PKI Compliance Audits Verify Compliance With Organization PKI Certificate Policy (CP) And MOAs, v1.0

Addresses the requirement for PKI compliance audis to verify compliance with the organization's PKI certificate policy and MOAs with other PKIs.
NOTE:If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Step

1
PKI Compliance Audits Verify Compliance With Organization PKI Certificate Policy (CP) And MOAs (PKIComplianceAuditsVerifyComplianceWithOrganizationPKICertificatePolicyCPAndMOAs)
Do compliance audits verify that the organization complies with with the requirements of the organization's PKI certificate policy and MOAs between the organization PKI and any other PKIs?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (1)

C1
The purpose of a compliance audit of an Organization PKI shall be to verify that an Organization subject to the requirements of an Organization CP is complying with the requirements of those documents, as well as any MOAs between the Organization PKI and any other PKI.
Citation
FBCA-CP
Section 8.4.