diff --git a/SecurityPolicy.html b/SecurityPolicy.html index db8116e..0e248b1 100644 --- a/SecurityPolicy.html +++ b/SecurityPolicy.html @@ -775,7 +775,7 @@ and progress information should be published as soon as possible. The knowledge of the existence of the event must not be kept secret, nor the manner and methods be kept confidential. -See §9.7. +See §9.5.

6. DISASTER RECOVERY

@@ -1203,15 +1203,15 @@ Recovery must only be conducted under Arbitrator authority.

-

9.5. Legal

+

9.3. Legal

-

9.5.1. Responsibility

+

9.3.1. Responsibility

The board is responsible for the CA at the executive level.

-

9.5.2. Response to external (legal) inquiry

+

9.3.2. Response to external (legal) inquiry

All external inquiries of security import are filed as disputes and placed before the Arbitrator under DRP. @@ -1227,7 +1227,7 @@ The Arbitrator's ruling may instruct individuals, and becomes your authority to act.

-

9.6. Outsourcing

+

9.4. Outsourcing

Components may be outsourced. @@ -1270,7 +1270,7 @@ Contracts should be written with the above in mind.

-

9.7 Confidentiality, Secrecy

+

9.5 Confidentiality, Secrecy

CAcert is an open organisation and adopts a principle