{"title":"Certificate policy and Certification Practice Statement for root CA Indonesia","authors":"Arfive Gandhi, Y. G. Sucahyo, T. Sirait","doi":"10.1109/ICSITECH.2016.7852654","DOIUrl":null,"url":null,"abstract":"Certificate Policy (CP) and Certification Practice Statement (CPS) are required documents for Certification Authority (CA) to describe its information security mechanism, business processes and regulation compliance. Ministry of Communication and Information Technology (MCIT) Indonesia need to compose CP and CPS because of its role as Root CA in Indonesia National Public Key Infrastructure (INPKI). This research proposes CP and CPS for Root CA Indonesia following the content structure in Request for Comment (RFC) 3647. The proposed CP and CPS involve elaboration among applied technology, procedures of information security, and legal aspect of information security in Indonesia. Significant contribution of this research is the development of CP and CPS as fundamental standards in establishing Indonesia National Public Key Infrastructure (INPKI) as part of national information security system. Moreover, Webtrust Perspective Criteria is used to appraise the comprehensiveness of CP and CPS. As a result, the constructed CP and CPS have 96 percent suitability (43 criteria out of 45). This performance indicates that CP and CPS are applicable and ready to be adopted by Root CA Indonesia.","PeriodicalId":447090,"journal":{"name":"2016 2nd International Conference on Science in Information Technology (ICSITech)","volume":"53 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 2nd International Conference on Science in Information Technology (ICSITech)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICSITECH.2016.7852654","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4
Abstract
Certificate Policy (CP) and Certification Practice Statement (CPS) are required documents for Certification Authority (CA) to describe its information security mechanism, business processes and regulation compliance. Ministry of Communication and Information Technology (MCIT) Indonesia need to compose CP and CPS because of its role as Root CA in Indonesia National Public Key Infrastructure (INPKI). This research proposes CP and CPS for Root CA Indonesia following the content structure in Request for Comment (RFC) 3647. The proposed CP and CPS involve elaboration among applied technology, procedures of information security, and legal aspect of information security in Indonesia. Significant contribution of this research is the development of CP and CPS as fundamental standards in establishing Indonesia National Public Key Infrastructure (INPKI) as part of national information security system. Moreover, Webtrust Perspective Criteria is used to appraise the comprehensiveness of CP and CPS. As a result, the constructed CP and CPS have 96 percent suitability (43 criteria out of 45). This performance indicates that CP and CPS are applicable and ready to be adopted by Root CA Indonesia.