Audit of licensed certification authority, requirements, exemptions, procedure
Effective Aug 28, 1998(L. 1998 S.B. 680 § 6)
Viewing an earlier version · effective Aug 28, 1998
- 1. A certified public accountant having expertise in computer security, or an accredited computer security professional, shall audit the operations of each licensed certification authority at least once each year to evaluate compliance with sections 28.600 to 28.678. The division may specify qualifications for auditors in greater detail by rule.
2.
(1) Based on information gathered in the audit, the auditor shall categorize the licensed certification authority's compliance as one of the following:
- (a) Full compliance, which means the certification authority appears to conform to all applicable statutory and regulatory requirements;
- (b) Substantial compliance, which means the certification authority generally appears to conform to all applicable statutory and regulatory requirements; however, one or more instances of noncompliance or inability to demonstrate compliance were found in the audited sample, but were likely to be inconsequential;
- (c) Partial compliance, which means the certification authority appears to comply with some statutory and regulatory requirements, but was found not to have complied or not to be able to demonstrate compliance with one or more important safeguards; or
- (d) Noncompliance, which means the certification authority complies with few or none of the statutory and regulatory requirements, fails to keep adequate records to demonstrate compliance with more than a few requirements, or refused to submit to an audit;
- (2) The auditor shall report the date of the audit of the licensed certification authority and resulting categorization to the division;
- (3) The division shall publish in the certification authority disclosure record it maintains for the certification authority, the date of the audit and the resulting categorization of the certification authority.
3.
(1) The division may exempt a licensed certification authority from the requirements of subsection 1 of this section if:
- (a) The certification authority to be exempted requests exemption in writing;
- (b) The most recent performance audit, if any, of the certification authority resulted in a finding of full or substantial compliance; and
(c) The certification authority declares under oath or affirmation that one or more of the following is true with respect to the certification authority:
- a. The certification authority has issued fewer than six certificates during the past year and the total of the recommended reliance limits of all such certificates does not exceed ten thousand dollars;
- b. The aggregate lifetime of all certificates issued by the certification authority during the past year is less than thirty days and the total of the recommended reliance limits of all such certificates does not exceed ten thousand dollars; or
- c. The recommended reliance limits of all certificates outstanding and issued by the certification authority total less than one thousand dollars;
- (2) If the certification authority's declaration pursuant to subdivision (1) of subsection 3 of this section falsely states a material fact, the certification authority shall have failed to comply with the performance audit requirement of this subsection;
- (3) If a licensed certification authority is exempt pursuant to this subsection, the division shall publish in the certification authority disclosure record it maintains for the certification authority a statement that the certification authority is exempt from the performance audit requirement.
(L. 1998 S.B. 680 § 6)