+SOV-3-03 External Identity Provider
---+SOV-3-03-C
---+SOV-3-03-AC1
---+SOV-3-03-AC2
---+SOV-3-03-AC3

1. Overview

SOV-3-03 External Identity Provider

SOV-3-03 External Identity Provider
Summary Standard
SOV-3-03-C

The cloud service provider MUST support standards-based integration of external identity providers for authentication and access management for the cloud service.

SOV-3-03-AC1

The integration of an external Identity Provider MUST be implemented via open, non-proprietary standards.

SOV-3-03-AC2

The provider MUST support a stateless authentication model that does not mandate the creation and copies of accounts within the provider’s directory.

SOV-3-03-AC3

Authorization MUST be controllable via dynamic claims and attributes issued directly by the customer's external identity provider.

1.1 References

1.2 Identified Requirements

1.2 Related Regulation

2. Identified Requirements

Requirements
Source Requirement

3. Related Regulations

Regulations
Source Regulation
Impressum