Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Audit section updates for ETSI TS 119 411-6 #209

Closed
srdavidson opened this issue Aug 3, 2023 · 3 comments
Closed

Audit section updates for ETSI TS 119 411-6 #209

srdavidson opened this issue Aug 3, 2023 · 3 comments
Labels

Comments

@srdavidson
Copy link
Contributor

Following the publication of ETSI TS 119 411-6 updates should be considered to the following sections:

8.4 (3)
"ETSI EN 319 411-1 v1.3.1 or newer" or "ETSI EN 319 411-2 v2.4.1 or newer", which includes normative references to ETSI EN 319 401 (the latest version of referenced ETSI documents should be applied) AND this document; or

8.6 (10)
(For audits conducted in accordance with any of the ETSI standards) a statement to indicate if the audit was a full audit or a surveillance audit, and which portions of the criteria were applied and evaluated, e.g., ETSI EN 319 401, ETSI EN 319 411-1 policy LCP, NCP or NCP+, ETSI EN 319 411-2 policy QCP-n, QCP-n-qscd, QCP-l or QCP-l-qscd; and

@srdavidson
Copy link
Contributor Author

ETSI TS 119 411-6 has been published. This standard maps the S/MIME BR to the ETSI CP OIDs, facilitating audits for ETSI-regime trust service providers.
https://portal.etsi.org/webapp/workProgram/Report_WorkItem.asp?wki_id=67990

@srdavidson
Copy link
Contributor Author

srdavidson commented Aug 22, 2023

Possible text for 8.4 (3):
"ETSI EN 319 411-1 v1.3.1 or newer" or "ETSI EN 319 411-2 v2.4.1 or newer", including normative references to ETSI EN 319 401 AND ETSI TS 119 411-6 (the latest version of referenced ETSI documents should be applied); or

Possible text for 8.6 (10):
(For audits conducted in accordance with any of the ETSI standards) a statement to indicate if the audit was a full audit or a surveillance audit, and which portions of the criteria were applied and evaluated, e.g., ETSI EN 319 401, ETSI TS 119 411-6, ETSI EN 319 411-1 policy LCP, NCP or NCP+, ETSI EN 319 411-2 policy QCP-n, QCP-n-qscd, QCP-l or QCP-l-qscd; and

see https://github.com/srdavidson/smime/blob/Ballot-SMC04/SBR.md

@srdavidson
Copy link
Contributor Author

See proposed text at srdavidson@e92c9f4 and srdavidson@f9cb877

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant