service provider. For purposes of this Requirement, the term &amp;quot;THIRD-PARTY service provider&amp;quot; refers to THIRD-PARTIES that an assessed entity outsources or delegates to perform digital identity management functions on behalf of the assessed entity.&lt;br /&gt;
&lt;br /&gt;
In some [[IDEF Glossary FEDERATIONS|FEDERATIONS]], the federation itself may also act as an intermediary or service provider for participant entities in some identity management functions, and thereby be subject to this requirement.&lt;br /&gt;
&lt;br /&gt;
Cloud computing service providers providing data storage or other services for an entity may also be within the scope of this Requirement, depending on the functions performed on behalf of the assessed entity, and the provider&amp;#039;s access to the data handled on behalf of the assessed entity. See comments about &amp;quot;data storage companies&amp;quot; in the Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules Under the HITECH Act (2013), Final Rule comments on HITECH Act Section 13408:  http://federalregister.gov/a/2013-01073.&lt;br /&gt;
&lt;br /&gt;
Regarding &amp;quot;digital identity management functions&amp;quot;, see [[APPENDIX_A-Defined_Terms|Appendix A]].&lt;br /&gt;
&lt;br /&gt;
=== REFERENCES ===&lt;br /&gt;
Reference for cloud computing processors of personal information:  ISO/IEC 27018 (2014): Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors. http://www.iso.org/iso/catalogue_detail.htm?csnumber=61498, and https://www.iso.org/obp/ui/#iso:std:iso-iec:27018:ed-1:v1:en&lt;br /&gt;
&lt;br /&gt;
Reference example of intermediaries and similar subcontractors or service agencies who fulfill data transactions for others, and take responsibility for their compliance with various requirements: see &amp;quot;Business Associate&amp;quot; regulations in the HIPAA Privacy Regulations:  45 CFR Parts 160 and 164, §§ 160.103, 164.502(a)(3), (a)(4) and (e);  and the treatment of &amp;quot;Clearinghouse&amp;quot; functions in § 164.500(b) :  http://www.ecfr.gov/cgi-bin/text-idx?node=pt45.1.164&amp;amp;rgn=div5&lt;br /&gt;
&lt;br /&gt;
=== APPLIES TO ACTIVITIES ===&lt;br /&gt;
[[IDEF Functional Model REGISTRATION|REGISTRATION]], &lt;br /&gt;
[[IDEF Functional Model CREDENTIALING|CREDENTIALING]], &lt;br /&gt;
[[IDEF Functional Model AUTHENTICATION|AUTHENTICATION]], &lt;br /&gt;
[[IDEF Functional Model AUTHORIZATION|AUTHORIZATION]], &lt;br /&gt;
[[IDEF Functional Model INTERMEDIATION|INTERMEDIATION]]&lt;br /&gt;
&lt;br /&gt;
=== KEYWORDS ===&lt;br /&gt;
[[IDEF Keywords COMPLIANCE|COMPLIANCE]], [[IDEF Keywords INTEROPERABILITY|INTEROPERABILITY]], [[IDEF Keywords INTERMEDIARIES|INTERMEDIARIES]], &lt;br /&gt;
[[IDEF Keywords TRANSACTION|TRANSACTION]], [[IDEF Keywords THIRD PARTIES|THIRD-PARTIES]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
----&lt;br /&gt;
Quick Links:   [[SALS]]  |  [[Baseline Functional Requirements v1.0]]  |  [[Glossary]]  |&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
</feed>