PKI Subscriber Responsibilities, v1.0

Addresses the requirement for subscribers of Organization CAs at the Basic Assurance Level shall agree to accurately represent themselves in all communications with the PKI authorities.
NOTE:If an assessment step references organization-defined elements (E.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), corresponding citations/excerpts must be provided to confirm that the organization has established and documented these values and that they apply as referenced in the conformance criteria.

Similarly, if a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]) is specified, evidence must be provided to establish that the option(s) implemented by the organization have been defined and documented.

The assessment step shall not be marked as satisfied without this evidence.

Assessment Step

1
Subscribers agree To Accurately Represent Themselves In Communications With PKI Authorities (SubscribersagreeToAccuratelyRepresentThemselvesInCommunicationsWithPKIAuthorities)
Does the organization include the following in their PKI subscriber requirements that must be acknowledged before certificates are issued to subscribers? Subscribers must: Accurately represent themselves in all communications with the PKI authorities. Protect their private keys at all times, in accordance with this policy, as stipulated in their certificate acceptance agreements and local procedures. Promptly notify the appropriate CA upon suspicion of loss or compromise of their private keys. Such notification shall be made directly or indirectly through mechanisms consistent with the CA's CPS. Abide by all the terms, conditions, and restrictions levied on the use of their private keys and certificates.
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
If conformance criteria reference organization-defined elements (e.g. <organization-defined personnel or roles>, <organization-defined frequency>, etc.), these values must be defined and documented by the organization.

Similarly, if the criteria specify a "Selection" among multiple options (e.g. [Selection (one or more): as needed; ]), the option(s) implemented by the organization must also be defined and documented.

Conformance Criteria (1)

C1
Subscribers of Entity CAs at Basic, Medium, and High Assurance Levels shall agree to the following: Accurately represent themselves in all communications with the PKI authorities. Protect their private keys at all times, in accordance with this policy, as stipulated in their certificate acceptance agreements and local procedures. Promptly notify the appropriate CA upon suspicion of loss or compromise of their private keys. Such notification shall be made directly or indirectly through mechanisms consistent with the CA's CPS. Abide by all the terms, conditions, and restrictions levied on the use of their private keys and certificates.
Citation
FBCA-CP
Section 9.6.3.