8.4 已翻譯 對應原文版本:2.3.0

稽核涵蓋事項

跳至原文

Topics covered by assessment

The CA SHALL undergo an audit in accordance with one of the following schemes:

  1. WebTrust:
    • “Principles and Criteria for Certification Authorities” Version 2.2 or newer; and either
      • “WebTrust Principles and Criteria for Certification Authorities – SSL Baseline with Network Security” Version 2.7 or newer; or
      • “WebTrust Principles and Criteria for Certification Authorities – SSL Baseline” Version 2.8 or newer and “WebTrust Principles and Criteria for Certification Authorities – Network Security” Version 1.0 or newer
  2. ETSI:
    • ETSI EN 319 411-1 v1.4.1 or newer, which includes normative references to ETSI EN 319 401 (the latest version of the referenced ETSI documents should be applied); or
  3. Other:
    • If a Government CA is required by its Certificate Policy to use a different internal audit scheme, it MAY use such scheme provided that the audit either
      1. encompasses all requirements of one of the above schemes; or
      2. consists of comparable criteria that are available for public review.

憑證機構(Certification Authority,CA)應(SHALL)依下列稽核架構之一接受稽核:

  1. WebTrust:
    • 「憑證機構原則與準則(Principles and Criteria for Certification Authorities)」第 2.2 版或更新版本;以及下列之一:
      • 「WebTrust 憑證機構原則與準則——SSL 基本要求及網路安全(WebTrust Principles and Criteria for Certification Authorities – SSL Baseline with Network Security)」第 2.7 版或更新版本;或
      • 「WebTrust 憑證機構原則與準則——SSL 基本要求(WebTrust Principles and Criteria for Certification Authorities – SSL Baseline)」第 2.8 版或更新版本,以及「WebTrust 憑證機構原則與準則——網路安全(WebTrust Principles and Criteria for Certification Authorities – Network Security)」第 1.0 版或更新版本。
  2. ETSI:
    • ETSI EN 319 411-1 v1.4.1 或更新版本,其中包含對 ETSI EN 319 401 之規範性引用(所引用之 ETSI 文件應採用最新版本);或
  3. 其他:
    • 若政府憑證機構(Government CA)依其憑證政策(CP)之規定須採用不同的內部稽核架構,則得(MAY)採用該內部稽核架構,但其稽核應符合下列任一條件:
      1. 包含上述任一稽核架構之所有要求;或
      2. 由可供公開審查之類似準則所組成。

Whichever scheme is chosen, it MUST incorporate periodic monitoring and/or accountability procedures to ensure that its audits continue to be conducted in accordance with the requirements of the scheme.

無論選擇何種稽核架構,該稽核架構應(MUST)納入定期監督及/或課責程序,以確保依該稽核架構所進行之稽核,持續遵循該稽核架構之要求。

The audit MUST be conducted by a Qualified Auditor, as specified in Section 8.2.

稽核應(MUST)由第 8.2 節所定之合格稽核業者(Qualified Auditor)執行。

For Delegated Third Parties which are not Enterprise RAs, then the CA SHALL obtain an audit report, issued under the auditing standards that underlie the accepted audit schemes found in Section 8.4, that provides an opinion whether the Delegated Third Party’s performance complies with either the Delegated Third Party’s practice statement or the CA’s Certificate Policy and/or Certification Practice Statement. If the opinion is that the Delegated Third Party does not comply, then the CA SHALL not allow the Delegated Third Party to continue performing delegated functions.

對於非企業註冊中心(Enterprise RA)之受委任第三方(Delegated Third Party),CA 應(SHALL)取得依第 8.4 節所列之認可稽核架構依據的稽核標準所出具的稽核報告;該報告應就受委任第三方之作業執行情形是否遵循其作業基準(practice statement),或是否遵循 CA 的憑證政策(CP)及/或憑證實務作業基準(CPS)表示意見。若稽核意見認定受委任第三方不遵循前述文件之規定,CA 應(SHALL)禁止該受委任第三方繼續執行受委託作業(delegated functions)。

The audit period for the Delegated Third Party SHALL NOT exceed one year (ideally aligned with the CA’s audit).

受委任第三方之稽核期間不得(SHALL NOT)超過一年(理想情況下宜與 CA 之稽核期間一致)。