PKI Certificate Revocation Request Processing Time, v1.0

Addresses the requirement for organization PKI certificate authorities (CAs) to revoke certificates within a documented processing time upon receipt of a proper revocation request.
If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Step

1
PKI Certificate Revocation Request Processing Time (PKICertificateRevocationRequestProcessingTime)
Do organization PKI certificate authorities (CAs) require the revoke PKI certificates within a documented processing time upon receipt of a proper revocation request?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
Parameter
Revocation Request Processing Timerequired
ENUM_MULTI : Select all applicable requirements for certificate revocation request processing time
  • As quickly as practical
  • Before the next certificate revocation list (CRL) is published
  • Before the next two CRLs are published when requests validated within two hours of CRL issuance
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (1)

C1
The Organization CAs will revoke certificates as quickly as practical upon receipt of a proper revocation request.
Citation
FBCA-CP
Section 4.9.5.