Search book title
Filters:
FORMAT
BOOKS
PACKAGES
EDITION
to
PUBLISHER
(1)
(338)
(589)
(599)
(55)
(234)
(1006)
(690)
(2183)
(117)
(95207)
(63)
(575)
(124)
(33)
(21)
(20)
(95391)
(3)
(17)
(1)
(374)
(322)
(6938)
(241)
(21)
(6)
(1667)
(17)
(19)
(28)
(4)
 
(6)
(7)
(115)
(3)
(57)
(5)
(5)
(1)
(1)
(2)
(25)
(27)
(27)
(13)
(61)
(24)
(22)
(7)
(8)
(20)
(1)
(3)
(50)
(6)
(33)
CONTENT TYPE
 Act
 Admin Code
 Announcements
 Bill
 Book
 CADD File
 CAN
 CEU
 Charter
 Checklist
 City Code
 Code
 Commentary
 Comprehensive Plan
 Conference Paper
 County Code
 Course
 DHS Documents
 Document
 Errata
 Executive Regulation
 Federal Guideline
 Firm Content
 Guideline
 Handbook
 Interpretation
 Journal
 Land Use and Development
 Law
 Legislative Rule
 Local Amendment
 Local Code
 Local Document
 Local Regulation
 Local Standards
 Manual
 Model Code
 Model Standard
 Notice
 Ordinance
 Other
 Paperback
 PASS
 Periodicals
 PIN
 Plan
 Policy
 Product
 Product - Data Sheet
 Program
 Provisions
 Requirements
 Revisions
 Rules & Regulations
 Standards
 State Amendment
 State Code
 State Manual
 State Plan
 State Standards
 Statute
 Study Guide
 Supplement
 Sustainability
 Technical Bulletin
 All
  • BSI
    21/30389093 DC BS ISO/IEC 27099. Information Technology. Public key infrastructure. Practices and policy framework
    Edition: 2021
    $80.37
    / user per year

Description of 21/30389093 DC 2021

This document sets out a framework of requirements to manage information security for PKI trust service providers through Certificate Policies, Certificate Practice Statements, and, where applicable, their internal underpinning by an ISMS. The framework of requirements includes the assessment and treatment of information security risks, tailored to meet the agreed service requirements of its users as specified through the certificate policy. This document is also intended to help trust service providers to support multiple Certificate Policies.

This document addresses the life-cycle of public key certificates that are used for digital signatures, authentication, or key establishment for data encryption. It does not address authentication methods, non-repudiation requirements, or key management protocols based on the use of public key certificates. For the purposes of this document, the term “certificate” refers to public key certificates. Attribute certificates are outside the scope of this document.

This document uses concepts and requirements of an ISMS as defined in the ISO/IEC 27000 family. It uses the code of practice for information security controls as defined in ISO/IEC 27002:2013. Specific PKI requirements (e.g. certificate content, identity proofing, certificate revocation handling) are not addressed directly by a ISMS such as defined by ISO/IEC 27001.

The use of an ISMS or equivalent is adapted to the application of PKI service requirements specified in the Certificate Policy as described in the present document.

A PKI trust service provider is a special class of trust service for the use of public key certificates. A PKI trust service provider consists of one or more Certification Authorities providing a trust service with coherent policies and practices.

This document draws a distinction between PKI systems used in closed, open and contractual environments. This document facilitates the implementation of operational, baseline controls and practices in a contractual environment. While the focus of this document is on the contractual environment, application of this document to open or closed environments is not specifically precluded.

The document is organised as follows: Clause 5 provides guidance on the concepts used in this document. Clause 6 specifies requirements on the management of policies and practices applied by CAs. Clause 7 specifies requirements on the operation of CA. The annexes are all informative.



About BSI

BSI Group, also known as the British Standards Institution is the national standards body of the United Kingdom. BSI produces technical standards on a wide range of products and services and also supplies certification and standards-related services to businesses.

X