Singapore legislation
Regulation 14
of Electronic Transactions (Certification Authority) Regulations 2010
Regulation 14
Trustworthy transaction logs
Subregulation 1
Every accredited certification authority must make and keep in a trustworthy manner the records relating to —
activities in issuance, renewal, suspension and revocation of certificates, including the process of identification of any person requesting a certificate from an accredited certification authority;
the process of generating subscribers’ (where applicable) or the accredited certification authority’s own key pairs;
the administration of an accredited certification authority’s computing facilities; and
any critical related activity of an accredited certification authority that may be determined by the Controller.
Subregulation 2
Every accredited certification authority must archive all certificates issued by it and maintain mechanisms to access the certificates for at least 7 years.
Subregulation 3
Every accredited certification authority must retain all records required to be kept under paragraph (1) and all logs of the creation of the archive of certificates mentioned in paragraph (2) for at least 7 years.