5.5.2 已翻譯 對應原文版本:2.3.0

歸檔紀錄之保留期限

跳至原文

Retention period for archive

Archived audit logs (as set forth in Section 5.5.1) SHALL be retained for a period of at least two (2) years from their record creation timestamp, or as long as they are required to be retained per Section 5.4.3, whichever is longer.

歸檔之稽核紀錄(如第 5.5.1 節所規定)應(SHALL)自其紀錄建立時間戳記起保留至少 2 年,或按照第 5.4.3 節對此類紀錄所規定之保留期限,以較長者為準。

Additionally, the CA and each Delegated Third Party SHALL retain, for at least two (2) years:

此外,憑證機構(Certification Authority,CA)及每個受委任第三方(Delegated Third Party)應(SHALL)將下列資料至少保留 2 年:

  1. All archived documentation related to the security of Certificate Systems, Certificate Management Systems, Root CA Systems and Delegated Third Party Systems (as set forth in Section 5.5.1); and
  1. 所有已歸檔之與憑證系統(Certificate Systems)、憑證管理系統(Certificate Management Systems)、根憑證機構系統(Root CA Systems)及受委任第三方系統(Delegated Third Party Systems)之安全有關的文件(如第 5.5.1 節所規定);以及
  1. All archived documentation relating to the verification, issuance, and revocation of certificate requests and Certificates (as set forth in Section 5.5.1) after the later occurrence of:
    1. such records and documentation were last relied upon in the verification, issuance, or revocation of certificate requests and Certificates; or
    2. the expiration of the Subscriber Certificates relying upon such records and documentation.
  1. 所有與憑證申請及憑證所進行之驗證、簽發及廢止有關之已歸檔文件(如第 5.5.1 節所規定),自下列事項中較晚發生者起至少保留 2 年:
    1. 此類紀錄及文件最後一次作為憑證申請及憑證之驗證、簽發或廢止之依據;或
    2. 依據此類紀錄及文件簽發之用戶憑證到期。

Note: While these Requirements set the minimum retention period, the CA MAY choose a greater value as more appropriate in order to be able to investigate possible security or other types of incidents that will require retrospection and examination of past records archived.

注意:本文件僅規定最低保留期限,CA 得(MAY)視需求選擇較長之保留期限,以利日後調查可能發生、需回溯檢視過往已歸檔紀錄之安全事故或其他類型事故。