ETSI TR 101 533-2-2012 Electronic Signatures and Infrastructures (ESI) Data Preservation Systems Security Part 2 Guidelines for Assessors (V1 3 1)《电子签名和基础结构(ESI) 数据保存系统的安全性 第2部分 评估_1.pdf
《ETSI TR 101 533-2-2012 Electronic Signatures and Infrastructures (ESI) Data Preservation Systems Security Part 2 Guidelines for Assessors (V1 3 1)《电子签名和基础结构(ESI) 数据保存系统的安全性 第2部分 评估_1.pdf》由会员分享,可在线阅读,更多相关《ETSI TR 101 533-2-2012 Electronic Signatures and Infrastructures (ESI) Data Preservation Systems Security Part 2 Guidelines for Assessors (V1 3 1)《电子签名和基础结构(ESI) 数据保存系统的安全性 第2部分 评估_1.pdf(41页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI TR 101 533-2 V1.3.1 (2012-04) Electronic Signatures and Infrastructures (ESI); Data Preservation Systems Security; Part 2: Guidelines for Assessors Technical Report ETSI ETSI TR 101 533-2 V1.3.1 (2012-04)2Reference RTR/ESI-00123-2 Keywords data preservation, e-commerce, electronic signature, s
2、ecurity, trust services ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important notice Individual copies of th
3、e present document can be downloaded from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Portable Document Format (PDF). In
4、 case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information on the current status of thi
5、s and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may be reproduced except as auth
6、orized by written permission. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2012. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for the benefit of its Members. 3G
7、PPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TR 101 533-2 V1.3.1 (2012-04)3Contents Intellectual Property Rights 8g3Foreword . 8g3Ack
8、nowledgment 8g3Introduction 8g31 Scope 9g32 References 9g32.1 Normative references . 9g32.2 Informative references 9g33 Definitions and abbreviations . 10g33.1 Definitions 10g33.2 Abbreviations . 10g34 Overview 10g34.1 Preservation Service types 10g35 Provisions based on TS 102 573 11g35.1 Complianc
9、e with the TS 101 533-1 11g35.2 DPSP Obligations specified in TS 102 573, clause 6 . 11g35.2.1 Arrangements to cover liabilities and financial stability . 11g35.2.2 Conformance by Subcontractors . 11g35.2.3 DPSP service provisions in abidance by the applicable legislation 12g35.2.4 Contractual aspec
10、ts . 12g35.2.5 Resolution of complaints and disputes 12g35.2.6 Organisation independence . 13g35.2.7 DPSP Subscriber Obligations . 13g35.2.8 Information for trading partners 13g35.2.9 Information for auditor/regulatory/tax authorities 13g36 Objectives and controls in TS 102 573, annex A . 13g36.1 SS
11、.1. Signature . 13g36.1.1 SS.1.1. Class of Electronic Signature . 13g36.1.2 SS.1.2. Certification 14g36.1.3 SS.1.3. Signature Creation Data . 14g36.1.4 SS.1.4. Certificate Subjects Registration . 14g36.1.5 SS.1.5. Certificate Revocation 14g36.2 SS.2. Maintenance of Signature over Storage Period . 14
12、g36.3 SS.3. Storage 15g36.3.1 SS.3.1. Authorized Access 15g36.3.2 SS.2. Authenticity and Integrity 15g36.3.3 SS.3.3. Data Object Readability . 15g36.3.4 SS.3.4. Storage media type . 16g36.3.5 SS.3.5. Data Objects Format . 16g36.3.6 SS.3.6. Requirements on Separation and Confidentiality . 16g36.4 SS.
13、4. Reporting to and Exchanges with Authorities . 16g36.5 SS.5. Conversion of Analog Originals to Digital Formats . 16g3Annex A: ISO/IEC 27001 related Long Term Preservation-specific ISMS guidelines for control assessment . 17g3A.1 Reference to ISO/IEC 27001 17g3A.2 Basic ISO/IEC 27002 provision . 17
14、g3A.3 Enhanced ISO/IEC 27002 provisions . 17g3A.4 New specific controls . 17g3ETSI ETSI TR 101 533-2 V1.3.1 (2012-04)4A.5 Security Policy . 17g3A.5.1 Information security policy 17g3A.5.1.1 Information security policy document 17g3A.5.1.2 Review of the information security policy 17g3A.6 Organizatio
15、n of information security . 18g3A.6.1 Internal organization. 18g3A.6.1.1 Management commitment to information security . 18g3A.6.1.2 Information security co-ordination . 18g3A.6.1.3 Allocation of information security responsibilities . 18g3A.6.1.4 Authorization process for information processing fac
16、ilities . 18g3A.6.1.5 Confidentiality agreements . 18g3A.6.1.6 Contact with authorities 18g3A.6.1.7 Contact with special interest groups . 18g3A.6.1.8 Independent review of information security . 19g3A.6.2 External Parties 19g3A.6.2.1 Identification of risks related to external parties . 19g3A.6.2.2
17、 Addressing security when dealing with customers . 19g3A.6.2.3 Addressing security in third party agreements 19g3A.7 Asset Management . 19g3A.7.1 Responsibility for assets . 19g3A.7.1.1 Inventory of assets 19g3A.7.1.2 Ownership of assets 20g3A.7.1.3 Acceptable use of assets . 20g3A.7.2 Information c
18、lassification . 20g3A.7.2.1 Classification guidelines . 20g3A.7.2.2 Information labelling and handling . 20g3A.8 Human resources security 20g3A.8.1 Prior to Employment 20g3A.8.1.1 Roles and responsibilities . 20g3A.8.1.2 Screening 20g3A.8.1.3 Terms and conditions of employment . 20g3A.8.2 During Emp
19、loyment . 21g3A.8.2.1 Management responsibilities 21g3A.8.2.2 Information security awareness, education, and training 21g3A.8.2.3 Disciplinary process 21g3A.8.3 Termination or Change of Employment . 21g3A.8.3.1 Termination responsibilities 21g3A.8.3.2 Return of assets . 21g3A.8.3.3 Removal of access
20、 rights 21g3A.9 Physical and environmental security 21g3A.9.1 Secure Areas . 21g3A.9.1.1 Physical security perimeter . 21g3A.9.1.2 Physical entry controls 21g3A.9.1.3 Securing offices, rooms, and facilities 22g3A.9.1.4 Protecting against external and environmental threats 22g3A.9.1.5 Working in secu
21、re areas 22g3A.9.1.6 Public access, delivery, and loading areas 22g3A.9.2 Equipment Security 22g3A.9.2.1 Equipment siting and protection . 22g3A.9.2.2 Supporting utilities 22g3A.9.2.3 Cabling security 22g3A.9.2.4 Equipment maintenance 22g3A.9.2.5 Security of equipment off-premises 22g3A.9.2.6 Secure
22、 disposal or re-use of equipment 22g3A.9.2.7 Removal of property . 22g3A.10 Communications and operations management . 23g3A.10.1 Operational procedures and responsibilities . 23g3A.10.1.1 Documented operating procedures . 23g3ETSI ETSI TR 101 533-2 V1.3.1 (2012-04)5A.10.1.2 Change management . 23g3
23、A.10.1.3 Segregation of duties 23g3A.10.1.4 Separation of development, test, and operational facilities . 23g3A.10.2 Third party service delivery management 23g3A.10.2.1 Service delivery 23g3A.10.2.2 Monitoring and review of third party services 23g3A.10.2.3 Managing changes to third party services
24、. 24g3A.10.3 System planning and acceptance 24g3A.10.3.1 Capacity management . 24g3A.10.3.2 System acceptance 24g3A.10.4 Protection against malicious and mobile code 24g3A.10.4.1 Controls against malicious code . 24g3A.10.4.2 Controls against mobile code 24g3A.10.5 Back-up 24g3A.10.5.1 Information b
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSITR10153322012ELECTRONICSIGNATURESANDINFRASTRUCTURESESIDATAPRESERVATIONSYSTEMSSECURITYPART2GUIDELINESFORASSESSORSV131

链接地址:http://www.mydoc123.com/p-735329.html