GB/T 28447-2012 Information security technology—Specification on the operation management of a certificate authority
GB/T 28447-2012 Information security technology—Specification on the operation management of a certificate authority
Basic Information
Scope
This standard specifies the requirements that electronic certification service providers should follow in multiple aspects, including business operations, certification system operation, physical environment and facility security, organization and personnel management, document, record, and media management, business continuity, audit, and improvement.
This standard applies to the construction, management, and evaluation of electronic certification service providers that provide digital certificate services in an open and interconnected environment.
For electronic certification service providers operating in a closed environment (such as within a specific group or industry), they can selectively refer to this standard based on their own security risk assessments and relevant national laws and regulations. Relevant national evaluation agencies and regulatory authorities can also use this standard as a basis for evaluation and supervision.