FAL2 compliance requires trust agreements as documented in #71. Opening this issue to move the discussion forward on how IPSIE should approach trust agreements.
chair hat off
For enterprise use cases, I do not believe trust agreements should be a part of IPSIE. These are business agreements between organizations and not definable security controls that the IPSIE WG should tackle.
chair hat on
FAL2 compliance requires trust agreements as documented in #71. Opening this issue to move the discussion forward on how IPSIE should approach trust agreements.
chair hat off
For enterprise use cases, I do not believe trust agreements should be a part of IPSIE. These are business agreements between organizations and not definable security controls that the IPSIE WG should tackle.
chair hat on