Assurance frameworks

Policies and practices

Define the legal, technical, operational and business rules that govern a trust service and the practices used to meet them.

Make the operating rules explicit

Policies define the legal, technical, operational and business rules by which a trust service operates. They can also provide a reference against which the service is reviewed, audited or assessed where an applicable scheme or standard calls for it.

Certificate policies and practice statements

Trust services based on issuing and managing digital certificates are commonly described through a Certificate Policy (CP). It identifies the participants and the rules governing the service. The supporting operational practices are normally described in a Certification Practice Statement (CPS).

These documents help stakeholders and assessors understand both the rules a service claims to follow and the practices used to meet them.

Beyond certificate issuance

Policy and practice documents may also be needed for services such as electronic time stamping, signature creation, signature validation, signature augmentation and remote hardware security module management. The required structure and level of detail depend on the service, its risk profile and the applicable standards or rules.

Talk through the requirement

Need a clearer route forward?

Start with the business process, the assurance you need and the questions that are blocking progress.

Contact TrustAssert