ANSI INCITS ISO IEC TR 14516-2002 Information technology - Security techniques - Guidelines on the use and management of Trusted Third Party services (Technical Report).pdf
《ANSI INCITS ISO IEC TR 14516-2002 Information technology - Security techniques - Guidelines on the use and management of Trusted Third Party services (Technical Report).pdf》由会员分享,可在线阅读,更多相关《ANSI INCITS ISO IEC TR 14516-2002 Information technology - Security techniques - Guidelines on the use and management of Trusted Third Party services (Technical Report).pdf(42页珍藏版)》请在麦多课文档分享上搜索。
1、 INCITS/ISO/IEC TR 14516:2002 2015 (ISO/IEC TR 14516:2002, IDT) Information technology - Security techniques - Guidelines on the use and management of Trusted Third Party services (Technical Report) INCITS/ISO/IEC TR 14516:2002 2015 PDF disclaimer This PDF file may contain embedded typefaces. In acc
2、ordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobes
3、licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for pri
4、nting. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. Registered by INCITS (InterNational Committee for Information Technology
5、Standards) as an American National Standard. Date of Registration: 6/28/2015 Published by American National Standards Institute, 25 West 43rd Street, New York, New York 10036 Copyright 2015 by Information Technology Industry Council (ITI). All rights reserved. These materials are subject to copyrigh
6、t claims of International Standardization Organization (ISO), International Electrotechnical Commission (IEC), American National Standards Institute (ANSI), and Information Technology Industry Council (ITI). Not for resale. No part of this publication may be reproduced in any form, including an elec
7、tronic retrieval system, without the prior written permission of ITI. All requests pertaining to this standard should be submitted to ITI, 1101 K Street NW, Suite 610, Washington DC 20005. Printed in the United States of America ii ITIC 2015 All rights reserved Reference numberISO/IEC TR 14516:2002(
8、E)ISO/IEC 2002TECHNICAL REPORT ISO/IECTR14516First edition2002-06-15Information technology Security techniques Guidelines for the use and management of Trusted Third Party services Technologies de linformation Techniques de scurit Lignes directrices pour lemploi et la gestion des services TTP ISO/IE
9、C TR 14516:2002(E) PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In down
10、loading this file, parties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the
11、 General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address
12、given below. ISO/IEC 2002 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISOs
13、 member body in the country of the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail copyrightiso.ch Web www.iso.ch Printed in Switzerland ii ISO/IEC 2002 All rights reservedISO/IEC TR 14516:2002(E) ISO/IEC 2002 All rights reserved
14、iiiCONTENTS Page 1 Scope . 1 2 References 1 2.1 Identical Recommendations | International Standards 1 2.2 Paired Recommendations | International Standards equivalent in technical content 1 2.3 Additional References 1 3 Definitions 2 4 General Aspects 3 4.1 Basis of Security Assurance and Trust 3 4.2
15、 Interaction between a TTP and Entities Using its Services 4 4.2.1 In-line TTP Services . 4 4.2.2 On-line TTP Services 4 4.2.3 Off-line TTP Services. 5 4.3 Interworking of TTP Services 5 5 Management and Operational Aspects of a TTP 5 5.1 Legal Issues. 6 5.2 Contractual Obligations 6 5.3 Responsibil
16、ities 7 5.4 Security Policy. 7 5.4.1 Security Policy Elements 8 5.4.2 Standards 8 5.4.3 Directives and Procedures. 8 5.4.4 Risk Management. 8 5.4.5 Selection of Safeguards. 9 5.4.5.1 Physical and Environmental Measures . 9 5.4.5.2 Organisational and Personnel Measures . 9 5.4.5.3 IT Specific Measure
17、s. 9 5.4.6 Implementation Aspects of IT Security 10 5.4.6.1 Awareness and Training 10 5.4.6.2 Trustworthiness and Assurance 10 5.4.6.3 Accreditation of TTP Certification Bodies 11 5.4.7 Operational Aspects of IT Security 11 5.4.7.1 Audit/Assessment 11 5.4.7.2 Incident Handling 12 5.4.7.3 Contingency
18、 Planning 12 5.5 Quality of Service 12 5.6 Ethics 12 5.7 Fees. 12 6 Interworking. 12 6.1 TTP-Users . 13 6.2 User-User 13 6.3 TTP-TTP. 13 6.4 TTP-Law Enforcement Agency 14 7 Major Categories of TTP Services. 14 7.1 Time Stamping Service 14 7.1.1 Time Stamping Authority 14 7.2 Non-repudiation Services
19、 . 15 7.3 Key Management Services. 16 7.3.1 Key Generation Service 16 7.3.2 Key Registration Service. 16 7.3.3 Key Certification Service 16 7.3.4 Key Distribution Service. 17 7.3.5 Key Installation Service 17 7.3.6 Key Storage Service 17 7.3.7 Key Derivation Service. 17 7.3.8 Key Archiving Service 1
20、7 ISO/IEC TR 14516:2002(E) iv ISO/IEC 2002 All rights reservedPage 7.3.9 Key Revocation Service 17 7.3.10 Key Destruction Service . 17 7.4 Certificate Management Services . 18 7.4.1 Public Key Certificate Service 18 7.4.2 Privilege Attribute Service 18 7.4.3 On-line Authentication Service Based on C
21、ertificates 19 7.4.4 Revocation of Certificates Service. 19 7.5 Electronic Notary Public Services 19 7.5.1 Evidence Generation Service 20 7.5.2 Evidence Storage Service 20 7.5.3 Arbitration Service 20 7.5.4 Notary Authority 20 7.6 Electronic Digital Archiving Service 21 7.7 Other Services . 22 7.7.1
22、 Directory Service 22 7.7.2 Identification and Authentication Service 23 7.7.2.1 On-line Authentication Service 23 7.7.2.2 Off-line Authentication Service . 25 7.7.2.3 In-line Authentication Service 25 7.7.3 In-line Translation Service 25 7.7.4 Recovery Services 25 7.7.4.1 Key Recovery Services 25 7
23、.7.4.2 Data Recovery Services . 26 7.7.5 Personalisation Service . 26 7.7.6 Access Control Service. 26 7.7.7 Incident Reporting and Alert Management Service 26 Annex A Security Requirements for Management of TTPs 28 Annex B Aspects of CA management . 29 B.1 Example of Registration Process Procedures
24、. 29 B.2 An example of requirements for Certification Authorities. 29 B.3 Certification Policy and Certification Practice Statement (CPS) 31 Annex C Bibliography 32 Table of Figures Figure 1 In-line TTP Service Between Entities 4 Figure 2 On-line TTP Service Between Entities 5 Figure 3 Off-line TTP
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ANSIINCITSISOIECTR145162002INFORMATIONTECHNOLOGYSECURITYTECHNIQUESGUIDELINESONTHEUSEANDMANAGEMENTOFTRUSTEDTHIRDPARTYSERVICESTECHNICALREPORTPDF

链接地址:http://www.mydoc123.com/p-436613.html