<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Secure_Req_1</id>
	<title>Secure Req 1 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Secure_Req_1"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Secure_Req_1&amp;action=history"/>
	<updated>2026-05-01T09:53:25Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=Secure_Req_1&amp;diff=6545&amp;oldid=prev</id>
		<title>Omaerz: 9 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Secure_Req_1&amp;diff=6545&amp;oldid=prev"/>
		<updated>2018-06-28T04:03:32Z</updated>

		<summary type="html">&lt;p&gt;9 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;lt;&amp;lt; Back to [[Baseline_Functional_Requirements_v1.0|Baseline Functional Requirements Index]]&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
== SECURE-1.    SECURITY PRACTICES ==&lt;br /&gt;
Entities MUST apply appropriate and industry-accepted information security [[IDEF Glossary STANDARDS|STANDARDS]], guidelines, and practices to the systems that support their identity functions and services.&lt;br /&gt;
&lt;br /&gt;
=== SUPPLEMENTAL GUIDANCE ===&lt;br /&gt;
Entities may satisfy this Requirement by confirming that they (a) have considered existing&lt;br /&gt;
information security standards, guidelines and practices relevant to their environment; (b) have&lt;br /&gt;
identified the specific sources of guidance that are appropriate for their operations, in light of the&lt;br /&gt;
information security risks they face; and (c) have implemented the portions of that guidance they&lt;br /&gt;
deemed appropriate.&lt;br /&gt;
&lt;br /&gt;
This Requirement does not mandate which information security policies, procedures or technologies&lt;br /&gt;
an entity should or must use. However, some specific policies and technologies are the subject of&lt;br /&gt;
other, more specific items elsewhere in this Requirements set.&lt;br /&gt;
&lt;br /&gt;
Entities must have risk-based countermeasures and safeguards in place to resist common threats to&lt;br /&gt;
identity solutions and identity data, including, for example, Session hijacking; Eavesdropping; Theft;&lt;br /&gt;
Man-in-the-middle; Online Guessing; Replay; Unauthorized copying or duplication; and Insider&lt;br /&gt;
Threats.&lt;br /&gt;
&lt;br /&gt;
The security standards, guidelines, and practices employed in digital identity management services,&lt;br /&gt;
to govern the security of their networks, devices, solutions, and systems, must be both operational and&lt;br /&gt;
well documented. Please note the applicability of Requirement [[Interop Req 5|INTEROP-5 (DOCUMENTED PROCESSES)]]&lt;br /&gt;
regarding documentation and best practice [[Interop Best Practice G|INTEROP-BP-G (RECOMMENDED LEGAL COMPLIANCE)]]&lt;br /&gt;
regarding limitations imposed by laws. Please note the applicability of best practice [[Interop Best Practice F|INTEROP-BP-F&lt;br /&gt;
(RECOMMENDED FEDERATION COMPLIANCE)]] and Requirement [[Interop Req 6|INTEROP-6 (THIRD-PARTY&lt;br /&gt;
COMPLIANCE)]] regarding limitations arising from the involvement of [[IDEF Glossary THIRD PARTIES|THIRD-PARTIES]] such as&lt;br /&gt;
intermediaries, similar service providers, or [[IDEF Glossary FEDERATIONS|FEDERATIONS]].&lt;br /&gt;
&lt;br /&gt;
=== REFERENCES ===&lt;br /&gt;
Potential candidates for adoption include: ISO/IEC 27000 series, PCI-DSS, NIST SP 800-53-4, CSA&lt;br /&gt;
CCM, COBIT v5, FFIEC (multiple documents), PCI-DSS, NISTIR 7621 R1 (draft) &lt;br /&gt;
&lt;br /&gt;
=== APPLIES TO ACTIVITIES ===&lt;br /&gt;
[[IDEF Functional Model REGISTRATION|REGISTRATION]], &lt;br /&gt;
[[IDEF Functional Model CREDENTIALING|CREDENTIALING]], &lt;br /&gt;
[[IDEF Functional Model AUTHENTICATION|AUTHENTICATION]], &lt;br /&gt;
[[IDEF Functional Model AUTHORIZATION|AUTHORIZATION]], &lt;br /&gt;
[[IDEF Functional Model INTERMEDIATION|INTERMEDIATION]]&lt;br /&gt;
&lt;br /&gt;
=== KEYWORDS ===&lt;br /&gt;
[[IDEF Keywords POLICIES|POLICIES]], [[IDEF Keywords RISK|RISK]], [[IDEF Keywords SECURITY|SECURITY]], [[IDEF Keywords OPEN-STANDARDS|OPEN-STANDARDS]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
----&lt;br /&gt;
Quick Links:   [[SALS]]  |  [[Baseline Functional Requirements v1.0]]  |  [[Glossary]]  |&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
</feed>