CONTENTS

  • 1.1 Scope and purpose
  • 2 Key organisations
    • 2.1 DIP Manager
    • 2.2 DIP Verification Service Provider
    • 2.3 DIP Users
    • 2.4 DIP Connection Providers (DCP)
    • 2.5 Replying Parties
  • 3 DIP Repositories and responsibilities
    • 3.1 DIP Repositories
    • 3.2 DIP-PKI Repository responsibilities
  • 4 Identification and Authentication
    • 4.1 Naming
    • 4.2 Identification and authentication for routine re-key
  • 5 Certificate lifecycle Operational requirements
    • 5.1 Digital Certificate application processing
    • 5.2 Digital Certificate Issuance
    • 5.3 Digital Certificate acceptance
    • 5.4 Key Pair and Digital Certificate usage
    • 5.5 Digital Certificate renewal
    • 5.6 Digital Certificate voluntary revocation
    • 5.6 Circumstances for revoking a Digital Certificate
    • 5.7 CRL issuance frequency
    • 5.8 On-line revocation/status checking
    • 5.9 Actions in the event of a Private Key compromise
    • 5.10 End of subscription
    • 5.11 Key escrow and recovery statements and practices
  • 6 Facility, management, and operational controls
    • 6.1 Overview
    • 6.2 Physical Controls
    • 6.3 Procedural controls
    • 6.4 Personnel controls
    • 6.5 Audit Logging Procedures
    • 6.6 The IA shall ensure the RA shall record for audit purposes, at minimum, the event types listed below:
    • 6.7 Record archiving
    • 6.8 Key changeover
    • 6.9 Compromise and disaster recovery
  • 7 Technical Security Controls
    • 7.1 Key pair generation and installation
    • 7.2 Key sizes and parameters
    • 7.3 Key usage purposes (as per x.509 v3 key usage field)
    • 7.4 Private Key protection and cryptographic module engineering controls
    • 7.5 Private Key transfer into or from a cryptographic module
    • 7.6 Method of activating Private Keys
    • 7.7 Method of destroying private key
    • 7.8 Other aspects of key pair management
    • 7.9 Activation Data
    • 7.10 Computer security controls
    • 7.11 Life Cycle Technical Controls
    • 7.12 Network Security Controls
  • 8 Certificate, CRL, and OCSP Profiles
    • 8.1 Certificate Profile
    • 8.2 CRL Profile
    • 8.3 OCSP Profile
  • 9 Compliance Audit and other assessments
    • 9.1 Frequency or circumstances of assessment
    • 9.2 Identity/qualifications of assessor
    • 9.3 Assessor's relationship to assessed entity
    • 9.4 Topics covered by assessment
    • 9.5 Actions taken as a result of deficiency
    • 9.6 Communication of results
  • Amendment Record

DSD002 Annex 3 - The DIP PKI Policy V1.0.0

Effective From Date:01/10/2024
Status:LIVE
Other versions
Download