5 已翻譯 對應原文版本:2.3.0

管理、作業及實體控管

跳至原文

MANAGEMENT, OPERATIONAL, AND PHYSICAL CONTROLS

The CA/Browser Forum’s Network and Certificate System Security Requirements are incorporated by reference as if fully set forth herein.

CA/Browser Forum《網路與憑證系統安全要求》(Network and Certificate System Security Requirements)以引用方式納入本文件,其內容視同已全文載明於本文件。

The CA SHALL develop, implement, and maintain a comprehensive security program designed to:

憑證機構(Certification Authority,CA)應(SHALL)建立、實施並維護一套全面性的安全計畫,以:

  1. Protect the confidentiality, integrity, and availability of Certificate Data and Certificate Management Processes;
  1. 保護憑證資料(Certificate Data)與憑證管理流程(Certificate Management Processes)之機密性、完整性及可用性;
  1. Protect against anticipated threats or hazards to the confidentiality, integrity, and availability of the Certificate Data and Certificate Management Processes;
  1. 防範對憑證資料與憑證管理流程之機密性、完整性及可用性構成預期威脅或危害的情形;
  1. Protect against unauthorized or unlawful access, use, disclosure, alteration, or destruction of any Certificate Data or Certificate Management Processes;
  1. 防範任何憑證資料或憑證管理流程遭未經授權或非法之存取、使用、揭露、變更或破壞;
  1. Protect against accidental loss or destruction of, or damage to, any Certificate Data or Certificate Management Processes; and
  1. 防範任何憑證資料或憑證管理流程遭意外遺失、毀損或損害;以及
  1. Comply with all other security requirements applicable to the CA by law.
  1. 遵循法律對 CA 所適用之其他所有安全要求。

The Certificate Management Process MUST include:

憑證管理流程應(MUST)包括:

  1. physical security and environmental controls;
  1. 實體安全與環境控制;
  1. system integrity controls, including configuration management, integrity maintenance of trusted code, and malware detection/prevention;
  1. 系統完整性控管,包括組態管理、受信任程式碼之完整性維護,以及惡意軟體之偵測與防範;
  1. network security and firewall management, including port restrictions and IP address filtering;
  1. 網路安全與防火牆管理,包括連接埠限制及 IP 位址過濾;
  1. user management, separate trusted-role assignments, education, awareness, and training; and
  1. 使用者管理、信賴角色(Trusted Role)之職責分離、教育、認知及訓練;以及
  1. logical access controls, activity logging, and inactivity time-outs to provide individual accountability.
  1. 邏輯存取控制、活動記錄及閒置逾時機制,以確保個別責任歸屬。

The CA’s security program MUST include an annual Risk Assessment that:

CA 的安全計畫應(MUST)包括每年執行之風險評估(Risk Assessment),該風險評估應:

  1. Identifies foreseeable internal and external threats that could result in unauthorized access, disclosure, misuse, alteration, or destruction of any Certificate Data or Certificate Management Processes;
  1. 識別可預見的內部及外部威脅,該等威脅可能導致任何憑證資料或憑證管理流程遭未經授權之存取、揭露、誤用、變更或破壞;
  1. Assesses the likelihood and potential damage of these threats, taking into consideration the sensitivity of the Certificate Data and Certificate Management Processes; and
  1. 考量憑證資料與憑證管理流程之敏感性,評估該等威脅發生之可能性及其潛在損害;以及
  1. Assesses the sufficiency of the policies, procedures, information systems, technology, and other arrangements that the CA has in place to counter such threats.
  1. 評估 CA 為了因應該等威脅所建立之政策、程序、資訊系統、技術及其他措施是否足以因應該等威脅。

Based on the Risk Assessment, the CA SHALL develop, implement, and maintain a security plan consisting of security procedures, measures, and products designed to achieve the objectives set forth above and to manage and control the risks identified during the Risk Assessment, commensurate with the sensitivity of the Certificate Data and Certificate Management Processes. The security plan MUST include administrative, organizational, technical, and physical safeguards appropriate to the sensitivity of the Certificate Data and Certificate Management Processes. The security plan MUST also take into account then-available technology and the cost of implementing the specific measures, and SHALL implement a reasonable level of security appropriate to the harm that might result from a breach of security and the nature of the data to be protected.

基於風險評估結果,CA 應(SHALL)建立、實施並維護一套安全計畫,該安全計畫應由安全程序、措施及產品組成,其目的在於達成前述目標,並依據憑證資料及憑證管理流程之敏感性,管理及控管風險評估中所識別之風險。該安全計畫應(MUST)包括與憑證資料及憑證管理流程之敏感性相應的行政、組織、技術及實體保護措施。該安全計畫亦應(MUST)考量當時可取得之技術,以及實施具體措施所需之成本,並應(SHALL)採行與安全事件所造成的潛在損害與受保護資料性質相應之合理安全水準。