ETSI TS 101 533-1-2012 Electronic Signatures and Infrastructures (ESI) Data Preservation Systems Security Part 1 Requirements for Implementation and Management (V1 3 1)《电子签名和基础结构(E.pdf
《ETSI TS 101 533-1-2012 Electronic Signatures and Infrastructures (ESI) Data Preservation Systems Security Part 1 Requirements for Implementation and Management (V1 3 1)《电子签名和基础结构(E.pdf》由会员分享,可在线阅读,更多相关《ETSI TS 101 533-1-2012 Electronic Signatures and Infrastructures (ESI) Data Preservation Systems Security Part 1 Requirements for Implementation and Management (V1 3 1)《电子签名和基础结构(E.pdf(68页珍藏版)》请在麦多课文档分享上搜索。
1、 ETSI TS 101 533-1 V1.3.1 (2012-04) Electronic Signatures and Infrastructures (ESI); Data Preservation Systems Security; Part 1: Requirements for Implementation and Management Technical Specification ETSI ETSI TS 101 533-1 V1.3.1 (2012-04)2Reference RTS/ESI-00123-1 Keywords e-commerce, electronic si
2、gnature, data preservation, security, trust services ETSI 650 Route des Lucioles F-06921 Sophia Antipolis Cedex - FRANCE Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16 Siret N 348 623 562 00017 - NAF 742 C Association but non lucratif enregistre la Sous-Prfecture de Grasse (06) N 7803/88 Important n
3、otice Individual copies of the present document can be downloaded from: http:/www.etsi.org The present document may be made available in more than one electronic version or in print. In any case of existing or perceived difference in contents between such versions, the reference version is the Porta
4、ble Document Format (PDF). In case of dispute, the reference shall be the printing on ETSI printers of the PDF version kept on a specific network drive within ETSI Secretariat. Users of the present document should be aware that the document may be subject to revision or change of status. Information
5、 on the current status of this and other ETSI documents is available at http:/portal.etsi.org/tb/status/status.asp If you find errors in the present document, please send your comment to one of the following services: http:/portal.etsi.org/chaircor/ETSI_support.asp Copyright Notification No part may
6、 be reproduced except as authorized by written permission. The copyright and the foregoing restriction extend to reproduction in all media. European Telecommunications Standards Institute 2012. All rights reserved. DECTTM, PLUGTESTSTM, UMTSTMand the ETSI logo are Trade Marks of ETSI registered for t
7、he benefit of its Members. 3GPPTM and LTE are Trade Marks of ETSI registered for the benefit of its Members and of the 3GPP Organizational Partners. GSM and the GSM logo are Trade Marks registered and owned by the GSM Association. ETSI ETSI TS 101 533-1 V1.3.1 (2012-04)3Content Intellectual Property
8、 Rights 8g3Foreword . 8g3Acknowledgment 8g3Introduction 8g31 Scope 10g32 References 10g32.1 Normative references . 10g32.2 Informative references 10g33 Definitions and abbreviations . 12g33.1 Definitions 12g33.2 Abbreviations . 16g34 Overview 17g34.1 Preservation Service types 18g34.2 User Community
9、 and Applicability 19g34.3 Conformance requirements 19g35 Provisions based on TS 102 573 19g35.1 Compliance with the present document provisions 19g35.2 DPSP Obligations specified in TS 102 573, clause 6 . 20g35.2.1 Arrangements to cover liabilities and financial stability . 20g35.2.2 Conformance by
10、 sub-contractors 20g35.2.3 DPSP service provisions in abidance by the applicable legislation 21g35.2.4 Contractual aspects . 21g35.2.5 Resolution of complaints and disputes 22g35.2.6 Organisation independence . 23g35.2.7 DPSP Subscriber Obligations . 23g35.2.8 Information for trading partners 23g35.
11、2.9 Information for auditor/regulatory/tax authorities 24g36 Objectives and controls in TS 102 573, annex A . 24g36.1 SS.1. Signature . 24g36.1.1 SS.1.1. Class of Electronic Signature . 24g36.1.2 SS.1.2. Certification 24g36.1.3 SS.1.3. Signature Creation Data . 25g36.1.4 SS.1.4. Certificate subjects
12、 Registration 25g36.1.5 SS.1.5. Certificate Revocation 25g36.2 SS.2. Maintenance of Signature over storage period 25g36.3 SS.3. Storage 26g36.3.1 SS.3.1. Authorized Access 26g36.3.2 SS.3.2. Authenticity and Integrity . 26g36.3.3 SS.3.3. Data Object Readability . 27g36.3.4 SS.3.4. Storage media type
13、. 28g36.3.5 SS.3.5. Data Objects Format . 28g36.3.6 SS.3.6. Requirements on Separation and Confidentiality . 29g36.4 SS.4. Reporting to and Exchanges with Authorities . 29g36.5 SS.5. Conversion of Analog Originals to Digital Formats . 30g3Annex A (normative): ISO/IEC 27001 related Long Term Preserva
14、tion-specific ISMS control objectives, controls and implementation guidance 31g3A.1 Reference to ISO/IEC 27001 31g3A.2 Basic ISO/IEC 27002 provision . 31g3A.3 Enhanced ISO/IEC 27002 provisions . 31g3ETSI ETSI TS 101 533-1 V1.3.1 (2012-04)4A.4 New specific controls . 31g3A.5 Security Policy . 31g3A.5
15、.1 Information security policy 31g3A.5.1.1 Information security policy document 31g3A.5.1.2 Review of the information security policy 32g3A.6 Organization of information security . 32g3A.6.1 Internal organization. 32g3A.6.1.1 Management commitment to information security . 32g3A.6.1.2 Information se
16、curity co-ordination . 32g3A.6.1.3 Allocation of information security responsibilities . 33g3A.6.1.4 Authorization process for information processing facilities . 33g3A.6.1.5 Confidentiality agreements . 33g3A.6.1.6 Contact with authorities 34g3A.6.1.7 Contact with special interest groups . 34g3A.6.
17、1.8 Independent review of information security . 34g3A.6.2 External Parties 34g3A.6.2.1 Identification of risks related to external parties . 34g3A.6.2.2 Addressing security when dealing with customers . 34g3A.6.2.3 Addressing security in third party agreements 34g3A.7 Asset Management . 35g3A.7.1 R
18、esponsibility for assets . 35g3A.7.1.1 Inventory of assets 35g3A.7.1.2 Ownership of assets 36g3A.7.1.3 Acceptable use of assets . 36g3A.7.2 Information classification . 36g3A.7.2.1 Classification guidelines . 36g3A.7.2.2 Information labelling and handling . 37g3A.8 Human resources security 37g3A.8.1
19、 Prior to Employment 37g3A.8.1.1 Roles and responsibilities . 37g3A.8.1.2 Screening 38g3A.8.1.3 Terms and conditions of employment . 38g3A.8.2 During Employment . 38g3A.8.2.1 Management responsibilities 38g3A.8.2.2 Information security awareness, education, and training 38g3A.8.2.3 Disciplinary proc
20、ess 39g3A.8.3 Termination or Change of Employment . 39g3A.8.3.1 Termination responsibilities 39g3A.8.3.2 Return of assets . 39g3A.8.3.3 Removal of access rights 39g3A.9 Physical and environmental security 39g3A.9.1 Secure Areas . 39g3A.9.1.1 Physical security perimeter . 39g3A.9.1.2 Physical entry c
21、ontrols 40g3A.9.1.3 Securing offices, rooms, and facilities 40g3A.9.1.4 Protecting against external and environmental threats 40g3A.9.1.5 Working in secure areas 40g3A.9.1.6 Public access, delivery, and loading areas 40g3A.9.2 Equipment Security 41g3A.9.2.1 Equipment siting and protection . 41g3A.9.
22、2.2 Supporting utilities 41g3A.9.2.3 Cabling security 41g3A.9.2.4 Equipment maintenance 41g3A.9.2.5 Security of equipment off-premises 41g3A.9.2.6 Secure disposal or re-use of equipment 41g3A.9.2.7 Removal of property . 41g3A.10 Communications and operations management . 42g3A.10.1 Operational proce
23、dures and responsibilities . 42g3ETSI ETSI TS 101 533-1 V1.3.1 (2012-04)5A.10.1.1 Documented operating procedures . 42g3A.10.1.2 Change management . 42g3A.10.1.3 Segregation of duties 43g3A.10.1.4 Separation of development, test, and operational facilities . 43g3A.10.2 Third party service delivery m
24、anagement 43g3A.10.2.1 Service delivery 43g3A.10.2.2 Monitoring and review of third party services 43g3A.10.2.3 Managing changes to third party services . 44g3A.10.3 System planning and acceptance 44g3A.10.3.1 Capacity management . 44g3A.10.3.2 System acceptance 44g3A.10.4 Protection against malicio
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ETSITS10153312012ELECTRONICSIGNATURESANDINFRASTRUCTURESESIDATAPRESERVATIONSYSTEMSSECURITYPART1REQUIREMENTSFORIMPLEMENTATIONANDMANAGEMENTV131

链接地址:http://www.mydoc123.com/p-738110.html