GSO ISO/IEC 27099:2024

ISO/IEC 27099:2022
Gulf Standard   Current Edition · Approved on 31 January 2024

Information technology — Public key infrastructure — Practices and policy framework

GSO ISO/IEC 27099:2024 Files

GSO ISO/IEC 27099:2024 Scope

This document sets out a framework of requirements to manage information security for Public key infrastructure (PKI) trust service providers through certificate policies, certificate practice statements, and, where applicable, their internal underpinning by an information security management system (ISMS). The framework of requirements includes the assessment and treatment of information security risks, tailored to meet the agreed service requirements of its users as specified through the certificate policy. This document is also intended to help trust service providers to support multiple certificate policies.

This document addresses the life cycle of public key certificates that are used for digital signatures, authentication, or key establishment for data encryption. It does not address authentication methods, non-repudiation requirements, or key management protocols based on the use of public key certificates. For the purposes of this document, the term “certificate” refers to public key certificates. This document is not applicable to attribute certificates.

This document uses concepts and requirements of an ISMS as defined in the ISO/IEC 27000 family of standards. It uses the code of practice for information security controls as defined in ISO/IEC 27002. Specific PKI requirements (e.g. certificate content, identity proofing, certificate revocation handling) are not addressed directly by an ISMS such as defined by ISO/IEC 27001 [26].

The use of an ISMS or equivalent is adapted to the application of PKI service requirements specified in the certificate policy as described in this document.

A PKI trust service provider is a special class of trust service for the use of public key certificates.

This document draws a distinction between PKI systems used in closed, open and contractual environments. This document is intended to facilitate the implementation of operational, baseline controls and practices in a contractual environment. While the focus of this document is on the contractual environment, application of this document to open or closed environments is not specifically precluded.

Best Sellers From Information Sector

GSO ISO/TR 18492:2017
ISO/TR 18492:2005 
Gulf Standard
Long-term preservation of electronic document-based information
GSO ISO/IEC 15773:2013
ISO/IEC 15773:1998 
Gulf Standard
Information technology -- Telecommunications and information exchange between systems -- Broadband Private Integrated Services Network -- Inter-exchange signalling protocol -- Transit counter additional network feature
GSO ISO 16175-2:2013
ISO 16175-2:2011 
Gulf Standard
Information and documentation -- Principles and functional requirements for records in electronic office environments -- Part 2: Guidelines and functional requirements for digital records management systems
GSO ISO/TR 13028:2013
ISO/TR 13028:2010 
Gulf Standard
Information and documentation - Implementation guidelines for digitization of records

Recently Published from Information Sector

GSO ISO/IEC 23859:2024
ISO/IEC 23859:2023 
Gulf Standard
Information technology — User interfaces — Requirements and recommendations on making written text easy to read and understand
GSO ISO/IEC 22123-1:2024
ISO/IEC 22123-1:2023 
Gulf Standard
Information technology — Cloud computing — Part 1: Vocabulary
GSO ISO 29585:2024
ISO 29585:2023 
Gulf Standard
Health informatics — Framework for healthcare and related data reporting
GSO ISO 16245:2024
ISO 16245:2023 
Gulf Standard
Information and documentation — Boxes, file covers and other enclosures, made from cellulosic materials, for storage of paper and parchment documents