usnistgov / NISTIR-8149

Home to public draft NISTIR-8149: Developing Trust Frameworks to Support Identity Federations
https://pages.nist.gov/NISTIR-8149
6 stars 5 forks source link

Liability of the 3rd party assessor #16

Open lva opened 8 years ago

lva commented 8 years ago

Organization: VASCO Data Security

Type: 2 - Industry

Reference: section "6.2. Risk and Liability Allocation" and section "7.2. 3rd-Party Assessment"

Comment: the text can be expanded with rules about the possible liability of a 3rd party assessor. For example, if an incident happens at a member that was assessed by means of a 3rd party assessment, is it possible to put liability to the 3rd party assessor?