5.4.3 已翻譯 對應原文版本:2.3.0
稽核紀錄之保留期限
Retention period for audit log
The CA and each Delegated Third Party SHALL retain, for at least two (2) years:
憑證機構(Certification Authority,CA)及每個受委任第三方(Delegated Third Party)應(SHALL)將下列資料至少保留 2 年:
- CA certificate and key lifecycle management event records (as set forth in Section 5.4.1 (1)) after the later occurrence of:
- the destruction of the CA Private Key; or
- the revocation or expiration of the final CA Certificate in that set of Certificates that have an X.509v3
basicConstraintsextension with thecAfield set to TRUE and which share a common Public Key corresponding to the CA Private Key;
- CA 憑證及金鑰生命週期管理事件紀錄(如第 5.4.1 節第(1)項所規定),自下列事項中較晚發生者為起算點:
- CA 私密金鑰遭銷毀;或
- 具有 X.509v3
basicConstraints擴充欄位(其cA欄位設為 TRUE),且共用該 CA 私密金鑰所對應之同一把公開金鑰的憑證集合中,最後一張 CA 憑證遭廢止或到期;
- Subscriber Certificate lifecycle management event records (as set forth in Section 5.4.1 (2)) after the expiration of the Subscriber Certificate;
- 用戶憑證生命週期管理事件紀錄(如第 5.4.1 節第(2)項所規定),以用戶憑證到期為起算點;
- Any security event records (as set forth in Section 5.4.1 (3)) after the event occurred.
- 安全事件紀錄(如第 5.4.1 節第(3)項所規定),以事件發生為起算點。
Note: While these Requirements set the minimum retention period, the CA MAY choose a greater value as more appropriate in order to be able to investigate possible security or other types of incidents that will require retrospection and examination of past audit log events.
注意:本文件僅規定最低保留期限,CA 得(MAY)視需求選擇較長之保留期限,以利日後調查可能發生、需回溯檢視過往稽核紀錄之安全事故或其他類型事故。