Singapore legislation

Regulation 34

of Electronic Transactions (Certification Authority) Regulations 2010

Regulation 34

Audit

Subregulation 1

The Controller may, by written notice, require an accredited certification authority to undergo and pass an audit.

Subregulation 2

The audit mentioned in paragraph (1) must be —

(a)

conducted in accordance with the auditing requirements specified in this regulation; and

(b)

completed within the time that the Controller may, by written notice, specify.

Subregulation 3

The audit must be conducted by a qualified independent audit team approved by the Controller for this purpose comprising a person who is a Certified Public Accountant and a person who is a Certified Information Systems Auditor and either of whom must possess sufficient knowledge of digital signatures and certificates.

Subregulation 4

The firm or company to which the audit team belongs must be independent of the certification authority being audited and must not be a software or hardware vendor that is providing or has provided services or is supplying or has supplied equipment to the certification authority.

Subregulation 5

Auditing fees must be borne by the certification authority.

Subregulation 6

A copy of the audit report must be submitted to the Controller within 4 weeks of the completion of an audit.