5.4.8 已翻譯 對應原文版本:2.3.0
弱點評估
Vulnerability assessments
Additionally, the CA’s security program MUST include an annual Risk Assessment that:
此外,憑證機構(Certification Authority,CA)的安全計畫應(MUST)包括每年執行之風險評估,該風險評估應:
- Identifies foreseeable internal and external threats that could result in unauthorized access, disclosure, misuse, alteration, or destruction of any Certificate Data or Certificate Management Processes;
- 識別可預見之內部與外部威脅,該等威脅可能導致任何憑證資料(Certificate Data)及憑證管理流程(Certificate Management Processes)發生未經授權之存取、揭露、誤用、變更或破壞;
- Assesses the likelihood and potential damage of these threats, taking into consideration the sensitivity of the Certificate Data and Certificate Management Processes; and
- 考量憑證資料及憑證管理流程的敏感性,評估該等威脅之發生可能性與潛在損害;以及
- Assesses the sufficiency of the policies, procedures, information systems, technology, and other arrangements that the CA has in place to counter such threats.
- 評估 CA 為了因應該等威脅所建立之政策、程序、資訊系統、技術及其他安排措施是否足夠。