As an enterprise focused profile, should IPSIE take on the privacy requirements of SP800-63Crev4 section 3.9 as seen in #71? Privacy requirements differ around the world and are likely subject to business agreements that are outside of the scope of an IPSIE profile.
chair hat off
I recommend that IPSIE does not require implementers to follow these controls. IPSIE should recommend that implementers devise and document their privacy controls.
chair hat on
As an enterprise focused profile, should IPSIE take on the privacy requirements of SP800-63Crev4 section 3.9 as seen in #71? Privacy requirements differ around the world and are likely subject to business agreements that are outside of the scope of an IPSIE profile.
chair hat off
I recommend that IPSIE does not require implementers to follow these controls. IPSIE should recommend that implementers devise and document their privacy controls.
chair hat on