0% found this document useful (0 votes)
6 views13 pages

Cdac

The WebTrust Security Framework for Certification Authorities (CAs) outlines principles and criteria for ensuring the security, availability, processing integrity, confidentiality, and privacy of CA systems. It serves as a control framework for assessing CA systems and provides guidelines for self-assessment and independent evaluations. The framework includes detailed criteria and illustrative controls related to business practices, environmental controls, and key lifecycle management.

Uploaded by

addpolas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views13 pages

Cdac

The WebTrust Security Framework for Certification Authorities (CAs) outlines principles and criteria for ensuring the security, availability, processing integrity, confidentiality, and privacy of CA systems. It serves as a control framework for assessing CA systems and provides guidelines for self-assessment and independent evaluations. The framework includes detailed criteria and illustrative controls related to business practices, environmental controls, and key lifecycle management.

Uploaded by

addpolas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

WebTrust Security Framework for CCA

Principles and Criteria for Certification Authorities

C-DAC Bangalore
Introduction to WebTrust

• Trust Services: Audit and assurance services.

• Set of principles and criteria put forth jointly by AICPA and CICA.

• WebTrust taskforce is an associate member of CA|B forum.

• Consistent with standards developed by the American National Standards Institute


(ANSI), International Organization for Standardization (ISO), and Internet Engineering Task
Force (IETF).
Trust Services Principles

• Security: The system is protected, both logically and physically, against unauthorized access.

• Availability: The system is available for operation and use as committed or agreed to.

• Processing Integrity: System processing is complete, accurate, timely, and authorized.

• Confidentiality: Information that is designated “confidential” is protected as committed or


agreed.

• Privacy: Personal information is collected, used, retained, and disclosed in conformity with
the commitments in the entity’s privacy notice and with the privacy principles
WebTrust Audit Schemes
Intended Use of the WebTrust Principles and Criteria

• The WebTrust Principles and Criteria for CAs can be used as a control framework to assess
the adequacy of the CA systems, policies and procedures.

• It provides a basis for self-assessment for either development or maintaining strong PKI
systems.

• Assessors / practitioners can use the framework as a benchmark for performing an


internal or independent assessment.
Principles and Criteria for Certification Authorities

• CA business practices disclosure: Disclosure of key and Certificate Life Cycle Management, and CA
Environmental Control practices in its Certification Practice Statement & Certificate Policy

CP and CPS documents in accordance with IETF RFC 3647 Internet X.509 Public Key Infrastructure
Certificate Policy and Certification Practices Framework

• Service integrity: The integrity of keys and certificates it manages is established and protected
throughout their life cycles

• CA environmental controls: Logical and physical access to CA systems & data is restricted and CA
systems development, maintenance and operations are properly authorized and performed to
maintain CA systems integrity
Criteria and Illustrative Controls

1. Business Practices Disclosure (2 Disclosers)

2. Business Practices Management (3 Criteria, 15 Illustrative controls)

3. CA Environmental Controls (28 Criteria, 151 Illustrative controls)

4. CA Key Lifecycle management Controls (12 Criteria, 68 Illustrative controls)

5. Subscriber Key Lifecycle Controls (19 Criteria, 64 Illustrative controls)

6. Certificate Lifecycle management (10 Criteria, 97 Illustrative controls)

7. Subordinate CA and Cross Certificate Lifecycle management Controls (7 Criteria, 13 Illustrative


controls)
Security framework
Architecture for CCA
Core Security Framework

• Security activities and controls organized and customized based on WebTrust Principles
and Criteria.

• Designed to cover the breadth of security objectives for CCA, while not being detailed.

• Refers to policy and procedure for depth of security objectives which are derived with
standard references from ISO, NIST and ITA.
Policy and procedures
1. Information Security Management 9. Monitoring and logging policy

2. Asset Management 10. Risk Management

3. Human Resources Security 11. Roles and responsibility

4. Physical and Environmental Security 12. Incident Management

5. Media and Operations Management 13. Incident response procedure

6. Access Control Management 14. Key lifecycle management

7. Maintenance and Change management. 15. Certificate lifecycle management

8. Business Continuity Management 16. Awareness and Training


CA Environmental Controls / Security Management
Criteria Illustrative Controls Policy and procedures with
Informative Reference
Information • An information security policy document published Information Security Management
security policy and communicated PL-1
• information security, its overall objectives and scope, 5.2, 5.3, 7.5.1, 7.5.2, 7.5.3, A.5.1.1,
and the importance A.5.1.2, A.6.1.1, A.12.1.1, A.18.1.1,
• review process for maintaining the information A.18.2.2
security policy
Information • Management support to manage risks Information Security Management
security • Responsibilities for the protection of individual assets PM-2, PM-6, PM-29
infrastructure • process for new information processing 5.1, 5.3, 9.2, A.6.1.1
Security of third • Enforced to control physical and logical access by Information Security Management
party access third parties PE-2,PE-3,RA-3
• Risk assessment is performed to determine specific A.12.6.1, A.11.1.1, A.11.1.2, A.11.1.13
control requirements. Risk Management
• Formal contract containing necessary security RA-3
requirements. 6.1.2, 8.2
CA Environmental Controls / System Access Management

Criteria Illustrative Controls Policy and procedures with


Informative Reference
User access • Roles, access permissions, authentication process and Roles and responsibility
management segregation of duties
• procedure for access to systems software and network devices Asset Management
• Authentication procedure and privilege management
Network access • Access is authorized and controlled Asset Management
control • Routing control and Isolation from any other domain Physical and Environmental Security
• System configuration and compliance Maintenance and Change
• Data confidentiality during transit management.
System software • Periodic review and update of System configuration Maintenance and Change
and network • Patch management based on risk assessment management.
device access • Secure login process Access Control Management
control • Unique User identification and individual accountability
Application access • Application system functions are restricted Access Control Management
control • CA personnel are successfully identified and authenticated Physical and Environmental Security
• Dedicated and isolated compute environment for Root CA

You might also like