Name:
DANSK DSF/ISO/IEC DIS 27099 PDF
Published Date:
Status:
[ Draft ]
Publisher:
Dansk Standard
This document sets out a framework of requirements to manage information security for PKI trust service providers through Certificate Policies, Certificate Practice Statements, and, where applicable, their internal underpinning by an ISMS. The framework of requirements includes the assessment and treatment of information security risks, tailored to meet the agreed service requirements of its users as specified through the certificate policy. This document is also intended to help trust service providers to support multiple Certificate Policies. This document addresses the life-cycle of public key certificates that are used for digital signatures, authentication, or key establishment for data encryption. It does not address authentication methods, non-repudiation requirements, or key management protocols based on the use of public key certificates. For the purposes of this document, the term “certificate” refers to public key certificates. Attribute certificates are outside the scope of this document. This document uses concepts and requirements of an ISMS as defined in the ISO/IEC 27000 family. It uses the code of practice for information security controls as defined in ISO/IEC 27002:2013. Specific PKI requirements (e.g. certificate content, identity proofing, certificate revocation handling) are not addressed directly by a ISMS such as defined by ISO/IEC 27001. The use of an ISMS or equivalent is adapted to the application of PKI service requirements specified in the Certificate Policy as described in the present document. A PKI trust service provider is a special class of trust service for the use of public key certificates. A PKI trust service provider consists of one or more Certification Authorities providing a trust service with coherent policies and practices.
| Edition : | 21 |
| File Size : | 1 file , 5.7 MB |
| Number of Pages : | 100 |
| Product Code(s) : | DSF-061, DSF-061 |