Certificate Revocation List (CRL) Availability, v1.0

Addresses requirements for mechanisms and procedures designed to ensure the availability of PKI Certificate Revocation Lists (CRLs)
If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Step

1
Certificate Revocation List (CRL) Availability (CertificateRevocationListCRLAvailability)
Are mechanisms and procedures designed to ensure PKI certificate Revocation Lists (CRLs) are available for retrieval 24 hours a day, 7 days a week, with a minimum of 99% availability overall per year and scheduled down-time not to exceed 0.5% annually?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameters
Annual Scheduled Downtime (Percentage)required
NUMBER : Provide the annual percentage of scheduled down time during which PKI certificates and CRLs are not available.
Days Per Week Availabilityrequired
NUMBER : Provide the number of days per week PKI Certificates and CRLs are available for retrieval.
Hours Per Day Availabilityrequired
NUMBER : Provide the number of hours per day PKI Certificates and CRLs are available for retrieval.
Yearly Availability (Percentage)required
NUMBER : Provide the percent of the time annually that PKI Certificates and CRLs are available for retrieval.
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (1)

C1
Organizations CAs being considered for cross certification shall design mechanisms and procedures to ensure CRLs are available for retrieval 24 hours a day, 7 days a week, with a minimum of 99% availability overall per year and scheduled down-time not to exceed 0.5% annually.
Citation
FBCA-CP
Section 2.2.1.