From 9cfceaad121125026a9fd6977d8c226c1eef13ab Mon Sep 17 00:00:00 2001 From: Teus Hagen Date: Mon, 22 Oct 2007 10:24:41 +0000 Subject: [PATCH] nitial version of sub policy for Germany: draft status. git-svn-id: http://svn.cacert.org/CAcert/Policies@447 14b1bab8-4ef6-0310-b690-991c95c89dfd --- .../OrganisationAssurance-SubPolGermany.html | 62 +++++++++++++++++++ 1 file changed, 62 insertions(+) create mode 100644 OrganisationAssurancePolicy/OrganisationAssurance-SubPolGermany.html diff --git a/OrganisationAssurancePolicy/OrganisationAssurance-SubPolGermany.html b/OrganisationAssurancePolicy/OrganisationAssurance-SubPolGermany.html new file mode 100644 index 0000000..4348b2d --- /dev/null +++ b/OrganisationAssurancePolicy/OrganisationAssurance-SubPolGermany.html @@ -0,0 +1,62 @@ +

Organisation Assurance - sub-policy for German organisations

+

+Author: Jens Paul +
+Creation date: WIP 2007-10-19 V0.1 +
+Status: DRAFT 2007-10-22 based on WIP version 0.2 +
+Date next status: changes expected in December 2007. +
+ + +

0. Preliminaries

+This sub-policy describes how Organisation Assurers ("OAs") conduct assurances on German organisations. +It fits within the overall web-of-trust or assurance process and the Organisation Assurance Policy (OAP) of CAcert. +


+ +

1. Purpose

+This is a subsidiary policy to the OAP. +

+a. This sub-policy is applicable for the assurance of German organisations only.
+b. This sub-policy is an implementation of the OAP.
+c. In the below, where the Assurance Officer (AO) is referred to, this includes his local delegate. +


+ +

2. Organisation Assurers

+ +

2.1 Requirements for the Organisation Assurer

+In addition to the requirements defined in the OAP, an OA must meet the following requirements for assuring German organisations:
+a. Knowledge on common legal forms of organisations in Germany.
+b. Must pass an additional test on local knowledge even if he is already an OA.
+c. Should help the AO to define local requirements. +


+ +

3. Process

+ +

3.1 Organisations

+Acceptable organisations under this sub-policy must be: +

+a. Organisations created under the rules of the German jurisdiction.
+b. Organisations must not be revoked by a competent authority with direct oversight over the organisation. +

+ +

3.2 Documents

+The organisation has to provide documents to prove the essential standard of Organisation Assurance as defined in the policy:
+a. The primary mechanism to prove existence is to get an official extract from the official register, either via an online interface +or via physical means (organisation is asked to carry the costs)
+b. Where not available, an official document will be required from the company, subject to such checks as defined by the AO.
+c. If copies of official extracts from the official register are provided, they must be officially certified
+d. Extracts from the official register should not be older than 4 weeks.
+e. The AO maintains a list of which specific documents and tests can be acceptable for the certain types +of organisations.
+f. The OA can ask for additional documents if needed to validate required information for the assurance action. +

+ +

3.3 COAP

+In addition to the checks defined in the policy, the COAP form for German organisations requires:
+a. The OA must keep all documentation for 10 years.
+b. Signatures from organisation officials must meet the following requirements
+    i.   as legally specified for the type of organisation
+    ii.  as specified in the official documents (f.e. the excerpt from the register)
+    iii. as delegated within the organisation (proof of delegation needed)