Before initial approval as a licensed Certification Authority, and thereafter at least once every year, the Certification Authority shall submit to a security compliance audit by a security firm. The audit must evidence compliance with Federal Information Processing Standards 140-1 "Security: Cryptographic Modules" Level 2 and TSEC (The Orange Book) C2 criteria or comply with contemporary Certification Authority security criteria as expressed in terms of the "Common Criteria" - ISO 15408-1:1999. In order for an audit firm to be approved by the Electronic Commerce Section, it must engage or employ at least one Certified Information Systems Auditor (CISA) certified by the Information Systems Audit and Control Association (CISACA), 3701 Algonquin Road, Rolling Meadows, Illinois, 60008, www.ISACA.org. A certified copy of the current unqualified security audit report must be attached to an application for a new certification authority license or renewal license, and submitted to the NC Department of Secretary of State, Electronic Commerce Section.
18 N.C. Admin. Code 10 .0303
Codifier determined on November 23, 1999, agency findings did not meet criteria fo temporary rule;
Temporary Adoption Eff. December 3, 1999;
Eff. March 26, 2001;
Pursuant to G.S. 150B-21.3A, rule is necessary without substantive public interest Eff. December 6, 2016.
Codifier determined on November 23, 1999, agency findings did not meet criteria fo temporary rule;
Temporary Adoption Eff. December 3, 1999;
Eff. March 26, 2001.