Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add requirement that CAs implement and maintain a Security Program #18

Open
BenWilson-Mozilla opened this issue Apr 1, 2022 · 0 comments

Comments

@BenWilson-Mozilla
Copy link
Contributor

CAs shall implement and maintain a Network and Systems Security Program.

The CA shall implement and maintain network and systems security documentation (e.g. physical, personnel, procedural and technical controls) appropriate for the services provided.

  • WebTrust § 3.1.1 - An information security policy document, that includes physical, personnel, procedural and technical controls, is approved by management, published and communicated to all employees.
  • NIST 800-53 PM-1 a. Develop and disseminate an organization-wide information security program plan that: ….
  • ETSI 6.3

The Security Plan shall be reviewed and updated at least annually.

  • WebTrust § 3.1.3 -There is a defined review process for maintaining the information security policy, including responsibilities and review dates.
  • NIST 800-53 PM-1 c. Update the information security program plan to address organizational changes and problems identified during plan implementation or control assessments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants