8.2 已翻譯 對應原文版本:2.3.0
稽核者之身分與資格
Identity/qualifications of assessor
The CA’s audit SHALL be performed by a Qualified Auditor. A Qualified Auditor means a natural person, Legal Entity, or group of natural persons or Legal Entities that collectively possess the following qualifications and skills:
- Independence from the subject of the audit;
- The ability to conduct an audit that addresses the criteria specified in an eligible audit scheme (see Section 8.4);
- Employs individuals who have proficiency in examining Public Key Infrastructure technology, information security tools and techniques, information technology and security auditing, and the third-party attestation function;
- (For audits conducted in accordance with any one of the ETSI standards) accredited in accordance with ISO 17065 applying the requirements specified in ETSI EN 319 403;
- (For audits conducted in accordance with the WebTrust standard) licensed by WebTrust;
- Bound by law, government regulation, or professional code of ethics; and
- Except in the case of an Internal Government Auditing Agency, maintains Professional Liability/Errors & Omissions insurance with policy limits of at least one million US dollars in coverage.
憑證機構(Certification Authority,CA)之稽核應(SHALL)由合格稽核業者(Qualified Auditor)執行。合格稽核業者係指自然人(natural person)、法人(Legal Entity),或者由自然人或法人所組成之團體,且其全體具備下列資格與能力:
- 與稽核對象保持獨立關係;
- 具備執行稽核之能力,且該稽核涵蓋合格稽核架構所定之準則(參見第 8.4 節);
- 雇用具備公開金鑰基礎建設(Public Key Infrastructure,PKI)技術、資訊安全工具及其技術、資訊技術與安全稽核,以及第三方驗證職能等專業能力之人員;
- (依任一 ETSI 標準進行稽核時)依 ISO 17065 取得認可,並適用 ETSI EN 319 403 所定之要求;
- (依 WebTrust 標準進行稽核時)取得 WebTrust 授權;
- 受法律、政府法規或專業倫理守則之約束;及
- 除政府內部稽核機關(Internal Government Auditing Agency)外,稽核業者應維持專業責任保險(Professional Liability/Errors & Omissions insurance)之投保,其保險金額上限至少為一百萬美元。