From 9fbb6d5ba789b66d05cd9a328c11baea394ec2a5 Mon Sep 17 00:00:00 2001 From: Ian Grigg Date: Wed, 1 Sep 2010 09:56:50 +0000 Subject: [PATCH] committed the blue into black, from Ulrich. git-svn-id: http://svn.cacert.org/CAcert/Policies@2017 14b1bab8-4ef6-0310-b690-991c95c89dfd --- TTPAssistedAssurancePolicy.html | 291 ++++++++++++++------------------ 1 file changed, 126 insertions(+), 165 deletions(-) diff --git a/TTPAssistedAssurancePolicy.html b/TTPAssistedAssurancePolicy.html index e179e86..0ef4c3b 100644 --- a/TTPAssistedAssurancePolicy.html +++ b/TTPAssistedAssurancePolicy.html @@ -38,11 +38,11 @@ CAcert Policy Status Editor: Iang
Creation Date : 20091215
- Status: WIP 20100705
- Licence: CC-by-sa/DRP
+ Status: WIP 2010901
+ Licence: CC-by-sa+DRP

-

0. Preliminaries

+

0. Preliminaries

This sub-policy extends the @@ -50,25 +50,21 @@ by specifying how Assurers can be assisted by outsourcing the identity documents verification component of assurance to trusted third parties (TTPs). - Definitions can be found in AP or in Assurance Handbook ("AH"). -

-

1. Scope

+

1. Scope

This sub-policy is restricted to members located in areas not well-served with Assurers. - It serves a goal of promoting both Assurers and Members is those areas. -

-

2. Roles

+

2. Roles

-

2.1 Trusted Third Party

+

2.1 Trusted Third Party

A Trusted Third Party ("TTP") is a person who is traditionally respected for making reliable statements to others, especially over identification @@ -76,24 +72,12 @@ Notaries (European), bank managers, accountants and lawyers.

-

- The Board maintains a list of approved classes of TTP - and forms of documents. - The list is expected to vary according to the - different juridical traditions of different regions. -

-

2.2 The Assurer (aka TTP-admin)

+

2.2 The Assurer (aka TTP-admin)

uli: (Synonyms: TTP-Assurer, TTP-Admin)

To employ a TTP in an assurance, - the Assurer must - - be a Senior Assurer. - - - have 50 experience points, and pass other checks as imposed by the Board from time to time. - + the Assurer must be a Senior Assurer. The Assurer must be familiar with the local language and customs.

@@ -104,20 +88,19 @@ -

2.3 Member

+

2.3 Member

A Member ("assuree") who is located in a place not well-served by Assurers may use the TTP-assisted Assurance.

-

3. The Assurance

+

3. The Assurance

-

Iang: I suggest this be section 3:

-

+

Assurance assisted by TTP must meet these requirements:

-
  1. +
    1. The Assurer must positively confirm the identity and suitability of the TTP.
    2. @@ -128,21 +111,129 @@ The Assurer makes a reliable statement to confirm the Assurance Statement.
    3. - Assurance must be marked as TTP-Assisted (e.g., by use of TTPAdmin flag). -
    -

    And all the rest in pink box be pushed into the HANDBOOK. This way, the policy sets requirements and standards, and AO is responsible for meeting them as a PRACTICE.

    + +

    See Appendix A for example text for Handbook text.

    + +

    4. Assurance Officer ("AO")

    +

    + The Board routinely delegates its responsibilities to the + Assurance Officer (and this section assumes that, but does + not require it). +

    + +

    + A report is requested annually from the Assurance Officer + on performance of this policy for the association's + annual report. +

    +

    4.1 Practice

    +

    + Assurance Officer should prepare + a detailed documentation under + AH + that meets the needs of this policy, including: +

    +
    • + Form for TTPs +
    • + Guide for TTPs. +
    • + Form for TTP-assisted assurance (used by Assurer) +
    • + Guide and protocol + (Appendix A below) + for Assurers. +
    • + Mechanisms for contacting Assurers available for + TTP-assisted Assurances. +
    • + Definition of + + Senior Assurer. +
    + +

    4.2 Deserts

    +

    + The Assurance Officer maintains a list of regions + that are designated as 'deserts,' being areas that are so short + of Assurers as to render face-to-face Assurance impractical. + In each region, approved types of TTP are listed (e.g., Notary). + The list is expected to vary according to the + different juridical traditions of different regions. + Changes to the regional lists are prepared by + either an Organisation Assurer for that region + (as described by OAP) + or by two Assurers familiar with the traditions + in that region. + Changes are then submitted to the Board for approval. +

    +

    + Use of a type of TTP not on the list must be approved by + AO and notified to Board. + It is an explicit goal to reduce the usage of + TTP-assisted Assurances in favour of face-to-face Assurance. +

    + +

    + In coordination with internal and external auditors, + the Assurance Officer shall design and implement a + suitable programme to meet the needs of audit. + Where approved by auditors or Board, the Assurance + Officer may document and implement minor variations to this policy. +

    + +

    5. Topup Assurance Points

    + +

    + AO is to operate a topup Assurance programme + to help seed desert areas with Assurers. +

    + +

    + A topup Assurance is conducted by a third Senior Assurer + according to the following requirements: +

    + +
    1. + Assurer must be a Senior Assurer. +
    2. + Assurer Challenge must be completed as passed by Member. +
    3. + The topup must be requested by Member for purpose of enabling the Member to reach Assurer level. +
    4. + The two TTP-Assisted Assurances already conducted are to be reviewed. +
    5. + Topup may award up to 35 points. +
    6. + Assurance must be marked as Topup + (e.g., by use of new feature with TTPAdmin flag). +
  2. + +

    + Each topup is to be reported to AO. + Topup is only available in designated deserts. +

    + +
    + +

    Appendix A - Handbook text, not for policy

    +

    + This pink part into the HANDBOOK when it goes to DRAFT, not part of policy!
    + This way, the policy sets requirements and standards,
    + and AO is responsible for meeting them as a PRACTICE. +

    These steps are taken.

    -

    3.1 Preliminaries

    +

    3.1 Preliminaries

    1. The Member creates her account @@ -163,9 +254,7 @@

    2. The Assurer confirms that standard Assurances do not meet the needs of the Member. - This is only likely in areas not well-served with Assurers. -

    3. @@ -180,7 +269,7 @@ and gives the Member a Token.

    -

    3.2 Face-to-face meeting with the TTP

    +

    3.2 Face-to-face meeting with the TTP

    1. The TTP and the Member meet face-to-face. @@ -231,7 +320,7 @@

    -

    3.3 Completion of the Assurance

    +

    3.3 Completion of the Assurance

    1. The Assurer must confirm the assurance using the paperwork, @@ -283,133 +372,5 @@

    -

    4. Assurance Officer ("AO")

    -

    - The Board routinely delegates its responsibilities to the - Assurance Officer (and this section assumes that, but does - not require it). -

    - -

    - A report is requested annually from the Assurance Officer - on performance of this policy for the association's - annual report. -

    -

    4.1 Practice

    -

    - Assurance Officer should prepare - - a detailed documentation under - AH - that meets the needs of this policy, including: - - - documentation - to support the TTP-assisted Assurance, including: - -

    - - -

    4.2 Deserts

    -

    - - The Assurance Officer maintains a list of regions - that are designated as 'deserts,' being areas that are so short - of Assurers as to render face-to-face Assurance impractical. - In each region, approved types of TTP are listed (e.g., Notary). - The list is expected to vary according to the - different juridical traditions of different regions. - - Changes to the regional lists are prepared by - either an Organisation Assurer for that region - (as described by OAP) - or by two Assurers familiar with the traditions - in that region. - Changes are then submitted to the Board for approval. -

    -

    - Use of a type of TTP not on the list must be approved by - - AO and notified to - - Board. - - It is an explicit goal to reduce the usage of - TTP-assisted Assurances in favour of face-to-face Assurance. - -

    - -

    - In coordination with internal and external auditors, - the Assurance Officer shall design and implement a - suitable programme to meet the needs of audit. - Where approved by auditors or Board, the Assurance - Officer may document and implement minor variations to this policy. -

    - -

    5. Topup Assurance Points

    - - - - -

    -AO is to operate a topup Assurance programme -to help seed desert areas with Assurers. -

    - -

    -A topup Assurance is conducted by a third Senior Assurer -according to the following requirements: -

    - -
    1. - Assurer must be a Senior Assurer. -
    2. - Assurer Challenge must be completed as passed by Member. -
    3. - The topup must be requested by Member for purpose of enabling the Member to reach Assurer level. -
    4. - The two TTP-Assisted Assurances already conducted are to be reviewed. -
    5. - Topup may award up to 35 points. -
    6. - Assurance must be marked as Topup - (e.g., by use of new feature with TTPAdmin flag). -
    - -

    -Each topup is to be reported to AO. -Topup is only available in designated deserts. -

    -