diff --git a/TTPAssistedAssurancePolicy-20130211.html b/TTPAssistedAssurancePolicy-20130211.html new file mode 100644 index 0000000..72893df --- /dev/null +++ b/TTPAssistedAssurancePolicy-20130211.html @@ -0,0 +1,214 @@ + + + + + CAcert -- TTP-Assisted Assurance Policy + + + + +
+ + + + + + +
+ Name: TTP-Assist COD13.2
+ Status: DRAFT p20100913
+ Editor: Ulrich Schroeter
+ Licence: CC-by-sa+DRP
+
+ TTP-Assist Status - DRAFT + +
+
+ +

TTP-Assisted Assurance Policy

+ +

0. Preliminaries

+

+ This sub-policy extends the + + Assurance Policy ("AP" => COD13) + by specifying how Assurers can be assisted by + outsourcing the identity documents verification + component of assurance to trusted third parties (TTPs). + Other definitions and terms can be found in AP or in + Assurance Handbook + ("AH"). +

+ +

1. Scope

+

+ This sub-policy is restricted to members located + in areas not well-served with Assurers. + It serves a goal of promoting both Assurers and Members in those areas. +

+ +

2. Roles

+ +

2.1 Trusted Third Party

+

+ A Trusted Third Party ("TTP") is a person who is traditionally respected + for making reliable statements to others, especially over identification + documents. Typically, notaries public (anglo), + Notaries (European), bank managers, accountants + and lawyers. +

+ +

2.2 The Assurer (aka TTP-admin)

+

+ To employ a TTP in an assurance, + the Assurer must be a Senior Assurer. + The Assurer must be familiar with the local + language and customs. +

+ +

2.3 Member

+ +

+ A Member ("assuree") who is located in a place not well-served + by Assurers may use the TTP-assisted assurance. +

+ +

3. The Assurance

+ +

+ Assurance assisted by TTP must meet these requirements: +

+
  1. + The Assurer must positively confirm the identity and + suitability of the TTP. +
  2. + The TTP and the Member must meet face-to-face. +
  3. + The TTP confirms the details supporting the Assurance Statement. +
  4. + The Assurer makes a reliable statement to confirm the + Assurance Statement. +
  5. + Assurance must be marked as TTP-Assisted + (e.g., by use of TTPAdmin flag). +
+ + + +

4. Assurance Officer ("AO")

+

+ The Board routinely delegates its responsibilities to the + Assurance Officer (and this section assumes that, but does + not require it). +

+ +

+ A report is requested annually from the Assurance Officer + on performance of this policy for the association's + annual report. +

+

4.1 Practice

+

+ Assurance Officer should prepare a + detailed documentation + under + AH + that meets the needs of this policy, including: +

+ + +

4.2 Deserts

+

+ The Assurance Officer maintains a + list of regions + that are designated as 'deserts,' being areas that are so short + of Assurers as to render face-to-face Assurance impractical. + In each region, approved types of TTP are listed (e.g., Notary). + The list is expected to vary according to the + different juridical traditions of different regions. + Changes to the regional lists are prepared by + either an Organisation Assurer for that region + (as described by OAP) + or by two Assurers familiar with the traditions + in that region. + Changes are then submitted to the Board for approval. +

+

+ Use of a type of TTP not on the list must be approved by + AO and notified to Board. + It is an explicit goal to reduce the usage of + TTP-assisted assurances in favour of face-to-face Assurance. +

+ +

+ In coordination with internal and external auditors, + the Assurance Officer shall design and implement a + suitable programme to meet the needs of audit. + Where approved by auditors or Board, the Assurance + Officer may document and implement minor variations to this policy. +

+ +

5. Topup Assurance

+ +

+ AO is to operate a Topup Assurance Programme + to help seed deserts with Assurers. + A topup assurance will add additional Assurance Points + to those gained from two previously conducted TTP-assisted assurances, + in order for a Member to reach 100 Assurance Points + for the express purpose of becoming an Assurer. +

+ +

+ A topup assurance is conducted by a third Senior Assurer + according to the following requirements: +

+ +
  1. + Assurer Challenge must be completed as passed by Member. +
  2. + The topup must be requested by Member for + purpose of enabling the Member to reach Assurer level. +
  3. + Topup Assurer must be a Senior Assurer, + and must be independent of the TTP-assist Assurers. +
  4. + The Topup Assurer reviews the two TTP-assisted assurances, + and conducts other checks as set by the Assurance Officer. + The normal face-to-face meeting is not conducted. +
  5. + Topup Assurer may award up to 35 points. +
  6. + Assurance must be marked as Topup + (e.g., by use of new feature with TTPAdmin flag). +
+ +

+ Each topup is to be reported to AO. + Topup is only available in designated deserts. +

+ + +