Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions categories/policies-and-documentation/_index.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ The Certificate Policy (CP) defines the overall policies and requirements of a P

| ID | Requirement | Weight |
|----|-------------|-------:|
| [`policy-scope`](#policy-scope) | he scope of policies is defined and documented | 2 |
| [`policy-scope`](#policy-scope) | The scope of policies is defined and documented | 2 |
| [`certificate-policy`](#certificate-policy) | Certificate policy is documented and published | 5 |
| [`practice-statement`](#practice-statement) | Certification practice statement is documented and published | 5 |
| [`disclosure-statement`](#disclosure-statement) | Disclosure statement is documented and published | 4 |
Expand All @@ -44,7 +44,7 @@ The Certificate Policy (CP) defines the overall policies and requirements of a P
## Details

<a id="policy-scope"></a>
### he scope of policies is defined and documented
### The scope of policies is defined and documented

#### Guidance

Expand Down
2 changes: 1 addition & 1 deletion data/pkimm-model-1.0.0.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -150,7 +150,7 @@ modules:
requirements:
- id: "1"
weight: 2
description: "he scope of policies is defined and documented"
description: "The scope of policies is defined and documented"
guidance: |
Each PKI implementation and use case is different, therefore it requires different care. The scope of policies that are applicable for the implementation should be defined and documented. When the proper description of the policies scope is provided, it helps all parties involved to understand the purpose of the policies and their applicability.

Expand Down
2 changes: 1 addition & 1 deletion data/pkimm-model-2.0.0.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -150,7 +150,7 @@ modules:
requirements:
- id: policy-scope
weight: 2
description: he scope of policies is defined and documented
description: The scope of policies is defined and documented
guidance: |
Each PKI implementation and use case is different, therefore it requires different care. The scope of policies that are applicable for the implementation should be defined and documented. When the proper description of the policies scope is provided, it helps all parties involved to understand the purpose of the policies and their applicability.

Expand Down
2 changes: 1 addition & 1 deletion integrations/eramba/pkimm-1.0.0.csv
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,7 @@ It consists of:
Properly documented policies keeps the PKI assets trusted over the time and serves as a basis for integrated processes and procedures. It is a living management system that is continuously updated and changed as technologies, security, and compliance requirements change.

The Certificate Policy (CP) defines the overall policies and requirements of a PKI, the Certification Practice Statement (CPS) provides detailed operational procedures followed by the Certification Authority (CA), and the disclosure statement offers transparency about the CA's identity and services to relying parties.
",G.2.1,he scope of policies is defined and documented,"Each PKI implementation and use case is different, therefore it requires different care. The scope of policies that are applicable for the implementation should be defined and documented. When the proper description of the policies scope is provided, it helps all parties involved to understand the purpose of the policies and their applicability.
",G.2.1,The scope of policies is defined and documented,"Each PKI implementation and use case is different, therefore it requires different care. The scope of policies that are applicable for the implementation should be defined and documented. When the proper description of the policies scope is provided, it helps all parties involved to understand the purpose of the policies and their applicability.

The scope can include the following:
- Identification of the policies required for the implementation
Expand Down
5 changes: 2 additions & 3 deletions integrations/eramba/pkimm-2.0.0.csv
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ It consists of:
Properly documented policies keeps the PKI assets trusted over the time and serves as a basis for integrated processes and procedures. It is a living management system that is continuously updated and changed as technologies, security, and compliance requirements change.

The Certificate Policy (CP) defines the overall policies and requirements of a PKI, the Certification Practice Statement (CPS) provides detailed operational procedures followed by the Certification Authority (CA), and the disclosure statement offers transparency about the CA's identity and services to relying parties.
",G.policies-and-documentation.policy-scope,he scope of policies is defined and documented,"Each PKI implementation and use case is different, therefore it requires different care. The scope of policies that are applicable for the implementation should be defined and documented. When the proper description of the policies scope is provided, it helps all parties involved to understand the purpose of the policies and their applicability.
",G.policies-and-documentation.policy-scope,The scope of policies is defined and documented,"Each PKI implementation and use case is different, therefore it requires different care. The scope of policies that are applicable for the implementation should be defined and documented. When the proper description of the policies scope is provided, it helps all parties involved to understand the purpose of the policies and their applicability.

The scope can include the following:
- Identification of the policies required for the implementation
Expand Down Expand Up @@ -1864,8 +1864,7 @@ Different methods can be applied to provide security awareness, for example:

References
- NIST SP 800-50 Building an Information Technology Security Awareness and Training Program
- PCI SSC - Best Practices for Implementing a
Security Awareness Program
- PCI SSC - Best Practices for Implementing a Security Awareness Program
- Raising Awareness of Cybersecurity"
R.knowledge-and-training,Knowledge and training,"The purpose of this category is to ensure that the PKI personnel have the required knowledge and skills to perform their duties and responsibilities.
Education and continuous gathering of required knowledge and skills to manage the PKI is important to be aware and properly react to current trends and threats that may impact the PKI.
Expand Down
2 changes: 1 addition & 1 deletion model/references/_index.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
date: 2026-05-20T00:00:00Z
date: 2026-05-21T00:00:00Z
title: References
weight: 4
---
Expand Down