/akn/sg/act/sub_leg/2010/ETA-RG1

Electronic Transactions (Certification Authority) Regulations 2010

The full official text, structured for quick navigation. Copy any provision or jump straight to a section.

Open source PDF
Type
Subsidiary Legislation
Status
In force
Enacted
2010
Sections
36

Quick answer

About this subsidiary legislation

Electronic Transactions (Certification Authority) Regulations 2010 is Singapore Subsidiary Legislation, cited as Subsidiary Legislation ETA-RG1 2010, currently marked in force and first recorded in 2010.

Part 1

PRELIMINARY

Regulation 1

Citation

Open as pageSuggest a correction

These Regulations are the Electronic Transactions (Certification Authority) Regulations 2010.

Regulation 2

Definitions

Open as pageSuggest a correction

In these Regulations —“accreditation” means accreditation granted under these Regulations;“accredited certification authority” means a certification authority that is accredited under these Regulations;“accreditation mark” means an accreditation mark as set out in the Schedule;“subscriber identity verification method” means the method used to verify and authenticate the identity of a subscriber;“trusted person” means any person who has —

(a)

direct responsibilities for the day‑to‑day operations, security and performance of those business activities that are regulated under the Act or these Regulations in respect of a certification authority; or

(b)

duties directly involving the issuance, renewal, suspension, revocation of certificates (including the identification of any person requesting a certificate from an accredited certification authority), creation of private keys or administration of a certification authority’s computing facilities.

Definition

“accreditation” means accreditation granted under these Regulations;

Suggest a correction

Definition

“accredited certification authority” means a certification authority that is accredited under these Regulations;

Suggest a correction

Definition

“accreditation mark” means an accreditation mark as set out in the Schedule;

Suggest a correction

Definition

“subscriber identity verification method” means the method used to verify and authenticate the identity of a subscriber;

Suggest a correction

Definition

“trusted person” means any person who has —

(a)

direct responsibilities for the day‑to‑day operations, security and performance of those business activities that are regulated under the Act or these Regulations in respect of a certification authority; or

(b)

duties directly involving the issuance, renewal, suspension, revocation of certificates (including the identification of any person requesting a certificate from an accredited certification authority), creation of private keys or administration of a certification authority’s computing facilities.

Suggest a correction

Part 2

ACCREDITATION OF CERTIFICATION AUTHORITIES

Regulation 3

Application to be accredited certification authority

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Every application to be an accredited certification authority must be made in the form and manner that the Controller may determine and must be supported by —

(a)

the certification practice statement of the certification authority;

(b)

an audit report prepared in accordance with regulations 23 and 34 for compliance with the Compliance Audit Checklist published on the Controller’s Internet website; and

(c)

any information that the Controller may require.

Subregulation 2

Suggest a correction

Upon submitting an application for accreditation, the applicant must pay to the Controller an application fee of $1,000.

Subregulation 3

Suggest a correction

The Controller must, in the form that the Controller may determine, notify the applicant as to whether the application is successful.

Subregulation 4

Suggest a correction

Upon notification that the application is successful, the applicant must pay to the Controller an accreditation fee of $1,000 and, subject to regulation 5, the Controller must grant accreditation to the applicant as an accredited certification authority upon the payment.

Subregulation 5

Suggest a correction

The accreditation is subject to any conditions or restrictions that the Controller may determine.

Subregulation 6

Suggest a correction

The accreditation is valid for 2 years unless cancelled or suspended under the Act or these Regulations.

Subregulation 7

Suggest a correction

The Controller must not refund any fee paid under this regulation if the application is unsuccessful, withdrawn or discontinued, or if the accreditation is cancelled or suspended.

Regulation 4

Renewal of accreditation

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Regulation 3 (with the exception of paragraph (2)) applies, with the necessary modifications, to an application for renewal of accreditation under this regulation as it applies to an application for accreditation under regulation 3.

Subregulation 2

Suggest a correction

The Controller may allow applications for renewal of accreditation to be submitted in the form of electronic records subject to any requirements that the Controller may impose.

Subregulation 3

Suggest a correction

If an accredited certification authority intends to renew its accreditation, the certification authority must submit an application for the renewal of its accreditation not later than 3 months before the expiry of its accreditation.

Subregulation 4

Suggest a correction

If an application for renewal is made later than the time prescribed in paragraph (3), the application is deemed to be an application under regulation 3 and the application fee prescribed in regulation 3(2) is payable.

Subregulation 5

Suggest a correction

If the certification authority does not intend to renew its accreditation, the certification authority must —

(a)

inform the Controller in writing not later than 3 months before the expiry of the accreditation;

(b)

inform all its subscribers in writing not later than 2 months before the expiry of the accreditation; and

(c)

advertise such intention in such daily newspapers and in such manner as the Controller may determine, not later than 2 months before the expiry of the accreditation.

Part 3

REFUSAL, CANCELLATION AND SUSPENSION OF ACCREDITATION

Regulation 5

Refusal to grant or renew accreditation

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

The Controller may refuse to grant or renew an accreditation if —

(a)

the applicant has not complied with any requirement in the Act or these Regulations;

(b)

the applicant has not provided the Controller with any information relating to it or any person employed by or associated with it for the purposes of its business, and to any circumstances likely to affect its method of conducting business, that the Controller may require;

(c)

the applicant or its substantial shareholder is in the course of being wound up or liquidated;

(d)

a receiver or a receiver and manager has been appointed to the applicant or its substantial shareholder;

(e)

the applicant or its substantial shareholder has, whether in Singapore or elsewhere, entered into a compromise or scheme of arrangement with its creditors, being a compromise or scheme of arrangement that is still in operation;

(f)

the applicant or its substantial shareholder or any trusted person has been convicted, whether in Singapore or elsewhere, of an offence the conviction for which involved a finding that it, he or she acted fraudulently or dishonestly, or has been convicted of an offence under the Act or these Regulations;

(g)

the Controller is not satisfied as to the qualifications or experience of the trusted person who is to perform duties in connection with the accreditation of the applicant;

(h)

the applicant fails to satisfy the Controller that it is a fit and proper person to be accredited or that all its trusted persons and substantial shareholders are fit and proper persons;

(i)

the Controller has reason to believe that the applicant may not be able to act in the best interest of its subscribers, customers or participants having regard to the reputation, character, financial integrity and reliability of the applicant or any of its substantial shareholders or trusted persons;

(j)

the Controller is not satisfied as to the financial standing of the applicant or its substantial shareholder;

(k)

the Controller is not satisfied as to the record of past performance or expertise of the applicant or its trusted person having regard to the nature of the business which the applicant may carry on in connection with the accreditation;

(l)

there are other circumstances which are likely to lead to the improper conduct of business by, or reflect discredit on the method of conducting the business of, the applicant or its substantial shareholder or any of the trusted persons; or

(m)

the Controller is of the opinion that it is in the interest of the public to do so.

Subregulation 2

Suggest a correction

In paragraph (1), “substantial shareholder”, in relation to an applicant which is a company, has the meaning given by the Companies Act 1967.

Regulation 6

Cancellation or suspension of accreditation

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

An accreditation is deemed to be cancelled if the certification authority is wound up.

Subregulation 2

Suggest a correction

The Controller may cancel or suspend the accreditation of a certification authority —

(a)

on any ground on which the Controller may refuse to grant an accreditation under regulation 5;

(b)

if any information furnished in support of the application for the accreditation was false, misleading or inaccurate;

(c)

if the certification authority fails to undergo or pass an audit required under regulation 34;

(d)

if the certification authority fails to comply with a direction of the Controller made under section 23 of the Act;

(e)

if the certification authority is being or will be wound up;

(f)

if the certification authority has entered into any composition or arrangement with its creditors; (g)if the certification authority fails to carry on business for which it was accredited;

(h)

if the Controller has reason to believe that the certification authority or its trusted person has not performed its, his or her duties efficiently, honestly or fairly; or

(i)

if the certification authority fails to comply with any condition or restriction applicable in respect of the accreditation.

Subregulation 3

Suggest a correction

The Controller may cancel the accreditation of a certification authority at the request of that certification authority.

Subregulation 4

Suggest a correction

The Controller must not cancel the accreditation under paragraph (2) without first giving the certification authority an opportunity of being heard.

Regulation 7

Inquiry into allegations of misconduct, etc.

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

The Controller may inquire into any allegation that a certification authority, or an officer or employee of a certification authority, is or has been guilty of any misconduct or is no longer fit to continue to remain accredited by reason of any other circumstances which have led, or are likely to lead, to the improper conduct of business by it or to reflect discredit on the method of conducting business.

Subregulation 2

Suggest a correction

If, after inquiring into an allegation under paragraph (1), the Controller is of the opinion that the allegation is proved, the Controller may if he or she thinks fit —

(a)

cancel the accreditation of the certification authority;

(b)

suspend the accreditation of the certification authority for any period, or until the happening of any event, that the Controller may determine; or

(c)

reprimand the certification authority.

Subregulation 3

Suggest a correction

The Controller must, at the hearing of an inquiry into an allegation under paragraph (1) against a certification authority, give the certification authority an opportunity of being heard.

Subregulation 4

Suggest a correction

Where the Controller is satisfied, after making an inquiry into an allegation under paragraph (1), that the allegation has been made in bad faith or that it is otherwise frivolous or vexatious, the Controller may, by written order, require the person who made the allegation to pay any costs and expenses involved in the inquiry.

Subregulation 5

Suggest a correction

The Controller may issue directions to the certification authority for compliance under section 23 of the Act as a result of making the inquiry.

Subregulation 6

Suggest a correction

For the purposes of this regulation, “misconduct” means —

(a)

any failure to comply with the requirements of the Act or these Regulations or the certification practice statement of the certification authority concerned; and

(b)

any act or omission relating to the conduct of business of the certification authority concerned which is or is likely to be prejudicial to public interest.

Regulation 8

Effect of cancellation or suspension of accreditation

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

A certification authority whose accreditation is cancelled or suspended under regulation 6 or 7 is deemed, for the purposes of the Act and these Regulations, not to be accredited from the date that the Controller cancels or suspends the accreditation, as the case may be.

Subregulation 2

Suggest a correction

The cancellation or suspension of the accreditation of a certification authority does not operate so as to —

(a)

avoid or affect any agreement, transaction or arrangement entered into by the certification authority, whether the agreement, transaction or arrangement was entered into before or after the cancellation or suspension of the accreditation; or

(b)

affect any right, obligation or liability arising under any such agreement, transaction or arrangement.

Regulation 9

Appeal to Minister

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Where the Controller —

(a)

refuses to grant or renew an accreditation under regulation 5;

(b)

cancels or suspends an accreditation under regulation 6; or

(c)

cancels or suspends an accreditation, or reprimands a certification authority, under regulation 7,any person who is aggrieved by the decision of the Controller may, within 14 days after the person is notified of the decision, appeal to the Minister and the decision of the Minister is final.

Subregulation 2

Suggest a correction

If an appeal is made against a decision made by the Controller, the Controller may, if he or she thinks fit, defer the execution of the decision until the appeal has been decided by the Minister or the appeal is withdrawn.

Subregulation 3

Suggest a correction

In considering whether to defer the execution of the decision, the Controller must have regard to whether the deferment is prejudicial to the interests of any subscriber of the certification authority or any other party who may be adversely affected.

Subregulation 4

Suggest a correction

If an appeal is made to the Minister, a copy of the appeal must be lodged with the Controller.

Part 4

ACCREDITATION REQUIREMENTS

Regulation 10

Business structure

Open as pageSuggest a correction

An applicant for accreditation must be a company operating in Singapore at the time of the application and throughout the period when it is an accredited certification authority.

Regulation 11

Personnel

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

An applicant for accreditation must, at the time of the application and throughout the period when the applicant is an accredited certification authority, take reasonable measures to ensure that every trusted person —

(a)

is a fit and proper person to carry out the duties assigned to him or her;

(b)

is not an undischarged bankrupt in Singapore or elsewhere, and has not made any composition or arrangement with his or her creditors; and

(c)

has not been convicted, whether in Singapore or elsewhere, of —

(i)

an offence the conviction for which involved a finding that he or she acted fraudulently or dishonestly; or

(ii)

an offence under the Act or these Regulations.

Subregulation 2

Suggest a correction

Despite paragraph (1)(c), the Controller may allow the applicant or accredited certification authority to have a trusted person who has been convicted of an offence mentioned in that paragraph, if the Controller is satisfied that —

(a)

the trusted person is now a fit and proper person to carry out his or her duties; and (b)10 years have elapsed from —

(i)

the date of conviction; or

(ii)

the date of release from imprisonment if he or she was sentenced to a term of imprisonment,whichever is the later.

Subregulation 3

Suggest a correction

Every trusted person must —

(a)

have a good knowledge of the Act and these Regulations;

(b)

be trained in the certification authority’s certification practice statement; and

(c)

possess the relevant technical qualifications, expertise and experience to effectively carry out his or her duties.

Regulation 12

Certification practice statement

Open as pageSuggest a correction

An accredited certification authority must have and comply with a certification practice statement approved by the Controller.

Part 5

CONDUCT OF BUSINESS BY ACCREDITED CERTIFICATION AUTHORITIES

Regulation 13

Trustworthy record keeping and archival

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

An accredited certification authority may keep its records in the form of paper documents or electronic records or any other form approved by the Controller.

Subregulation 2

Suggest a correction

The records must be indexed, stored, preserved and reproduced so as to be accurate, complete, legible and accessible to the Controller, an auditor or an authorised officer.

Regulation 14

Trustworthy transaction logs

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Every accredited certification authority must make and keep in a trustworthy manner the records relating to —

(a)

activities in issuance, renewal, suspension and revocation of certificates, including the process of identification of any person requesting a certificate from an accredited certification authority;

(b)

the process of generating subscribers’ (where applicable) or the accredited certification authority’s own key pairs;

(c)

the administration of an accredited certification authority’s computing facilities; and

(d)

any critical related activity of an accredited certification authority that may be determined by the Controller.

Subregulation 2

Suggest a correction

Every accredited certification authority must archive all certificates issued by it and maintain mechanisms to access the certificates for at least 7 years.

Subregulation 3

Suggest a correction

Every accredited certification authority must retain all records required to be kept under paragraph (1) and all logs of the creation of the archive of certificates mentioned in paragraph (2) for at least 7 years.

Regulation 15

Types of certificates

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Subject to the approval of the Controller, an accredited certification authority may issue certificates of the following different levels of assurance:

(a)

certificates which are considered as trustworthy certificates for the purposes of paragraph 3(b)(i) of the Third Schedule to the Act;

(b)

certificates which are not considered as trustworthy certificates for the purposes of paragraph 3(b)(i) of the Third Schedule to the Act.

Subregulation 2

Suggest a correction

The accredited certification authority must associate a distinct certification practice statement approved by the Controller for each type of certificate issued.

Subregulation 3

Suggest a correction

The accredited certification authority must draw the attention of subscribers and relying parties to the effect of using and relying on certificates that are not considered trustworthy certificates for the purposes of paragraph 3(b)(i) of the Third Schedule to the Act.

Regulation 16

Issuance of certificates

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

In addition to the requirements specified in paragraph 14 of the Third Schedule to the Act, every accredited certification authority must comply with the requirements in this regulation in relation to the issuance of certificates.

Subregulation 2

Suggest a correction

The certificate must contain or incorporate by reference information that is sufficient to locate or identify one or more repositories in which notification of the suspension or revocation of the certificate will be listed if the certificate is suspended or revoked.

Subregulation 3

Suggest a correction

The practices and procedures set forth in the certification practice statement of an accredited certification authority must contain conditions with standards higher than those conditions specified in paragraph 14(2) of the Third Schedule to the Act.

Subregulation 4

Suggest a correction

The subscriber identity verification method employed for issuance of certificates must be specified in the certification practice statement and is subject to the approval of the Controller during the application for accreditation.

Subregulation 5

Suggest a correction

Where a certificate is issued to a person (called in this regulation the new certificate) on the basis of another valid certificate held by the same person (called in this regulation the originating certificate) and subsequently the originating certificate has been suspended or revoked, the certification authority that issued the new certificate must conduct investigations to determine whether it is necessary to suspend or revoke the new certificate.

Subregulation 6

Suggest a correction

The accredited certification authority must provide a reasonable opportunity for the subscriber to verify the contents of the certificate before it is accepted.

Subregulation 7

Suggest a correction

If the subscriber accepts the issued certificate, the accredited certification authority must publish a signed copy of the certificate in a repository mentioned in paragraph (2).

Subregulation 8

Suggest a correction

Despite paragraph (7), the accredited certification authority may contractually agree with the subscriber not to publish the certificate.

Subregulation 9

Suggest a correction

If the subscriber does not accept the certificate, the accredited certification authority must not publish it.

Subregulation 10

Suggest a correction

Once the certificate has been issued by the accredited certification authority and accepted by the subscriber, the accredited certification authority must notify the subscriber within a reasonable time of any fact known to the accredited certification authority that significantly affects the validity or reliability of the certificate.

Subregulation 11

Suggest a correction

The date and time of all transactions in relation to the issuance of a certificate must be logged and kept in a trustworthy manner.

Regulation 17

Renewal of certificates

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Regulation 16 applies to the renewal of certificates as it applies to the issuance of certificates.

Subregulation 2

Suggest a correction

The subscriber identity verification method must be that specified in the certification practice statement as approved by the Controller.

Subregulation 3

Suggest a correction

The date and time of all transactions in relation to the renewal of a certificate must be logged and kept in a trustworthy manner.

Regulation 18

Suspension of certificates

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

This regulation applies only to every accredited certification authority which allows subscribers to request for suspension of certificates.

Subregulation 2

Suggest a correction

Every accredited certification authority may provide for immediate revocation instead of suspension if the subscriber has agreed in writing.

Subregulation 3

Suggest a correction

Upon receiving a request for suspension of a certificate under paragraph 16 of the Third Schedule to the Act, the accredited certification authority must ensure that the certificate is suspended and notice of the suspension published in the repository in accordance with paragraph 19 of the Third Schedule to the Act.

Subregulation 4

Suggest a correction

An accredited certification authority may suspend a certificate that it has issued if the accredited certification authority has reasonable grounds to believe that the certificate is unreliable, regardless of whether the subscriber consents to the suspension; but the accredited certification authority must complete its investigation into the reliability of the certificate and decide within a reasonable time whether to reinstate the certificate or to revoke the certificate in accordance with paragraph 17 or 18 of the Third Schedule to the Act.

Subregulation 5

Suggest a correction

It is the responsibility of any person relying on a certificate to check whether a certificate has been suspended.

Subregulation 6

Suggest a correction

An accredited certification authority must suspend a certificate after receiving a valid request for suspension (in accordance with paragraph 16 of the Third Schedule to the Act); but if the accredited certification authority considers that revocation is justified in the light of all the evidence available to it, the certificate must be revoked in accordance with paragraph 17 or 18 of the Third Schedule to the Act.

Subregulation 7

Suggest a correction

An accredited certification authority must check with the subscriber or his or her authorised agent whether the certificate should be revoked and whether to reinstate the certificate after suspension.

Subregulation 8

Suggest a correction

An accredited certification authority must terminate a suspension initiated by request if the accredited certification authority discovers and confirms that the request for suspension was made without authorisation by the subscriber or his or her authorised agent.

Subregulation 9

Suggest a correction

If the suspension of a certificate leads to a revocation of the certificate, the requirements for revocation apply.

Subregulation 10

Suggest a correction

The date and time of all transactions in relation to the suspension of certificates must be logged and kept in a trustworthy manner.

Subregulation 11

Suggest a correction

An accredited certification authority must maintain facilities to receive and act upon requests for suspension at all times of the day and on all days of every year.

Regulation 19

Revocation of certificates

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

In order to confirm the identity of the subscriber or authorised agent making a request for revocation under paragraph 17(a) of the Third Schedule to the Act, the accredited certification authority must use the subscriber identity verification method specified in the certification practice statement for this purpose.

Subregulation 2

Suggest a correction

An accredited certification authority must, after receiving a request for revocation, verify the request, revoke the certificate and publish notification of it under paragraph 20 of the Third Schedule to the Act.

Subregulation 3

Suggest a correction

An accredited certification authority must maintain facilities to receive and act upon requests for revocation at all times of the day and on all days of every year.

Subregulation 4

Suggest a correction

An accredited certification authority must give notice to the subscriber immediately upon the revocation of a certificate.

Subregulation 5

Suggest a correction

The date and time of all transactions in relation to the revocation of certificates must be logged and kept in a trustworthy manner.

Regulation 21

Maintenance of certification practice statement

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Every accredited certification authority must use the Internet draft of the Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework, adopted by the Internet Engineering Task Force and reproduced by the Controller on its Internet website, as a guide for the preparation of its certification practice statement.

Subregulation 2

Suggest a correction

Any change to the certification practice statement during the term of the accreditation requires the prior approval of the Controller.

Subregulation 3

Suggest a correction

Every accredited certification authority must highlight to its subscribers any limitation of their liabilities and, in particular, it must draw the subscribers’ attention to the implication of reliance limits on their certificates.

Subregulation 4

Suggest a correction

The subscriber identity verification method for the issuance, renewal, suspension and revocation of a certificate must be specified in the certification practice statement.

Subregulation 5

Suggest a correction

A copy of the latest version of the certification practice statement, together with its effective date, must be filed with the Controller and published on the certification authority’s Internet website accessible to members of the public.

Subregulation 6

Suggest a correction

After the effective date, the latest version filed with the Controller will be the prevailing version for a particular certificate.

Subregulation 7

Suggest a correction

Every accredited certification authority must log all changes to the certification practice statement together with the effective date of each change.

Subregulation 8

Suggest a correction

An accredited certification authority must keep in a trustworthy manner a copy of each version of the certification practice statement, together with the date it came into effect and the date it ceased to have effect.

Regulation 22

Secure digital signatures

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

The technical implementation of the requirements in paragraph 3 of the Third Schedule to the Act must be such as to ensure that it is computationally infeasible for any person, other than the person to whom the signature correlates, to have created a digital signature which is verified by reference to the public key listed in that person’s certificate.

Subregulation 2

Suggest a correction

The signature on its own should be such as to —

(a)

ensure that the name or other unique identifiable notation of the person to whom the signature correlates be incorporated as part of the signature and cannot be replaced or forged; and

(b)

readily present such indicia of identity to a person intending to rely on the signature.

Subregulation 3

Suggest a correction

The technical implementation should ensure that —

(a)

the steps taken towards the creation of the signature must be under the direction of the person to whom the signature correlates; and

(b)

no other person can reproduce the sequence of steps to create the signature and thereby create a valid signature without the involvement or the knowledge of the person to whom the signature correlates.

Subregulation 4

Suggest a correction

The technical implementation should indicate to a relying party of a signature whether the document or record that the signature purports to sign has been modified in any way and this indication should be revealed in the process of verifying the signature.

Regulation 23

Compliance Audit Checklist

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Every accredited certification authority must ensure that in the performance of its services it materially satisfies the Compliance Audit Checklist determined by the Controller and published on the Controller’s Internet website.

Subregulation 2

Suggest a correction

An auditor, when determining whether a departure from the Compliance Audit Checklist is material, must exercise reasonable professional judgment as to whether a condition that does not strictly comply with the Compliance Audit Checklist is or is not material, taking into consideration the circumstances and the system as a whole.

Subregulation 3

Suggest a correction

Without limiting the situations which the auditor may consider to be material, the following incidents of non‑compliance are to be considered to be material:

(a)

any non‑compliance relating to the validity of a certificate;

(b)

the performance of the functions of a trusted person by a person who is not suitably qualified;

(c)

the use by an accredited certification authority of any system other than a trustworthy system.

Subregulation 4

Suggest a correction

The Compliance Audit Checklist must be interpreted in a manner that is reasonable in relation to the context in which a system is used and is consistent with law.

Subregulation 5

Suggest a correction

Despite an auditor’s assessment of whether a departure from the Compliance Audit Checklist is material, the Controller may make his or her own assessment and reach a conclusion for the purpose of paragraph (1) which is at variance with that of the auditor.

Subregulation 6

Suggest a correction

Every accredited certification authority must provide every subscriber with a trustworthy system to generate his or her key pair.

Subregulation 7

Suggest a correction

Every accredited certification authority must provide the mechanism to generate and verify digital signatures in a trustworthy manner and the mechanism provided must also indicate the validity of the signature.

Subregulation 8

Suggest a correction

If the digital signature is not valid, the mechanism provided should indicate if the invalidity is due to the integrity of the document or the signature and the mechanism provided must also indicate the status of the certificate.

Subregulation 9

Suggest a correction

For mechanisms provided by third parties other than the accredited certification authority, the resulting signature is considered secure only if the accredited certification authority endorses the implementation of such mechanisms in conjunction with its certificate.

Subregulation 10

Suggest a correction

Every accredited certification authority is responsible for the storage of keys (including the subscriber’s key and the accredited certification authority’s own key) in a trustworthy manner.

Subregulation 11

Suggest a correction

The Controller may publish on its Internet website further details of the Compliance Audit Checklist for compliance by every accredited certification authority.

Regulation 24

Incident handling

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

An accredited certification authority must implement an incident management plan that must provide at the least for management of the following incidents: (a)compromise of key;

(b)

penetration of certification authority system and network;

(c)

unavailability of infrastructure;

(d)

fraudulent registration and generation of certificates, certificate suspension and revocation information.

Subregulation 2

Suggest a correction

If any incident mentioned in paragraph (1) occurs, it must be reported to the Controller within 24 hours.

Regulation 25

Confidentiality

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Every accredited certification authority and its authorised agent must keep all subscriber‑specific information confidential.

Subregulation 2

Suggest a correction

Paragraph (1) does not apply to —

(a)

any disclosure of subscriber‑specific information made —

(i)

with the permission of the subscriber;

(ii)

for the purposes of the administration or enforcement of section 23 or 24 or Part 6 of the Act;

(iii)

for any prosecution under any written law; or

(iv)

in compliance with an order of court or the requirement of any written law; or

(b)

any subscriber‑specific information which —

(i)

is contained in the certificate, or is otherwise provided by the subscriber to the accredited certification authority, for public disclosure; or

(ii)

relates to the fact that the certificate has been suspended or revoked.

Regulation 26

Change in management

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

An accredited certification authority must notify the Controller within 5 days of any changes in —

(a)

the appointment of any person as a member of its board of directors, its chairperson or its chief executive, or their equivalent; or

(b)

any persons with a controlling interest in the certification authority.

Subregulation 2

Suggest a correction

For the purposes of paragraph (1)(b), a person has a controlling interest in a certification authority if —

(a)

that person has an interest in the voting shares of the certification authority and exercises control over the certification authority; or

(b)

that person has an interest in the voting shares of the certification authority of an aggregate of at least 30% of the total votes attached to all voting shares in the certification authority, unless that person does not exercise control over the certification authority.

Subregulation 3

Suggest a correction

The notification required in relation to paragraph (1)(b) must be in the form that the Controller may require and must include the following information:

(a)

the name of the person with a controlling interest;

(b)

the percentage of the voting shares in the certification authority acquired by that person.

Part 6

REQUIREMENTS FOR REPOSITORY

Regulation 27

Availability of general purpose repository

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

A general purpose repository must be available at all times of the day and on all days of every year.

Subregulation 2

Suggest a correction

A general purpose repository must ensure that the total aggregate period of any down time in any period of one month does not exceed 0.3% of the period.

Subregulation 3

Suggest a correction

Any down time, whether scheduled or unscheduled, must not exceed 30 minutes duration at any one time.

Regulation 28

Specific purpose repository

Open as pageSuggest a correction

Subject to the approval of the Controller, a repository may be dedicated for a specific purpose for which specific hours of operation may be acceptable.

Part 7

ACCREDITATION MARK

Regulation 29

Use of accreditation mark

Open as pageSuggest a correction

Any person who, not being an accredited certification authority, uses an accreditation mark or a colourable imitation of an accreditation mark shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $50,000 or to imprisonment for a term not exceeding 12 months or to both.

Part 8

APPLICATION TO PUBLIC AGENCIES

Regulation 30

Application to public agencies

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

For the purposes of paragraph 3(b)(iii) of the Third Schedule to the Act, a public agency that is approved by the Minister under that paragraph to act as a certification authority must comply with the provisions of the following Parts as if it were an accredited certification authority:

(a)

Part 3 (with the exception of regulations 5, 6, 8 and 9);

(b)

Part 4 (with the exception of regulation 10);

(c)

Part 5 (with the exception of regulation 26);

(d)

Part 6;

(e)

Part 7 (with the exception of regulation 29);

(f)

Part 8;

(g)

Part 9 (with the exception of regulations 35 and 36).

Subregulation 2

Suggest a correction

The provisions mentioned in paragraph (1) apply, with the necessary modifications and any other modifications that the Controller may determine, to a public agency mentioned in that paragraph.

Part 9

ADMINISTRATION

Regulation 31

Waiver

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

Any accredited certification authority that wishes to apply for a waiver of any of the requirements specified in these Regulations may apply in writing to the Controller at the time when it submits an application for accreditation.

Subregulation 2

Suggest a correction

The application must be supported by reasons for the application and include any supporting documents that the Controller may require.

Regulation 32

Disclosure

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

The accredited certification authority must submit half‑yearly progress and financial reports to the Controller.

Subregulation 2

Suggest a correction

The half‑yearly progress reports must include information on —

(a)

the number of subscribers;

(b)

the number of certificates issued, suspended, revoked, expired and renewed;

(c)

system performance including system up and down time and any extraordinary incidents;

(d)

changes in the organisational structure of the certification authority; (e)changes since the preceding progress report was submitted or since the application for the accreditation; and

(f)

changes in the particulars of any trusted person since the last submission to the Controller, including the name, identification number, residential address, designation, function and date of employment of the trusted person.

Subregulation 3

Suggest a correction

The accredited certification authority has a continuing obligation to disclose to the Controller any changes in the information submitted.

Subregulation 4

Suggest a correction

All current versions of the accredited certification authority’s applicable certification practice statements together with their effective dates must be published in the accredited certification authority’s Internet website.

Regulation 33

Discontinuation of operations of accredited certification authority

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

If an accredited certification authority intends to discontinue its operations, the accredited certification authority may arrange for its subscribers to re‑subscribe to another accredited certification authority.

Subregulation 2

Suggest a correction

The accredited certification authority must make arrangements for its records and certificates to be archived in a trustworthy manner.

Subregulation 3

Suggest a correction

If the records are transferred to another accredited certification authority, the transfer must be done in a trustworthy manner.

Subregulation 4

Suggest a correction

An accredited certification authority must —

(a)

give to the Controller written notice of its intention to discontinue its operations not later than 3 months before the discontinuation;

(b)

give to its subscribers written notice of its intention to discontinue its operations not later than 2 months before the discontinuation; and

(c)

advertise, in such daily newspapers and in such manner as the Controller may determine, its intention to discontinue its operations not later than 2 months before the discontinuation.

Regulation 34

Audit

Open as pageSuggest a correction

Subregulation 1

Suggest a correction

The Controller may, by written notice, require an accredited certification authority to undergo and pass an audit.

Subregulation 2

Suggest a correction

The audit mentioned in paragraph (1) must be —

(a)

conducted in accordance with the auditing requirements specified in this regulation; and

(b)

completed within the time that the Controller may, by written notice, specify.

Subregulation 3

Suggest a correction

The audit must be conducted by a qualified independent audit team approved by the Controller for this purpose comprising a person who is a Certified Public Accountant and a person who is a Certified Information Systems Auditor and either of whom must possess sufficient knowledge of digital signatures and certificates.

Subregulation 4

Suggest a correction

The firm or company to which the audit team belongs must be independent of the certification authority being audited and must not be a software or hardware vendor that is providing or has provided services or is supplying or has supplied equipment to the certification authority.

Subregulation 5

Suggest a correction

Auditing fees must be borne by the certification authority.

Subregulation 6

Suggest a correction

A copy of the audit report must be submitted to the Controller within 4 weeks of the completion of an audit.

Regulation 35

Penalties

Open as pageSuggest a correction

Any person who, without any reasonable excuse, fails to comply with regulation 13(2), 14, 16(2) or (11), 17(3), 18(10), 19(5), 21(7) or (8) or 25(1) shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $5,000 and, in the case of a second or subsequent conviction, to a fine not exceeding $10,000.

Regulation 36

Composition of offences

Open as pageSuggest a correction

Any offence under section 23(2) of the Act or under these Regulations may be compounded by the Controller under section 36 of the Act.

Common questions

What is Electronic Transactions (Certification Authority) Regulations 2010?
Electronic Transactions (Certification Authority) Regulations 2010 is Singapore Subsidiary Legislation, cited as Subsidiary Legislation ETA-RG1 2010, currently marked in force and first recorded in 2010.
Is Electronic Transactions (Certification Authority) Regulations 2010 still in force?
Yes — Electronic Transactions (Certification Authority) Regulations 2010 is currently in force.
When did Electronic Transactions (Certification Authority) Regulations 2010 take effect?
Electronic Transactions (Certification Authority) Regulations 2010 was first recorded in 2010.
How many regulations does Electronic Transactions (Certification Authority) Regulations 2010 have?
Electronic Transactions (Certification Authority) Regulations 2010 contains 36 regulations.
Where can I read the official version of Electronic Transactions (Certification Authority) Regulations 2010?
The official text of Electronic Transactions (Certification Authority) Regulations 2010 is published at sso.agc.gov.sg.