BS ISO/IEC 27099:2022

Information technology. Public key infrastructure. Practices and policy framework


标准号
BS ISO/IEC 27099:2022
发布
2022年
发布单位
英国标准学会
当前最新
BS ISO/IEC 27099:2022
 
 
适用范围
1   Scope This document sets out a framework of requirements to manage information security for Public key infrastructure ( PKI ) trust service providers through certificate policies, certificate practice statements, and, where applicable, their internal underpinning by an information security management system (ISMS). The framework of requirements includes the assessment and treatment of information security risks, tailored to meet the agreed service requirements of its users as specified through the certificate policy. This document is also intended to help trust service providers to support multiple certificate policies. This document addresses the life cycle of public key certificates that are used for digital signatures , authentication , or key establishment for data encryption. It does not address authentication methods, non-repudiation requirements, or key management protocols based on the use of public key certificates . For the purposes of this document, the term “ certificate ” refers to public key certificates . This document is not applicable to attribute certificates . This document uses concepts and requirements of an ISMS as defined in the ISO/IEC 27000 family of standards. It uses the code of practice for information security controls as defined in ISO/IEC 27002. Specific PKI requirements (e.g.

BS ISO/IEC 27099:2022相似标准


推荐





Copyright ©2007-2022 ANTPEDIA, All Rights Reserved
京ICP备07018254号 京公网安备1101085018 电信与信息服务业务经营许可证:京ICP证110310号