首页 馆藏资源 舆情信息 标准服务 科研活动 关于我们
现行 ISO/IEC 27099:2022
到馆阅读
收藏跟踪
购买正版
Information technology - Public key infrastructure - Practices and policy framework 信息技术.公钥基础设施.实践和政策框架
发布日期: 2022-07-08
ISO/IEC 27099:2022本文件规定了一个要求框架,通过证书政策、证书实践声明,以及在适用情况下,通过信息安全管理系统(ISMS)的内部支持,管理公钥基础设施(PKI)信任服务提供商的信息安全。需求框架包括信息安全风险的评估和处理,根据证书政策的规定,量身定制以满足其用户的约定服务需求。本文档还旨在帮助信任服务提供商支持多个证书策略
本文档介绍了用于数字签名、身份验证或数据加密密钥建立的公钥证书的生命周期。 它不解决基于公钥证书使用的身份验证方法、不可否认性要求或密钥管理协议。在本文件中,“证书”一词是指公钥证书。本文件不适用于属性证书
本文件使用ISO/IEC 27000标准系列中定义的ISMS的概念和要求。它使用ISO/IEC 27002中定义的信息安全控制实施规程。特定的PKI要求(例如证书内容、身份验证、证书撤销处理)不是由ISO/IEC 27001[26]定义的ISMS直接解决的
ISMS或同等标准的使用适用于本文件所述证书政策中规定的PKI服务要求的应用。
PKI信任服务提供商是用于使用公钥证书的一类特殊的信任服务
本文件对封闭、开放和契约环境中使用的PKI系统进行了区分。本文件旨在促进在合同环境中实施运营、基线控制和实践。虽然本文件的重点是合同环境,但并不明确禁止将本文件应用于开放或封闭环境。
ISO/IEC 27099:2022 This document sets out a framework of requirements to manage information security for Public key infrastructure (PKI) trust service providers through certificate policies, certificate practice statements, and, where applicable, their internal underpinning by an information security management system (ISMS). The framework of requirements includes the assessment and treatment of information security risks, tailored to meet the agreed service requirements of its users as specified through the certificate policy. This document is also intended to help trust service providers to support multiple certificate policies.
This document addresses the life cycle of public key certificates that are used for digital signatures, authentication, or key establishment for data encryption. It does not address authentication methods, non-repudiation requirements, or key management protocols based on the use of public key certificates. For the purposes of this document, the term “certificate” refers to public key certificates. This document is not applicable to attribute certificates.
This document uses concepts and requirements of an ISMS as defined in the ISO/IEC 27000 family of standards. It uses the code of practice for information security controls as defined in ISO/IEC 27002. Specific PKI requirements (e.g. certificate content, identity proofing, certificate revocation handling) are not addressed directly by an ISMS such as defined by ISO/IEC 27001 [26].
The use of an ISMS or equivalent is adapted to the application of PKI service requirements specified in the certificate policy as described in this document.
A PKI trust service provider is a special class of trust service for the use of public key certificates.
This document draws a distinction between PKI systems used in closed, open and contractual environments. This document is intended to facilitate the implementation of operational, baseline controls and practices in a contractual environment. While the focus of this document is on the contractual environment, application of this document to open or closed environments is not specifically precluded.
分类信息
发布单位或类别: 国际组织-国际电工委员会
关联关系
研制信息
归口单位: ISO/IEC JTC 1/SC 27
相似标准/计划/法规
现行
GB/T 26855-2011
信息安全技术 公钥基础设施 证书策略与认证业务声明框架
Information security technology - Public key infrastructure - Certificate policy and certification practice statement framework
2011-07-29
现行
GB/T 20518-2018
信息安全技术 公钥基础设施 数字证书格式
Information security technology—Public key infrastructure—Digital certificate format
2018-06-07
现行
GB/T 20520-2006
信息安全技术 公钥基础设施 时间戳规范
Information security technology - Public key infrastructure - Time stamp specification
2006-08-30
现行
GB/T 19714-2005
信息技术 安全技术 公钥基础设施 证书管理协议
Information technology-Security technology-Internet public key infrastructure-Certificate management protocol
2005-04-19
现行
GB/T 32213-2015
信息安全技术 公钥基础设施 远程口令鉴别与密钥建立规范
Information security technology—Public key infrastructure—Specifications for remote password authentication and key establishment
2015-12-10
现行
GB/T 29241-2012
信息安全技术 公钥基础设施 PKI互操作性评估准则
Information security technology - Public key infrastructure - PKI interoperability evaluation criteria
2012-12-31
现行
GB/T 25064-2010
信息安全技术 公钥基础设施 电子签名格式规范
Information security technology - Public key infrastructure - Electronic signature formats specification
2010-09-02
现行
GB/T 30272-2021
信息安全技术 公钥基础设施 标准符合性测评
Information security technology—Public key infrastructure—Testing and assessment of compliance with standards
2021-10-11
现行
GB/T 19771-2005
信息技术 安全技术 公钥基础设施 PKI 组件最小互操作规范
Information technology-Security technology-Public key infrastructure-Minimum interoperability specification for PKI components
2005-05-25
现行
GB/T 21053-2023
信息安全技术 公钥基础设施 PKI系统安全技术要求
Information security techniques—Public key infrastructure—Security technology requirement for PKI system
2023-03-17
现行
GB/T 25065-2010
信息安全技术 公钥基础设施 签名生成应用程序的安全要求
Information security technology - Public key infrastructure - Security requirements for signature creation applications
2010-09-02
现行
GB/T 35285-2017
信息安全技术 公钥基础设施 基于数字证书的可靠电子签名生成及验证技术要求
Information security technology—Public key infrastructure—Technical requirements for digital certificate based reliable electronic signature creation and verification
2017-12-29