"Exchange OA policy in the WebDB with the one in SVN (rev p20080401.1)"
This commit is contained in:
parent
88446afac4
commit
825953e6b4
1 changed files with 83 additions and 60 deletions
|
@ -1,54 +1,51 @@
|
||||||
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
|
<?='<?xml version="1.0" encoding="utf-8"?>'?>
|
||||||
|
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
|
||||||
|
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
|
||||||
|
<html xmlns="http://www.w3.org/1999/xhtml">
|
||||||
|
<head>
|
||||||
|
<title> Organisation Assurance Policy </title>
|
||||||
|
<style type="text/css">
|
||||||
|
<!--
|
||||||
|
.comment {
|
||||||
|
color : steelblue;
|
||||||
|
}
|
||||||
|
-->
|
||||||
|
</style>
|
||||||
|
|
||||||
<html>
|
</head>
|
||||||
<head><title>Organisation Assurance Policy</title></head>
|
|
||||||
<body>
|
<body>
|
||||||
|
|
||||||
|
<div class="comment">
|
||||||
<table width="100%">
|
<table width="100%">
|
||||||
|
|
||||||
<tr>
|
<tr>
|
||||||
<td> OAP </td>
|
|
||||||
<td> </td>
|
|
||||||
<td width="20%"> Jens </td>
|
|
||||||
</tr>
|
|
||||||
|
|
||||||
<tr>
|
|
||||||
<td> POLICY <a href="http://wiki.cacert.org/wiki/TopMinutes-20070917">m20070918.x</a> </td>
|
|
||||||
<td> </td>
|
|
||||||
<td>
|
<td>
|
||||||
$Date: 2008/01/18 22:56:31 $
|
Name: OAP <a style="color: steelblue" href="//svn.cacert.org/CAcert/Policies/ControlledDocumentList.html">COD11</a><br />
|
||||||
<!--
|
|
||||||
to get this to work, we have to do this:
|
Status: POLICY/DRAFT <a style="color: steelblue" href="//wiki.cacert.org/wiki/TopMinutes-20070917">m20070918.x </a><br />
|
||||||
svn propset svn:keywords "Date" file.html
|
|
||||||
except it does not work through the website.
|
<span class="draftadd">DRAFT p20080401.1 </span> <br />
|
||||||
-->
|
Editor: Jens Paul <br />
|
||||||
|
Licence: <a style="color: steelblue" href="//wiki.cacert.org/Policy#Licence" title="this document is Copyright © CAcert Inc., licensed openly under CC-by-sa with all disputes resolved under DRP. More at wiki.cacert.org/Policy" > CC-by-sa+DRP </a><br /></td>
|
||||||
|
<td valign="top" align="right">
|
||||||
|
<a href="//www.cacert.org/policy/PolicyOnPolicy.html"><img src="/images/cacert-policy.png" alt="OAP Status - POLICY" height="31" width="88" style="border-style: none;" /></a><br />
|
||||||
|
<a href="//www.cacert.org/policy/PolicyOnPolicy.html"><img src="/images/cacert-draft.png" alt="OAP Status - DRAFT" height="31" width="88" style="border-style: none;" /></a>
|
||||||
|
|
||||||
</td>
|
</td>
|
||||||
</tr>
|
</tr>
|
||||||
|
|
||||||
<tr>
|
|
||||||
<td> COD11 </td>
|
|
||||||
<td> </td>
|
|
||||||
<td> </td>
|
|
||||||
</tr>
|
|
||||||
|
|
||||||
|
|
||||||
<tr>
|
|
||||||
<td> </td>
|
|
||||||
<td > <b>Organisation Assurance Policy</b> </td>
|
|
||||||
<td> </td>
|
|
||||||
</tr>
|
|
||||||
|
|
||||||
</table>
|
</table>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
|
||||||
|
<h1> Organisation Assurance Policy </h1>
|
||||||
|
|
||||||
<h2> <a name="0"> 0. </a> Preliminaries </h2>
|
<h2 id="s0">0. Preliminaries </h2>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
This policy describes how Organisation Assurers ("OAs")
|
This policy describes how Organisation Assurers ("OAs")
|
||||||
conduct Assurances on Organisations.
|
conduct Assurances on Organisations.
|
||||||
It fits within the overall web-of-trust
|
It fits within the overall web-of-trust
|
||||||
or Assurance process of Cacert.
|
or Assurance process of CAcert.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
|
@ -56,7 +53,7 @@ This policy is not a Controlled document, for purposes of
|
||||||
Configuration Control Specification ("CCS").
|
Configuration Control Specification ("CCS").
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<h2> <a name="1"> 1. </a> Purpose </h2>
|
<h2 id="s1"> 1. Purpose </h2>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
Organisations with assured status can issue certificates
|
Organisations with assured status can issue certificates
|
||||||
|
@ -76,27 +73,31 @@ and as described in the CPS.
|
||||||
to this policy.
|
to this policy.
|
||||||
</li><li>
|
</li><li>
|
||||||
The organisation is within the jurisdiction
|
The organisation is within the jurisdiction
|
||||||
and can be taken to Arbitration.
|
and can be taken to CAcert Arbitration.
|
||||||
</li></ul>
|
</li></ul>
|
||||||
|
|
||||||
|
|
||||||
<h2> <a name="2"> 2. </a> Roles and Structure </h2>
|
<h2 id="s2"> 2. Roles and Structure </h2>
|
||||||
|
|
||||||
<h3> <a name="2.1"> 2.1 </a> Assurance Officer </h3>
|
<h3 id="s2.1"> 2.1 Assurance Officer </h3>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
The Assurance Officer ("AO")
|
The Assurance Officer ("AO")
|
||||||
manages this policy and reports to the board.
|
manages this policy and reports to the CAcert Inc. Committee ("Board").
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
The AO manages all OAs and is responsible for process,
|
The AO manages all OAs and is responsible for process,
|
||||||
the CAcert Organisation Assurance Programme form ("COAP"),
|
the CAcert Organisation Assurance Programme ("COAP") form,
|
||||||
OA training and testing, manuals, quality control.
|
OA training and testing, manuals, quality control.
|
||||||
In these responsibilities, other Officers will assist.
|
In these responsibilities, other Officers will assist.
|
||||||
</p>
|
</p>
|
||||||
|
<p>
|
||||||
|
The OA is appointed by the Board.
|
||||||
|
Where the OA is failing the Board decides.
|
||||||
|
</p>
|
||||||
|
|
||||||
<h3> <a name="2.2"> 2.2 </a> Organisation Assurers </h3>
|
<h3 id="s2.2"> 2.2 Organisation Assurers </h3>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
</p>
|
</p>
|
||||||
|
@ -141,11 +142,30 @@ In these responsibilities, other Officers will assist.
|
||||||
as supervised, trained and tested.
|
as supervised, trained and tested.
|
||||||
</li>
|
</li>
|
||||||
</ol>
|
</ol>
|
||||||
|
</li>
|
||||||
|
<li>The OA can decide when a CAcert
|
||||||
|
(individual) Assurer
|
||||||
|
has done several OA Application Advises to appoint this
|
||||||
|
person to OA Assurer.
|
||||||
|
</li>
|
||||||
|
|
||||||
</ol>
|
</ol>
|
||||||
|
|
||||||
|
<h3 id="s2.3"> 2.3 Organisation Assurance Advisor ("OAA") </h3>
|
||||||
|
<p>In countries/states/provinces where no OA Assurers are
|
||||||
|
operating for an OA Application (COAP) the OA
|
||||||
|
can be advised by an experienced local CAcert
|
||||||
|
(individual) Assurer to take the decision
|
||||||
|
to accept the OA Application (COAP) of the organisation.
|
||||||
|
</p>
|
||||||
|
<p>
|
||||||
|
The local Assurer must have at least 150 Points,
|
||||||
|
should know the language, and know
|
||||||
|
the organisation trade office registry culture and quality.
|
||||||
|
</p>
|
||||||
|
|
||||||
|
|
||||||
<h3> <a name="2.3"> 2.3 </a> Organisation Administrator </h3>
|
<h3 id="s2.4"> 2.4 Organisation Administrator </h3>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
The Administrator within each Organisation ("O-Admin")
|
The Administrator within each Organisation ("O-Admin")
|
||||||
|
@ -175,9 +195,9 @@ and the issuing of certificates.
|
||||||
</ol>
|
</ol>
|
||||||
|
|
||||||
|
|
||||||
<h2> <a name="3"> 3. </a> Policies </h2>
|
<h2 id="s3"> 3. Policies </h2>
|
||||||
|
|
||||||
<h3> <a name="3.1"> 3.1 </a> Policy </h3>
|
<h3 id="s3.1"> 3.1 Policy </h3>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
There is one policy being this present document,
|
There is one policy being this present document,
|
||||||
|
@ -191,7 +211,7 @@ and several subsidiary policies.
|
||||||
<li> Organisations are assured under an appropriate subsidiary policy. </li>
|
<li> Organisations are assured under an appropriate subsidiary policy. </li>
|
||||||
</ol>
|
</ol>
|
||||||
|
|
||||||
<h3> <a name="3.2"> 3.2 </a> Subsidiary Policies </h3>
|
<h3 id="s3.2"> 3.2 Subsidiary Policies </h3>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
The nature of the Subsidiary Policies ("SubPols"):
|
The nature of the Subsidiary Policies ("SubPols"):
|
||||||
|
@ -210,7 +230,7 @@ The nature of the Subsidiary Policies ("SubPols"):
|
||||||
</li><li>
|
</li><li>
|
||||||
For OAs,
|
For OAs,
|
||||||
SubPol specifies the <i>tests of local knowledge</i>
|
SubPol specifies the <i>tests of local knowledge</i>
|
||||||
including the local organisational forms.
|
including the local organisation assurance COAP forms.
|
||||||
</li><li>
|
</li><li>
|
||||||
For assurances,
|
For assurances,
|
||||||
SubPol specifies the <i>local documentation forms</i>
|
SubPol specifies the <i>local documentation forms</i>
|
||||||
|
@ -221,7 +241,7 @@ The nature of the Subsidiary Policies ("SubPols"):
|
||||||
policy approval process.
|
policy approval process.
|
||||||
</li></ol>
|
</li></ol>
|
||||||
|
|
||||||
<h3> <a name=""> </a> 3.3 Freedom to Assemble </h3>
|
<h3 id="s3.3"> 3.3 Freedom to Assemble </h3>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
Subsidiary Policies are open, accessible and free to enter.
|
Subsidiary Policies are open, accessible and free to enter.
|
||||||
|
@ -254,9 +274,9 @@ Subsidiary Policies are open, accessible and free to enter.
|
||||||
</li></ol>
|
</li></ol>
|
||||||
|
|
||||||
|
|
||||||
<h2> <a name="4"> 4. </a> Process </h2>
|
<h2 id="s4"> 4. Process </h2>
|
||||||
|
|
||||||
<h3> <a name="4.1"> 4.1 </a> Standard of Organisation Assurance </h3>
|
<h3 id="s4.1"> 4.1 Standard of Organisation Assurance </h3>
|
||||||
<p>
|
<p>
|
||||||
The essential standard of Organisation Assurance is:
|
The essential standard of Organisation Assurance is:
|
||||||
</p>
|
</p>
|
||||||
|
@ -276,7 +296,7 @@ The essential standard of Organisation Assurance is:
|
||||||
requestor can sign on behalf of the organisation.
|
requestor can sign on behalf of the organisation.
|
||||||
</li><li>
|
</li><li>
|
||||||
the organisation has agreed to the terms of the
|
the organisation has agreed to the terms of the
|
||||||
Registered User Agreement,
|
CAcert Community Agreement
|
||||||
and is therefore subject to Arbitration.
|
and is therefore subject to Arbitration.
|
||||||
</li></ol>
|
</li></ol>
|
||||||
|
|
||||||
|
@ -285,7 +305,7 @@ The essential standard of Organisation Assurance is:
|
||||||
are stated in the SubPol.
|
are stated in the SubPol.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<h3> <a name="4.2"> 4.2 </a> COAP </h3>
|
<h3 id="s4.2"> 4.2 COAP </h3>
|
||||||
<p>
|
<p>
|
||||||
The COAP form documents the checks and the resultant
|
The COAP form documents the checks and the resultant
|
||||||
assurance results to meet the standard.
|
assurance results to meet the standard.
|
||||||
|
@ -302,12 +322,13 @@ Additional information to be provided on form:
|
||||||
<li>additional contact information (as required by SubPol).</li>
|
<li>additional contact information (as required by SubPol).</li>
|
||||||
</ol>
|
</ol>
|
||||||
</li><li>
|
</li><li>
|
||||||
administrator account names (1 or more)
|
administrator account name(s) (1 or more)
|
||||||
</li><li>
|
</li><li>
|
||||||
domain name(s)
|
domain name(s)
|
||||||
</li><li>
|
</li><li>
|
||||||
Agreement with registered user agreement.
|
Agreement with
|
||||||
Statement and initials box for organsation
|
CAcert Community Agreement.
|
||||||
|
Statement and initials box for organisation
|
||||||
and also for OA.
|
and also for OA.
|
||||||
</li><li>
|
</li><li>
|
||||||
Date of completion of Assurance.
|
Date of completion of Assurance.
|
||||||
|
@ -322,17 +343,17 @@ and indication provided that the English is the
|
||||||
ruling language (due to Arbitration requirements).
|
ruling language (due to Arbitration requirements).
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<h3> <a name="4.3"> 4.3 </a> Jurisdiction </h3>
|
<h3 id="s4.3"> 4.3 Jurisdiction </h3>
|
||||||
|
|
||||||
<p>
|
<p>
|
||||||
Organisation Assurances are carried out by
|
Organisation Assurances are carried out by
|
||||||
CAcert Inc under its Arbitration jurisdiction.
|
CAcert Inc. under its Arbitration jurisdiction.
|
||||||
Actions carried out by OAs are under this regime.
|
Actions carried out by OAs are under this regime.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<ol type="a"><li>
|
<ol type="a"><li>
|
||||||
The organisation has agreed to the terms of the
|
The organisation has agreed to the terms of the
|
||||||
Registered User Agreement,
|
CAcert Community Agreement.
|
||||||
</li><li>
|
</li><li>
|
||||||
The organisation, the Organisation Assurers, CAcert and
|
The organisation, the Organisation Assurers, CAcert and
|
||||||
other related parties are bound into CAcert's jurisdiction
|
other related parties are bound into CAcert's jurisdiction
|
||||||
|
@ -340,12 +361,13 @@ Actions carried out by OAs are under this regime.
|
||||||
</li><li>
|
</li><li>
|
||||||
The OA is responsible for ensuring that the
|
The OA is responsible for ensuring that the
|
||||||
organisation reads, understands, intends and
|
organisation reads, understands, intends and
|
||||||
agrees to the registered user agreement.
|
agrees to the
|
||||||
|
CAcert Community Agreement.
|
||||||
This OA responsibility should be recorded on COAP
|
This OA responsibility should be recorded on COAP
|
||||||
(statement and initials box).
|
(statement and initials box).
|
||||||
</li></ol>
|
</li></ol>
|
||||||
|
|
||||||
<h2> <a name="5"> 5. </a> Exceptions </h2>
|
<h2 id="s5"> 5. Exceptions </h2>
|
||||||
|
|
||||||
|
|
||||||
<ol type="a"><li>
|
<ol type="a"><li>
|
||||||
|
@ -376,4 +398,5 @@ Actions carried out by OAs are under this regime.
|
||||||
This means that the anglo law tradition of unregistered DBAs
|
This means that the anglo law tradition of unregistered DBAs
|
||||||
is not accepted without further proof.
|
is not accepted without further proof.
|
||||||
</li></ol>
|
</li></ol>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
|
|
Loading…
Reference in a new issue