Singapore legislation
Regulation 23
of Electronic Transactions (Certification Authority) Regulations 2010
Regulation 23
Compliance Audit Checklist
Subregulation 1
Every accredited certification authority must ensure that in the performance of its services it materially satisfies the Compliance Audit Checklist determined by the Controller and published on the Controller’s Internet website.
Subregulation 2
An auditor, when determining whether a departure from the Compliance Audit Checklist is material, must exercise reasonable professional judgment as to whether a condition that does not strictly comply with the Compliance Audit Checklist is or is not material, taking into consideration the circumstances and the system as a whole.
Subregulation 3
Without limiting the situations which the auditor may consider to be material, the following incidents of non‑compliance are to be considered to be material:
any non‑compliance relating to the validity of a certificate;
the performance of the functions of a trusted person by a person who is not suitably qualified;
the use by an accredited certification authority of any system other than a trustworthy system.
Subregulation 4
The Compliance Audit Checklist must be interpreted in a manner that is reasonable in relation to the context in which a system is used and is consistent with law.
Subregulation 5
Despite an auditor’s assessment of whether a departure from the Compliance Audit Checklist is material, the Controller may make his or her own assessment and reach a conclusion for the purpose of paragraph (1) which is at variance with that of the auditor.
Subregulation 6
Every accredited certification authority must provide every subscriber with a trustworthy system to generate his or her key pair.
Subregulation 7
Every accredited certification authority must provide the mechanism to generate and verify digital signatures in a trustworthy manner and the mechanism provided must also indicate the validity of the signature.
Subregulation 8
If the digital signature is not valid, the mechanism provided should indicate if the invalidity is due to the integrity of the document or the signature and the mechanism provided must also indicate the status of the certificate.
Subregulation 9
For mechanisms provided by third parties other than the accredited certification authority, the resulting signature is considered secure only if the accredited certification authority endorses the implementation of such mechanisms in conjunction with its certificate.
Subregulation 10
Every accredited certification authority is responsible for the storage of keys (including the subscriber’s key and the accredited certification authority’s own key) in a trustworthy manner.
Subregulation 11
The Controller may publish on its Internet website further details of the Compliance Audit Checklist for compliance by every accredited certification authority.