The organization must establish written agreements with all parties involved in electronic interaction, including senders, recipients, and any message intermediaries. These agreements must clearly define the roles and responsibilities of each party regarding the security of electronic data exchange.
All agreements must be in writing and must explicitly state the responsibilities of each party, including any message intermediary. Clear responsibility boundaries must be established between the sender, receiver, and intermediary organizations.
The sender/offering organization is responsible for:
- Its own connection security that prevents unintended access and intrusion
- Ensuring that the service cannot transmit programs containing malicious software or similar threats
- Secure end-to-end transmission encryption
The receiver/using organization is responsible for:
- Ensuring that the service cannot transmit malicious code or similar threats
- Its own connection security that prevents unintended access and intrusion
- Maintaining end-to-end transmission encryption